The 24 Dropbox security checks Black Cat runs
Black Cat SSPM evaluates 24 security policies against your Dropbox configuration on every scan, classifies each finding by risk, and provides remediation steps. Browse them by topic below.
How to connect Dropbox — what access Black Cat needs, and why.
Identity, MFA & sign-in
4 checks · highest severity: high
Access control & privilege
10 checks · highest severity: high
Data sharing & exposure
5 checks · highest severity: high
Identity, MFA & sign-in (4)
- EMM Not Required severity: high
- Stale Web Session severity: low
- Stale Desktop Session severity: low
- Excessive Device Sessions severity: medium
Access control & privilege (10)
- Group Creation Unrestricted severity: medium
- Excessive Admin Users severity: high
- Inactive Member Account severity: medium
- Stale Pending Invite severity: low
- Email Not Verified severity: medium
- Admin Email Not Verified severity: high
- User-Managed Group severity: medium
- Stale Mobile Session severity: low
- High Pending Invitation Count severity: medium
- Suspended Members Present severity: medium
Data sharing & exposure (5)
- External Folder Join Unrestricted severity: medium
- Folder Link Restriction Not Enforced severity: medium
- Suggest Members Enabled severity: medium
Other checks (5)
severity: info Office Add-in Disabled fix difficulty: easy #
Enable the Dropbox Office Add-in to allow users to save Microsoft Office files directly to Dropbox
- Sign in to the Dropbox Admin Console as an administrator
- Navigate to Admin Console > Settings > Integrations
- Locate the Microsoft Office Add-in setting
- Enable the Office Add-in for the team
- Notify users that they can now install and use the Dropbox for Office add-in
Satisfies: ISO 27001:2022 A.8.9 SOC 2 Type II CC7.2 CIS Controls v8 CIS-08 NIST CSF 2.0 DE.CM GDPR (SaaS Security) GDPR-32.1d HIPAA (SaaS Security) HIPAA-312.b NIS2 Directive NIS2-21.b.2 DORA (SaaS Security) DORA-10.1
severity: low Suspended Member Not Removed fix difficulty: easy #
Remove suspended Dropbox member accounts to free licenses and prevent accidental reactivation
- Sign in to the Dropbox Admin Console as an administrator
- Navigate to Admin Console > Members
- Filter by suspended status to identify affected accounts
- For each suspended account, confirm the member no longer requires access
- Click the member and select Remove from team
- Transfer any team-owned content to an active member before removal
Satisfies: ISO 27001:2022 A.8.9 SOC 2 Type II CC7.2 CIS Controls v8 CIS-08 NIST CSF 2.0 DE.CM GDPR (SaaS Security) GDPR-32.1d HIPAA (SaaS Security) HIPAA-312.b NIS2 Directive NIS2-21.b.2 DORA (SaaS Security) DORA-10.1
severity: low Empty Group fix difficulty: easy #
Remove empty Dropbox groups that have no members to reduce clutter
- Sign in to the Dropbox Admin Console as an administrator
- Navigate to Admin Console > Groups
- Identify groups with zero members
- Verify the group is no longer needed
- Delete the empty group
Satisfies: NIS2 Directive NIS2-21.e.4 DORA (SaaS Security) DORA-9.10
severity: low Archived Team Folder fix difficulty: easy #
Review archived Dropbox team folders and permanently delete them if no longer needed
- Sign in to the Dropbox Admin Console as an administrator
- Navigate to Admin Console > Team folders
- Identify archived team folders
- Verify with folder owners whether the data is still needed
- Permanently delete archived folders that are no longer required
Satisfies: NIS2 Directive NIS2-21.e.4 DORA (SaaS Security) DORA-9.10
severity: medium Connected App with Full Dropbox Access fix difficulty: medium #
Review and revoke Dropbox connected apps that have full account access instead of a sandboxed app folder
- Sign in to the Dropbox Admin Console as an administrator
- Navigate to Admin Console > Connected apps
- Locate the flagged application
- Review the app's permissions and whether full access is justified
- If the app does not require full access, revoke it and ask the user to reconnect with a scoped version
- If full access is required, document the justification
Satisfies: ISO 27001:2022 A.5.23 CIS Controls v8 CIS-15.1 NIST CSF 2.0 GV.SC GDPR (SaaS Security) GDPR-28.1 HIPAA (SaaS Security) HIPAA-314.a NIS2 Directive NIS2-21.d DORA (SaaS Security) DORA-28.4