Sophos Enterprise Console – You must be a member of at least one sub-estate to run this console

Recently I have been doing a lot of movements of server roles, one of those was changing our DCs to newer servers that will be pure best practice based (nothing else on them other than AD/DNS/File Storage). One of the old server however had the Sophos Enterprise Console (v4.7 for anyone who is keeping count) on and after removing AD DS from the server I was getting the following error when trying to get to the Sophos Enterprise Console-

Cannot open Sophos Enterprise Console

The user “DOMAIN\Administrator” is not assigned to any sub-estates. You must be a member of at least one sub-estate to run this console.

Contact your Administrator to resolve this issue.

Upon inspection (in Server Manager > Configuration > Local Users and Groups) it appeared that the user group Sophos Full Administrators no longer existed.

The simple solution is to create a new group (called Sophos Full Administrators) and assign your Administrative account to it, the screen shots below show this in a little more detail.

0
Be the first one to like this.
Please wait...

3 comments

  1. Thank you, sir. This helped me after a recent Sophos upgrade.

    No votes yet.
    Please wait...
  2. had previously ran some Windows updates, don’t know what caused the permission change but when I added the “Sophos Full Administrators” to Domain Admins everything worked again. Thanks for your posting!!!

    No votes yet.
    Please wait...
  3. https://www.sophos.com/en-us/support/knowledgebase/14509.aspx

    this was more comprehensive for me, and it worked.

    No votes yet.
    Please wait...

Leave a Reply to csa Cancel reply

Your email address will not be published. Required fields are marked *