Skip to content

DocuSign access control & privilege security checks

Admin roles, standing privileges, permission scopes and policy enforcement — the settings that decide how much damage one compromised account can do.

On DocuSign, Black Cat runs 20 checks in this area on every scan. Each one below lists its severity, how to fix it, and the compliance controls it satisfies where a control applies. See what access the DocuSign connector needs.

Checks (20)

severity: high Weak Password Length fix difficulty: easy #

Increase the minimum password length to at least 12 characters

  1. Sign in to the DocuSign Admin console at admin.docusign.com
  2. Navigate to Security Settings in the left-hand navigation
  3. Select Password Rules under the Security Settings section
  4. Set the Minimum Password Length to 12 or more characters
  5. Click Save to apply the new password policy

Vendor docs ↗

Satisfies: ISO 27001:2022 A.5.15 SOC 2 Type II CC6.1 CIS Controls v8 CIS-06.1 NIST CSF 2.0 PR.AA-05 GDPR (SaaS Security) GDPR-32.1b.i HIPAA (SaaS Security) HIPAA-312.d NIS2 Directive NIS2-21.i.1 DORA (SaaS Security) DORA-9.2

severity: high Weak Password Strength fix difficulty: easy #

Set password strength requirement to Strong in DocuSign password rules

  1. Sign in to the DocuSign Admin console at admin.docusign.com
  2. Navigate to Security Settings in the left-hand navigation
  3. Select Password Rules under the Security Settings section
  4. Set the Password Strength setting to Strong
  5. Click Save to apply the new password policy

Vendor docs ↗

Satisfies: ISO 27001:2022 A.5.15 SOC 2 Type II CC6.1 CIS Controls v8 CIS-06.1 NIST CSF 2.0 PR.AA-05 GDPR (SaaS Security) GDPR-32.1b.i HIPAA (SaaS Security) HIPAA-312.d NIS2 Directive NIS2-21.i.1 DORA (SaaS Security) DORA-9.2

severity: high No Password Expiration fix difficulty: easy #

Enable password expiration and set maximum age to 90 days or fewer

  1. Sign in to the DocuSign Admin console at admin.docusign.com
  2. Navigate to Security Settings in the left-hand navigation
  3. Select Password Rules under the Security Settings section
  4. Enable the Password Expiration toggle
  5. Set the Maximum Password Age to 90 days or fewer
  6. Click Save to apply the new password policy

Vendor docs ↗

Satisfies: ISO 27001:2022 A.5.15 SOC 2 Type II CC6.1 CIS Controls v8 CIS-06.1 NIST CSF 2.0 PR.AA-05 GDPR (SaaS Security) GDPR-25.2 HIPAA (SaaS Security) HIPAA-312.a NIS2 Directive NIS2-21.i.1 DORA (SaaS Security) DORA-9.2

severity: medium No Account Lockout fix difficulty: easy #

Enable account lockout policy with a lockout duration of at least 1 minute

  1. Sign in to the DocuSign Admin console at admin.docusign.com
  2. Navigate to Security Settings in the left-hand navigation
  3. Select Password Rules under the Security Settings section
  4. Enable the Account Lockout toggle
  5. Set a maximum number of failed attempts (e.g. 5) and a lockout duration of at least 1 minute
  6. Click Save to apply the lockout policy

Vendor docs ↗

Satisfies: ISO 27001:2022 A.5.15 SOC 2 Type II CC6.1 CIS Controls v8 CIS-06.1 NIST CSF 2.0 PR.AA-05 GDPR (SaaS Security) GDPR-25.2 HIPAA (SaaS Security) HIPAA-312.a NIS2 Directive NIS2-21.i.1 DORA (SaaS Security) DORA-9.2

severity: medium Long Web Session Timeout fix difficulty: easy #

Reduce web session timeout to 30 minutes or less in Security Settings

  1. Sign in to the DocuSign Admin console at admin.docusign.com
  2. Navigate to Security Settings in the left-hand navigation
  3. Locate the Session Timeout section
  4. Set the Web Session Timeout value to 30 minutes or fewer
  5. Click Save to apply the new session policy

Vendor docs ↗

Satisfies: ISO 27001:2022 A.5.15 SOC 2 Type II CC6.1 CIS Controls v8 CIS-06.1 NIST CSF 2.0 PR.AA-05 GDPR (SaaS Security) GDPR-25.2 HIPAA (SaaS Security) HIPAA-312.a NIS2 Directive NIS2-21.i.1 DORA (SaaS Security) DORA-9.2

severity: medium Long Signing Session Timeout fix difficulty: easy #

Reduce signing session timeout to 30 minutes or less in Security Settings

  1. Sign in to the DocuSign Admin console at admin.docusign.com
  2. Navigate to Security Settings in the left-hand navigation
  3. Locate the Session Timeout section
  4. Set the Signing Session Timeout value to 30 minutes or fewer
  5. Click Save to apply the new session policy

Vendor docs ↗

Satisfies: ISO 27001:2022 A.5.15 SOC 2 Type II CC6.1 CIS Controls v8 CIS-06.1 NIST CSF 2.0 PR.AA-05 GDPR (SaaS Security) GDPR-25.2 HIPAA (SaaS Security) HIPAA-312.a NIS2 Directive NIS2-21.i.1 DORA (SaaS Security) DORA-9.2

severity: medium Long Mobile Session Timeout fix difficulty: easy #

Reduce mobile session timeout to 30 minutes or less in Security Settings

  1. Sign in to the DocuSign Admin console at admin.docusign.com
  2. Navigate to Security Settings in the left-hand navigation
  3. Locate the Session Timeout section
  4. Set the Mobile Session Timeout value to 30 minutes or fewer
  5. Click Save to apply the new session policy

Vendor docs ↗

Satisfies: ISO 27001:2022 A.5.15 SOC 2 Type II CC6.1 CIS Controls v8 CIS-06.1 NIST CSF 2.0 PR.AA-05 GDPR (SaaS Security) GDPR-25.2 HIPAA (SaaS Security) HIPAA-312.a NIS2 Directive NIS2-21.i.1 DORA (SaaS Security) DORA-9.2

severity: high Excessive Admins fix difficulty: medium #

Reduce the number of admin users by reassigning non-essential admins to least-privilege profiles

  1. Sign in to the DocuSign Admin console at admin.docusign.com
  2. Navigate to Users in the left-hand navigation
  3. Filter the user list to show only Administrator permission profile members
  4. Review each admin user and determine whether full administrative access is required
  5. For users who do not require admin access, click their name and change their Permission Profile to a less privileged option
  6. Save changes for each updated user

Vendor docs ↗

Satisfies: ISO 27001:2022 A.5.15 SOC 2 Type II CC6.1 CIS Controls v8 CIS-06.1 NIST CSF 2.0 PR.AA-05 GDPR (SaaS Security) GDPR-25.2 HIPAA (SaaS Security) HIPAA-312.a NIS2 Directive NIS2-21.i.1 DORA (SaaS Security) DORA-9.2

severity: medium Inactive User With Access fix difficulty: easy #

Remove or deactivate inactive users who have not logged in recently

  1. Sign in to the DocuSign Admin console at admin.docusign.com
  2. Navigate to Users in the left-hand navigation
  3. Filter or sort users by Last Login date to identify inactive accounts
  4. For each inactive user, click their name to open the user detail page
  5. Click Close User or change their status to Closed to revoke access
  6. Confirm the action and notify the user's manager if required

Vendor docs ↗

Satisfies: ISO 27001:2022 A.5.15 SOC 2 Type II CC6.1 CIS Controls v8 CIS-06.1 NIST CSF 2.0 PR.AA-05 GDPR (SaaS Security) GDPR-25.2 HIPAA (SaaS Security) HIPAA-308.a3 NIS2 Directive NIS2-21.i.1 DORA (SaaS Security) DORA-9.2

severity: medium Overly Broad Permission Profile fix difficulty: medium #

Create a restricted permission profile without account management for general users

  1. Sign in to the DocuSign Admin console at admin.docusign.com
  2. Navigate to Permission Profiles in the left-hand navigation
  3. Review the existing profiles and identify those with account management capabilities granted to non-admin users
  4. Click Add Permission Profile to create a new restricted profile or clone an existing one
  5. Remove account management permissions from the new profile
  6. Reassign general users from the overly broad profile to the new restricted profile

Vendor docs ↗

Satisfies: ISO 27001:2022 A.5.15 SOC 2 Type II CC6.1 CIS Controls v8 CIS-06.1 NIST CSF 2.0 PR.AA-05 GDPR (SaaS Security) GDPR-25.2 HIPAA (SaaS Security) HIPAA-308.a4 NIS2 Directive NIS2-21.i.1 DORA (SaaS Security) DORA-9.2

severity: low User Without Group fix difficulty: easy #

Assign ungrouped users to appropriate groups for consistent permission management

  1. Sign in to the DocuSign Admin console at admin.docusign.com
  2. Navigate to Users in the left-hand navigation
  3. Filter the user list to identify users who are not members of any group
  4. For each ungrouped user, click their name to open the user detail page
  5. Under Groups, click Add to Group and select the appropriate group
  6. Save the user profile with the updated group membership

Vendor docs ↗

Satisfies: ISO 27001:2022 A.5.15 SOC 2 Type II CC6.1 CIS Controls v8 CIS-06.1 NIST CSF 2.0 PR.AA-05 GDPR (SaaS Security) GDPR-25.2 HIPAA (SaaS Security) HIPAA-312.a NIS2 Directive NIS2-21.i.1 DORA (SaaS Security) DORA-9.2

severity: high No SSO Configured fix difficulty: hard #

Configure SAML or OIDC SSO in DocuSign to enforce centralized authentication

  1. Sign in to the DocuSign Admin console at admin.docusign.com
  2. Navigate to Identity Providers in the left-hand navigation
  3. Click Add Identity Provider and select SAML 2.0 or OIDC as the protocol
  4. Enter the IdP metadata URL or manually configure the SSO endpoints and certificates
  5. Save the identity provider configuration
  6. Test the SSO flow and verify successful authentication before enforcing it for all users

Vendor docs ↗

Satisfies: ISO 27001:2022 A.5.15 SOC 2 Type II CC6.1 CIS Controls v8 CIS-06.1 NIST CSF 2.0 PR.AA-05 GDPR (SaaS Security) GDPR-25.1 HIPAA (SaaS Security) HIPAA-312.d NIS2 Directive NIS2-21.i.1 DORA (SaaS Security) DORA-9.2

severity: high Unclaimed Domain fix difficulty: medium #

Verify and claim your organization's email domain to enforce SSO and prevent unauthorized accounts

  1. Sign in to the DocuSign Admin console at admin.docusign.com
  2. Navigate to Domains in the left-hand navigation
  3. Click Claim a Domain and enter your organization's email domain
  4. Follow the DNS TXT record or HTTP file verification process to prove domain ownership
  5. Once verified, the domain status will change to Claimed
  6. Enable SSO enforcement for the claimed domain to prevent non-SSO account creation

Vendor docs ↗

Satisfies: ISO 27001:2022 A.5.15 SOC 2 Type II CC6.1 CIS Controls v8 CIS-06.1 NIST CSF 2.0 PR.AA-05 GDPR (SaaS Security) GDPR-25.2 HIPAA (SaaS Security) HIPAA-312.a NIS2 Directive NIS2-21.i.1 DORA (SaaS Security) DORA-9.2

severity: high SSO Not Mandatory fix difficulty: medium #

Enforce SSO for all users and enable automatic provisioning via the configured identity provider

  1. Sign in to the DocuSign Admin console at admin.docusign.com
  2. Navigate to Identity Providers in the left-hand navigation
  3. Select the configured identity provider
  4. Enable the Require SSO toggle to make SSO mandatory for all users in the organization
  5. Enable Automatic User Provisioning (JIT or SCIM) if supported by your IdP
  6. Save changes and communicate the enforcement timeline to users

Vendor docs ↗

Satisfies: ISO 27001:2022 A.5.15 SOC 2 Type II CC6.1 CIS Controls v8 CIS-06.1 NIST CSF 2.0 PR.AA-05 GDPR (SaaS Security) GDPR-25.1 HIPAA (SaaS Security) HIPAA-312.a NIS2 Directive NIS2-21.i.1 DORA (SaaS Security) DORA-9.2

severity: low Empty Group fix difficulty: easy #

Remove empty groups that have no members to reduce administrative clutter

  1. Sign in to the DocuSign Admin console at admin.docusign.com
  2. Navigate to Groups in the left-hand navigation
  3. Identify groups with zero members
  4. Verify the group is not required for future onboarding or automation
  5. Delete or archive the empty group

Vendor docs ↗

Satisfies: NIS2 Directive NIS2-21.i.1 DORA (SaaS Security) DORA-9.2

severity: medium Permission Profile Manages Users fix difficulty: medium #

Remove user management permission from profiles that do not require full account administration

  1. Sign in to the DocuSign Admin console at admin.docusign.com
  2. Navigate to Permission Profiles in the left-hand navigation
  3. Select the flagged permission profile
  4. Locate the user management setting and disable it
  5. Save the profile and verify affected users can still perform their required tasks

Vendor docs ↗

Satisfies: NIS2 Directive NIS2-21.i.1 DORA (SaaS Security) DORA-9.2

severity: low Unused Admin Permission Profile fix difficulty: easy #

Remove or disable unused permission profiles that have account management enabled

  1. Sign in to the DocuSign Admin console at admin.docusign.com
  2. Navigate to Permission Profiles in the left-hand navigation
  3. Identify profiles with account management enabled but zero assigned users
  4. Delete the profile if it is no longer needed or document its intended purpose

Vendor docs ↗

Satisfies: NIS2 Directive NIS2-21.i.1 DORA (SaaS Security) DORA-9.2

severity: high Disabled Admin Account fix difficulty: easy #

Remove admin privileges from disabled or closed user accounts

  1. Sign in to the DocuSign Admin console at admin.docusign.com
  2. Navigate to Users in the left-hand navigation
  3. Locate the flagged admin user with closed or disabled status
  4. Change their permission profile to a non-admin profile before removing the account
  5. Delete the user account or confirm it has been fully deprovisioned

Vendor docs ↗

Satisfies: NIS2 Directive NIS2-21.i.1 DORA (SaaS Security) DORA-9.2

severity: medium Domain Not Linked to Identity Provider fix difficulty: medium #

Link the reserved domain to an identity provider to enforce SSO for that domain

  1. Sign in to the DocuSign Admin console at admin.docusign.com
  2. Navigate to Domains in the left-hand navigation
  3. Select the reserved domain that is not linked to an identity provider
  4. Click Link to Identity Provider and select the configured SSO provider
  5. Save changes and verify users with that domain are redirected to SSO on login

Vendor docs ↗

Satisfies: NIS2 Directive NIS2-21.i.1 DORA (SaaS Security) DORA-9.2

severity: medium Password Security Questions Enabled fix difficulty: easy #

Disable security questions as a recovery mechanism in favor of stronger authentication methods

  1. Sign in to the DocuSign Admin console at admin.docusign.com
  2. Navigate to Security Settings or Password Rules in the left-hand navigation
  3. Locate the security questions configuration
  4. Set the number of required security questions to zero
  5. Save changes and ensure password reset flows use email or MFA-based recovery instead

Vendor docs ↗

Satisfies: NIS2 Directive NIS2-21.i.1 DORA (SaaS Security) DORA-9.2

More DocuSign checks

The information on this page is provided for general informational purposes and is believed to be accurate as of its most recent update. Product names, logos, and trademarks are the property of their respective owners and are used for identification purposes only; their use does not imply any affiliation with or endorsement by those owners. Descriptions of third-party applications and of compliance frameworks are based on publicly available documentation and may change over time.

See these checks run on your stack

Start a free 14-day trial — no credit card required.

Start Free Trial