Sophos Home Dashboard: Manage Account, License and Devices
The Sophos Home dashboard is the control room for a household, but four different systems meet there: account access, antivirus entitlement, managed computers and Cleverbridge billing. Most expensive mistakes happen when one action is assumed to control all four.

Quick answer: sign in at my.sophos.com or open Dashboard from a protected Windows or Mac computer. Use Add Device and a fresh account-generated installer for every additional computer. Premium manages up to ten supported computers; the trial manages three; mobile apps are separate. Removing a device frees a seat but does not uninstall Sophos. A license key attaches once and does not stack. History lasts 90 days. Enable MFA plus a recovery route, and remember that deleting the Home account does not cancel Cleverbridge billing.
Start with the right Sophos dashboard
The consumer console lives at my.sophos.com. You can type that address into a browser, or open Dashboard or Manage Devices from the local Sophos Home application. The second route can use Direct Access after the local Windows or Mac user has authenticated. Sophos says Windows may first request that computer’s own sign-in password; that is not the Home account password.
This guide is not for Sophos Central, Sophos Central Self Service, Sophos Firewall or an employer’s Intercept X tenant. Those products can share logos and familiar words while using different administrators, policies and license systems. If a school or workplace owns the endpoint, do not move it into a personal Home account. Ask the organization that controls the existing tenant.
Ignore pages offering “Sophos Home 360,” telephone activation or a mystery desktop portal. Sophos Home’s current consumer model is a web dashboard connected to Windows and Mac agents. The safest habit is to type or bookmark the official address instead of following a sponsored result whenever a warning appears.
Understand the four ownership layers before changing anything
The dashboard shows related information, but it does not collapse account, license, devices and billing into one object. An account owns credentials, MFA recovery and Direct Access sessions. A license determines trial, Premium, legacy Free or expired entitlement. Device records control remote settings and consume computer seats. Cleverbridge handles the commercial renewal state.

| Action | What it changes | What it does not do |
|---|---|---|
| Remove device | Ends dashboard management and frees a seat | Does not uninstall the local agent |
| Uninstall locally | Removes protection from that computer | May leave the old dashboard record |
| Cancel renewal | Stops the next automatic charge | Is not an automatic refund |
| Delete account | Permanently removes the Home identity | Does not cancel billing or uninstall endpoints |
| Install mobile app | Protects the phone within mobile OS limits | Does not add a Home dashboard computer |
That separation explains many support stories. A user removes a laptop and is surprised that Sophos still runs. Another deletes the account and expects renewal to disappear. A third buys another key and expects two terms to combine. The interface cannot make an incorrect assumption safe, so decide which layer you actually need to change first.
Sign in through the browser or a protected computer
The normal browser route asks for the Sophos Home account email and password. When Sophos needs to verify a sign-in, its current support article identifies [email protected] as the sender. Check the complete address rather than the display name, and never forward a verification code to someone claiming to be support.
The local route opens the dashboard through the installed endpoint and can use Direct Access. It is convenient for an owner managing several family computers and later becomes a valuable MFA recovery path. It is also a trust decision: someone who can use that local Windows or Mac account may reach settings for other computers. On a shared or borrowed device, use a private browser session and sign out; do not enable a remembered route merely to save one password entry.
If the password is forgotten, use the official Sophos Home password reset. Before assuming the reset email failed, confirm which address owns the account from a still-connected local app. Multiple household emails and an old purchase receipt are common reasons for resetting the wrong identity.
Read the dashboard one computer at a time
Sophos Home is organized around individual Windows and Mac computers rather than one dense enterprise overview. Select a computer before interpreting its status or changing a setting. The device view exposes protection, web filtering, privacy controls, scans, history and quarantine according to the platform and entitlement. A green computer does not prove that every other family endpoint is current.
A practical household review starts with names and timestamps. Give each computer a recognizable label, confirm it appears only once, compare its recent activity with when it was actually online and investigate grey, vulnerable, action-required or long-stale records. When Premium expires, affected computers can appear greyed out and management controls become unavailable; that state is an entitlement issue, not proof that the agent cleanly uninstalled itself.
Community criticism that the Home console lacks a stronger all-devices summary is fair directional evidence, not a change in official behavior. One r/sophos discussion describes the frustration of checking machines individually. Build a repeatable naming and review routine instead of assuming the quietest dashboard is the safest one.
Add Device is the correct route for another computer
Sign in to the account that should own the endpoint, choose Add Device, and either download the current installer on the target computer or send its official delivery link. Use a fresh installer for each computer. The public Sophos Home download can start a separate trial, while an old saved installer can carry stale account context or fail to create the expected record.
Premium covers up to ten supported Windows and Mac computers. The 30-day trial covers three. If the account is full, review the records and remove only a computer that is genuinely retired, lost or moving to a different account. Do not delete an active relative’s endpoint to make the number change; the local agent may keep running without the cloud management the family expects.
The full Sophos Home installation guide covers Windows support, Mac permissions and verification after restart. The dashboard’s job is ownership and remote control. Installation is complete only when the intended account shows the correct computer and the local shield remains protected after reboot.
Removing a device is not uninstalling Sophos Home
The official device-removal guidance is unusually explicit: removal frees the device count and stops remote management, but Sophos Home continues running on the computer until it is uninstalled there. This design helps when a record is being reorganized, but it is easy to misunderstand when selling or recycling a machine.
For a computer you still possess, first confirm that another security plan is ready, uninstall Sophos locally through the supported Windows or Mac route, restart, and then remove the stale dashboard record if it remains. For a lost device, remove it to stop treating it as managed and revoke Direct Access, but do not claim that this remotely erased the disk or agent. Sophos Home is antivirus management, not mobile-device-management or a remote wipe service.
If the computer is moving to another family account, remove it from the old dashboard and reinstall from a fresh Add Device link belonging to the new account. Simply entering a new password cannot transfer ownership. Preserve useful quarantine or history details before removal because the old dashboard relationship is part of that evidence.
Fix a missing device by correcting ownership
Sophos lists four common reasons for a computer not appearing: an old installer, installation under another account, manual dashboard removal or use of an account-less download. Start at the local app. Identify the account email if it is shown, compare the computer name and confirm whether protection still runs. Then sign into the matching Home account rather than cycling through passwords blindly.
If the endpoint belongs to the wrong account or was removed, use the normal local uninstall route, restart and reinstall from Add Device in the intended dashboard. The official missing-device article recommends a fresh installer. Repeated browser refreshes, renaming the record or buying another license cannot repair an installer tied to the wrong ownership path.
A long-running r/sophos Add Device thread captures the same real-world trap: the public installer and account-generated installer are not interchangeable when an existing subscription must own the endpoint. Use the community report to recognize the symptom, then follow current official instructions for the fix.
Activate a Premium key once, on the intended account
A Sophos Home Premium license key has twenty characters separated by three dashes. Enter it only through the official account path and verify which email is signed in before activation. Sophos says activation is one-time and the key becomes permanently linked to that account. A typo in the account choice is therefore more serious than a typo you can simply retry elsewhere.
Keys do not stack. If Premium is already active, wait until that subscription expires before activating the next key. Sophos also says the license term starts when the key is purchased, not when you eventually enter it, so buying a future year too early can consume time while another entitlement still runs. Keep the receipt and key private; support forums and screenshots are not safe storage.
After activation, open My Account and confirm the subscription state and covered devices. Do not infer success from a payment receipt alone. The separate Sophos Home pricing and renewal guide explains the current Premium, trial, legacy Free and expired paths in more detail.
Read “Renews” and “Expires” literally
An account that says Renews is set for another automatic term through the billing relationship. An account that says Expires should run until the displayed date without automatic renewal. Cancelling renewal changes the future charge; it is not the same as obtaining a refund, deleting the account or removing antivirus from a computer.
Keep the Sophos Home account email and the purchase or billing email in mind as separate records. They may be the same, but changing one does not guarantee the other changed. Save the Cleverbridge order reference and confirmation before losing access to an old inbox. When a payment issue and an account issue happen together, resolve billing through the purchase route and protection ownership through Home Dashboard.
At expiry, the dashboard can disable management of affected devices. That does not prove that every endpoint instantly falls back to a specific Windows or macOS protection state. Visit each computer, confirm what is running locally and make the transition deliberately. A grey record is a reason to inspect the endpoint, not a substitute for inspection.
Use the 90-day History tab as an operational record
The official History tab guide says the dashboard retains 90 days and offers five filters: All, Threats, Websites, Other and Quarantine. Review the time, computer and event type before acting. A blocked website, cleaned file and policy change are different incidents even when they appear near each other.
Sophos does not provide a way to manually delete individual history entries. That protects the usefulness of the rolling record, but it also means the dashboard is not a private notebook or permanent archive. Avoid device names that expose unnecessary personal details. Export or securely record evidence that matters for an investigation before the 90-day window rolls forward.
History is strongest when paired with the endpoint itself. Check the current quarantine state, file path, detection name and whether the computer was online. Do not restore a file merely because the person recognizes its name, and do not treat an empty History filter as proof that nothing happened outside the retention window.
Enable MFA with two recovery paths
Sophos Home supports authenticator-based multi-factor authentication and asks for at least one recovery method. The current MFA setup guide recommends a recovery email different from the Home account email and Direct Access on at least one trusted protected computer. That combination avoids making the same compromised inbox the only key to both sign-in and recovery.
A remembered browser can remain trusted for 30 days. Use that convenience only on an owner-controlled profile with a strong local password and disk encryption. Do not remember a family kiosk, borrowed laptop or shared work account. Keep recovery codes or methods in a password manager, and act on unexpected sign-in alerts instead of dismissing them as antivirus noise.
When the authenticator is lost, use Direct Access or the configured recovery email or mobile route documented in Sophos’ MFA recovery article. Repeated wrong codes can lock access, and support cannot simply remove every lock. Stop guessing, preserve the account email and switch to the recovery workflow.
Treat Direct Access as recovery and a local privilege
Direct Access is Sophos Home’s single-sign-on bridge from a protected computer to the dashboard. It can rescue an owner who lost an authenticator, but it also extends household-wide administrative power to that local Windows or Mac session. The right decision depends on who can unlock the computer, not just who originally installed Sophos.
Enable it on at least one trusted owner device, keep that device encrypted and protected by a unique local password, and avoid it on shared children’s profiles or machines leaving the household. To revoke access, Sophos directs users to My Account, confirms the Home password, then provides Sign out for one device or Sign out All under Device Protection.
If a laptop is lost or sold, revoke Direct Access before worrying about cosmetic dashboard cleanup. Removing its device record is a separate action and still does not wipe or uninstall it. The official Direct Access documentation should control the current menu wording.
Change the account email without losing the billing trail
Sophos Home lets the signed-in owner change the account email under My Account. The current email-change procedure sends a verification code to the existing address and gives that code a ten-minute window. Update while the old inbox still works; waiting until it is deleted turns a routine change into recovery.
The billing or purchase email must be updated separately. After changing the Home identity, verify MFA recovery, password-manager entries, Direct Access sessions, Cleverbridge notices and the computer records. A Premium user who has lost the old inbox can use official support channels; Sophos warns that a Free user without access to the registered address may not be recoverable.
If you are unsure which email owns a computer, use the local application and Sophos’ account email locator. Do not paste a license key into every possible account to test them. A key links once.
Keep mobile security outside the computer counter
Sophos Intercept X for Mobile is a separate app for Android and iOS. Sophos says it does not appear in the Home dashboard and does not consume one of the Premium or trial computer seats. A phone therefore cannot explain why Add Device says the ten-computer limit is full.
Install mobile only through the official app store route and manage its permissions on the phone. The Home dashboard cannot remotely scan an iPhone, show it beside a Mac or convert a mobile result into a Windows history event. Our current iPhone security guide and Android antivirus guide cover the platform-specific limits.
Delete the account only after billing and endpoints are settled
Account deletion is irreversible. The official Sophos deletion article also states two boundaries that are easy to miss: installed agents continue running until locally uninstalled, and deleting the account does not cancel billing. A rushed deletion can therefore remove the console while leaving both software and a commercial obligation behind.
- Check My Account. Record whether the subscription says Renews or Expires and save the expiry date.
- Cancel future renewal if intended. Complete the Cleverbridge purchase route and preserve confirmation; cancellation is not automatically a refund.
- Review every computer. Save incident evidence, revoke Direct Access and arrange local uninstall or a planned security replacement.
- Update ownership when needed. Move active computers through a fresh Add Device installer for the new account rather than abandoning them.
- Delete last. Use the permanent account action only when no dashboard, recovery or device history is still needed.
This order is deliberately conservative because only the last action is irreversible. Removing a stale device or cancelling renewal can be verified. Deleting the identity first makes every later check harder.
Run a five-minute household admin review each month
Open the typed or bookmarked dashboard, scan the computer list and investigate duplicates, grey records and devices that have not checked in. Select each active computer, review recent History filters, confirm protection state and remove only endpoints that are truly retired. Ten orderly records are easier to protect than six real devices plus four forgotten names.
Then open My Account. Confirm the owner email still works, MFA recovery is independent, Direct Access exists only on trusted systems and the subscription says the expected Renews or Expires state. Keep the billing order reference outside the antivirus account. That short routine catches ownership drift before it becomes an expired license, lost authenticator or unmanageable family laptop.
Use the broader Sophos Home review when deciding whether this per-device cloud model still fits the household. Dashboard competence cannot add unsupported platforms or turn consumer antivirus into enterprise administration, but it can make the product’s real boundaries predictable.
Sophos Home dashboard FAQ
Where do I sign in to the Sophos Home dashboard?
Type my.sophos.com into a browser or use Dashboard or Manage Devices from the Sophos Home app on a protected computer. The web console is Sophos Home, not Sophos Central or the Sophos Firewall portal. A browser sign-in uses the Home account email and password; launching through the local app can offer Direct Access after the Windows or Mac user is authenticated.
How many devices can Sophos Home protect?
Sophos Home Premium covers up to ten supported Windows and Mac computers, while the 30-day trial covers three. The free Sophos Intercept X for Mobile apps do not appear in the Home dashboard and do not consume a computer seat. A removed computer frees its seat, but the Sophos agent keeps running locally until it is separately uninstalled.
How do I add another computer to Sophos Home?
Sign in to the dashboard that owns the intended license, choose Add Device, and download or send the current installer to the target computer. Run that fresh installer on the target rather than reusing an old public download. This is the most reliable way to connect the new endpoint to the correct account and avoid creating an unrelated trial.
Why is my computer missing from the Sophos Home dashboard?
Common causes are an old installer, installation through a different Home account, manual removal from the dashboard, or an account-less public download. Confirm the account email from the local app, sign into the matching dashboard and use a fresh Add Device installer. If the endpoint was removed, reinstall from the intended dashboard; repeatedly refreshing the page cannot restore ownership.
Does removing a device uninstall Sophos Home?
No. Remove from the dashboard stops remote management and frees the device slot, but Sophos says the software continues running on that Windows or Mac computer until someone uninstalls it locally. Remove a device only when it is retired, lost or moving to another account, then arrange the local uninstall when the endpoint is still accessible.
Can I stack two Sophos Home license keys?
No. A Sophos Home Premium key is activated once and permanently linked to that account, and Sophos says keys do not stack. Wait until the current subscription expires before activating the next key. The key timer begins when it is purchased, so buying far ahead can waste part of its term.
What is Direct Access in Sophos Home?
Direct Access is Sophos Home's single-sign-on route from a protected computer into the dashboard without entering the Home password again. It is valuable as an MFA recovery route, but it also means a person using that local Windows or Mac account may reach household-wide settings. Revoke one or all Direct Access sessions under My Account when a computer is shared, sold or lost.
How far back does Sophos Home dashboard history go?
The History tab keeps 90 days of events and can filter All, Threats, Websites, Other and Quarantine. Sophos does not provide a control to manually delete individual history entries. Treat it as a rolling operational record, not permanent compliance storage, and preserve important incident evidence elsewhere before it ages out.
Does deleting my Sophos Home account cancel the subscription?
No. Account deletion is irreversible, but Sophos explicitly says it does not cancel billing. Cancel automatic renewal through the purchase and billing route first, verify whether the account says Renews or Expires, then remove or uninstall protected devices and delete the account only if that permanent step is still intended.
How do I recover Sophos Home MFA access?
Use Direct Access from an already protected computer or a configured recovery email or mobile method. Sophos recommends a recovery email different from the Home account email and Direct Access on at least one trusted system. Repeated incorrect authenticator codes can lock the account, so stop guessing and use the documented recovery route; support cannot simply remove every lock on request.
Bottom line: manage the relationship, not just the device count
A healthy Sophos Home setup has four aligned records: the owner can recover the account, the intended entitlement is active, every real computer appears once, and billing says exactly what the owner expects. Add Device creates the cleanest ownership path. MFA plus a trusted Direct Access route protects recovery. History provides a useful 90-day window when it is reviewed per computer.
The irreversible mistakes come from crossing layers. Remove does not uninstall. Delete does not cancel. A second key does not extend the first. A mobile app does not consume or appear as a computer. Keep those boundaries visible and the dashboard becomes a workable household console instead of a collection of surprising buttons.