Skip to content

Dropbox access control & privilege security checks

Admin roles, standing privileges, permission scopes and policy enforcement — the settings that decide how much damage one compromised account can do.

On Dropbox, Black Cat runs 10 checks in this area on every scan. Each one below lists its severity, how to fix it, and the compliance controls it satisfies where a control applies. See what access the Dropbox connector needs.

Checks (10)

severity: medium Group Creation Unrestricted fix difficulty: easy #

Restrict Dropbox group creation to administrators only

  1. Sign in to the Dropbox Admin Console as an administrator
  2. Navigate to Admin Console > Settings > Sharing
  3. Under Groups, find the group creation setting
  4. Change the setting to allow only admins to create groups
  5. Save the changes and notify the team of the updated policy

Vendor docs ↗

Satisfies: ISO 27001:2022 A.5.15 SOC 2 Type II CC6.1 CIS Controls v8 CIS-06.1 NIST CSF 2.0 PR.AA-05 GDPR (SaaS Security) GDPR-25.2 HIPAA (SaaS Security) HIPAA-312.a NIS2 Directive NIS2-21.i.1 DORA (SaaS Security) DORA-9.2

severity: high Excessive Admin Users fix difficulty: easy #

Reduce the number of Dropbox admin users to the minimum necessary

  1. Sign in to the Dropbox Admin Console as an administrator
  2. Navigate to Admin Console > Members
  3. Filter by role to identify all admin accounts
  4. Review each admin account and determine if the elevated role is still required
  5. For accounts that no longer need admin access, change the role to a member
  6. Document the justification for any remaining admin accounts

Vendor docs ↗

Satisfies: ISO 27001:2022 A.5.15 SOC 2 Type II CC6.1 CIS Controls v8 CIS-06.1 NIST CSF 2.0 PR.AA-05 GDPR (SaaS Security) GDPR-25.2 HIPAA (SaaS Security) HIPAA-312.a NIS2 Directive NIS2-21.i.1 DORA (SaaS Security) DORA-9.2

severity: medium Inactive Member Account fix difficulty: easy #

Remove or suspend Dropbox member accounts that have been inactive for over 90 days

  1. Sign in to the Dropbox Admin Console as an administrator
  2. Navigate to Admin Console > Members
  3. Sort members by last activity to identify inactive accounts
  4. Verify with the member's manager whether the account is still needed
  5. If the account is no longer needed, select the member and click Remove or Suspend
  6. If the account must remain, document the business justification

Vendor docs ↗

Satisfies: ISO 27001:2022 A.5.15 SOC 2 Type II CC6.1 CIS Controls v8 CIS-06.1 NIST CSF 2.0 PR.AA-05 GDPR (SaaS Security) GDPR-25.2 HIPAA (SaaS Security) HIPAA-312.a NIS2 Directive NIS2-21.i.1 DORA (SaaS Security) DORA-9.2

severity: low Stale Pending Invite fix difficulty: easy #

Revoke or resend Dropbox team invitations that have been pending for over 30 days

  1. Sign in to the Dropbox Admin Console as an administrator
  2. Navigate to Admin Console > Members
  3. Filter members by status to show invited (pending) accounts
  4. Identify invitations older than 30 days
  5. Confirm with the intended recipient whether the invitation is still valid
  6. Revoke stale invitations or resend them if still required

Vendor docs ↗

Satisfies: ISO 27001:2022 A.5.15 SOC 2 Type II CC6.1 CIS Controls v8 CIS-06.1 NIST CSF 2.0 PR.AA-05 GDPR (SaaS Security) GDPR-25.2 HIPAA (SaaS Security) HIPAA-312.a NIS2 Directive NIS2-21.i.1 DORA (SaaS Security) DORA-9.2

severity: medium Email Not Verified fix difficulty: easy #

Ensure all active Dropbox members have verified email addresses

  1. Sign in to the Dropbox Admin Console as an administrator
  2. Navigate to Admin Console > Members
  3. Identify active members with unverified email addresses
  4. Contact the affected members and ask them to verify their email address via the Dropbox verification email
  5. Resend the verification email if needed from the member's account settings
  6. Consider suspending accounts that remain unverified after a reasonable period

Vendor docs ↗

Satisfies: ISO 27001:2022 A.5.15 SOC 2 Type II CC6.1 CIS Controls v8 CIS-06.1 NIST CSF 2.0 PR.AA-05 GDPR (SaaS Security) GDPR-25.2 HIPAA (SaaS Security) HIPAA-312.a NIS2 Directive NIS2-21.i.1 DORA (SaaS Security) DORA-9.2

severity: high Admin Email Not Verified fix difficulty: easy #

Ensure Dropbox admin accounts have verified email addresses to prevent account compromise

  1. Sign in to the Dropbox Admin Console as an administrator
  2. Navigate to Admin Console > Members
  3. Identify admin members with unverified email addresses
  4. Contact the admin and require them to verify their email immediately
  5. Consider temporarily suspending the admin account until verification is complete

Vendor docs ↗

Satisfies: NIS2 Directive NIS2-21.i.1 DORA (SaaS Security) DORA-9.2

severity: medium User-Managed Group fix difficulty: easy #

Convert user-managed Dropbox groups to company-managed to ensure admin oversight of membership

  1. Sign in to the Dropbox Admin Console as an administrator
  2. Navigate to Admin Console > Groups
  3. Locate the user-managed group
  4. Change the group management type to Company managed
  5. Review current group membership for appropriateness

Vendor docs ↗

Satisfies: NIS2 Directive NIS2-21.i.1 DORA (SaaS Security) DORA-9.2

severity: low Stale Mobile Session fix difficulty: easy #

Revoke Dropbox mobile sessions that have been inactive for over 90 days

  1. Sign in to the Dropbox Admin Console as an administrator
  2. Navigate to Admin Console > Members
  3. Select the affected member
  4. Under the Security tab, review active mobile sessions
  5. Revoke any mobile sessions that have been inactive for more than 90 days

Vendor docs ↗

Satisfies: NIS2 Directive NIS2-21.i.1 DORA (SaaS Security) DORA-9.2

severity: medium High Pending Invitation Count fix difficulty: easy #

Review and clean up excessive pending Dropbox team invitations

  1. Sign in to the Dropbox Admin Console as an administrator
  2. Navigate to Admin Console > Members
  3. Filter by pending invitation status
  4. Revoke invitations that are no longer valid
  5. Resend invitations that are still needed

Vendor docs ↗

Satisfies: NIS2 Directive NIS2-21.i.1 DORA (SaaS Security) DORA-9.2

severity: medium Suspended Members Present fix difficulty: easy #

Review suspended Dropbox members and remove them to free licenses and reduce risk

  1. Sign in to the Dropbox Admin Console as an administrator
  2. Navigate to Admin Console > Members
  3. Filter by suspended status
  4. For each suspended member, determine if they should be removed or reactivated
  5. Remove members who no longer need access and transfer their content

Vendor docs ↗

Satisfies: NIS2 Directive NIS2-21.i.1 DORA (SaaS Security) DORA-9.2

More Dropbox checks

The information on this page is provided for general informational purposes and is believed to be accurate as of its most recent update. Product names, logos, and trademarks are the property of their respective owners and are used for identification purposes only; their use does not imply any affiliation with or endorsement by those owners. Descriptions of third-party applications and of compliance frameworks are based on publicly available documentation and may change over time.

See these checks run on your stack

Start a free 14-day trial — no credit card required.

Start Free Trial