Dropbox access control & privilege security checks
Admin roles, standing privileges, permission scopes and policy enforcement — the settings that decide how much damage one compromised account can do.
On Dropbox, Black Cat runs 10 checks in this area on every scan. Each one below lists its severity, how to fix it, and the compliance controls it satisfies where a control applies. See what access the Dropbox connector needs.
Checks (10)
severity: medium Group Creation Unrestricted fix difficulty: easy #
Restrict Dropbox group creation to administrators only
- Sign in to the Dropbox Admin Console as an administrator
- Navigate to Admin Console > Settings > Sharing
- Under Groups, find the group creation setting
- Change the setting to allow only admins to create groups
- Save the changes and notify the team of the updated policy
Satisfies: ISO 27001:2022 A.5.15 SOC 2 Type II CC6.1 CIS Controls v8 CIS-06.1 NIST CSF 2.0 PR.AA-05 GDPR (SaaS Security) GDPR-25.2 HIPAA (SaaS Security) HIPAA-312.a NIS2 Directive NIS2-21.i.1 DORA (SaaS Security) DORA-9.2
severity: high Excessive Admin Users fix difficulty: easy #
Reduce the number of Dropbox admin users to the minimum necessary
- Sign in to the Dropbox Admin Console as an administrator
- Navigate to Admin Console > Members
- Filter by role to identify all admin accounts
- Review each admin account and determine if the elevated role is still required
- For accounts that no longer need admin access, change the role to a member
- Document the justification for any remaining admin accounts
Satisfies: ISO 27001:2022 A.5.15 SOC 2 Type II CC6.1 CIS Controls v8 CIS-06.1 NIST CSF 2.0 PR.AA-05 GDPR (SaaS Security) GDPR-25.2 HIPAA (SaaS Security) HIPAA-312.a NIS2 Directive NIS2-21.i.1 DORA (SaaS Security) DORA-9.2
severity: medium Inactive Member Account fix difficulty: easy #
Remove or suspend Dropbox member accounts that have been inactive for over 90 days
- Sign in to the Dropbox Admin Console as an administrator
- Navigate to Admin Console > Members
- Sort members by last activity to identify inactive accounts
- Verify with the member's manager whether the account is still needed
- If the account is no longer needed, select the member and click Remove or Suspend
- If the account must remain, document the business justification
Satisfies: ISO 27001:2022 A.5.15 SOC 2 Type II CC6.1 CIS Controls v8 CIS-06.1 NIST CSF 2.0 PR.AA-05 GDPR (SaaS Security) GDPR-25.2 HIPAA (SaaS Security) HIPAA-312.a NIS2 Directive NIS2-21.i.1 DORA (SaaS Security) DORA-9.2
severity: low Stale Pending Invite fix difficulty: easy #
Revoke or resend Dropbox team invitations that have been pending for over 30 days
- Sign in to the Dropbox Admin Console as an administrator
- Navigate to Admin Console > Members
- Filter members by status to show invited (pending) accounts
- Identify invitations older than 30 days
- Confirm with the intended recipient whether the invitation is still valid
- Revoke stale invitations or resend them if still required
Satisfies: ISO 27001:2022 A.5.15 SOC 2 Type II CC6.1 CIS Controls v8 CIS-06.1 NIST CSF 2.0 PR.AA-05 GDPR (SaaS Security) GDPR-25.2 HIPAA (SaaS Security) HIPAA-312.a NIS2 Directive NIS2-21.i.1 DORA (SaaS Security) DORA-9.2
severity: medium Email Not Verified fix difficulty: easy #
Ensure all active Dropbox members have verified email addresses
- Sign in to the Dropbox Admin Console as an administrator
- Navigate to Admin Console > Members
- Identify active members with unverified email addresses
- Contact the affected members and ask them to verify their email address via the Dropbox verification email
- Resend the verification email if needed from the member's account settings
- Consider suspending accounts that remain unverified after a reasonable period
Satisfies: ISO 27001:2022 A.5.15 SOC 2 Type II CC6.1 CIS Controls v8 CIS-06.1 NIST CSF 2.0 PR.AA-05 GDPR (SaaS Security) GDPR-25.2 HIPAA (SaaS Security) HIPAA-312.a NIS2 Directive NIS2-21.i.1 DORA (SaaS Security) DORA-9.2
severity: high Admin Email Not Verified fix difficulty: easy #
Ensure Dropbox admin accounts have verified email addresses to prevent account compromise
- Sign in to the Dropbox Admin Console as an administrator
- Navigate to Admin Console > Members
- Identify admin members with unverified email addresses
- Contact the admin and require them to verify their email immediately
- Consider temporarily suspending the admin account until verification is complete
Satisfies: NIS2 Directive NIS2-21.i.1 DORA (SaaS Security) DORA-9.2
severity: medium User-Managed Group fix difficulty: easy #
Convert user-managed Dropbox groups to company-managed to ensure admin oversight of membership
- Sign in to the Dropbox Admin Console as an administrator
- Navigate to Admin Console > Groups
- Locate the user-managed group
- Change the group management type to Company managed
- Review current group membership for appropriateness
Satisfies: NIS2 Directive NIS2-21.i.1 DORA (SaaS Security) DORA-9.2
severity: low Stale Mobile Session fix difficulty: easy #
Revoke Dropbox mobile sessions that have been inactive for over 90 days
- Sign in to the Dropbox Admin Console as an administrator
- Navigate to Admin Console > Members
- Select the affected member
- Under the Security tab, review active mobile sessions
- Revoke any mobile sessions that have been inactive for more than 90 days
Satisfies: NIS2 Directive NIS2-21.i.1 DORA (SaaS Security) DORA-9.2
severity: medium High Pending Invitation Count fix difficulty: easy #
Review and clean up excessive pending Dropbox team invitations
- Sign in to the Dropbox Admin Console as an administrator
- Navigate to Admin Console > Members
- Filter by pending invitation status
- Revoke invitations that are no longer valid
- Resend invitations that are still needed
Satisfies: NIS2 Directive NIS2-21.i.1 DORA (SaaS Security) DORA-9.2
severity: medium Suspended Members Present fix difficulty: easy #
Review suspended Dropbox members and remove them to free licenses and reduce risk
- Sign in to the Dropbox Admin Console as an administrator
- Navigate to Admin Console > Members
- Filter by suspended status
- For each suspended member, determine if they should be removed or reactivated
- Remove members who no longer need access and transfer their content
Satisfies: NIS2 Directive NIS2-21.i.1 DORA (SaaS Security) DORA-9.2