Dropbox identity, MFA & sign-in security checks
Who can sign in, how strongly they authenticate, and whether sessions, passwords and sign-in locations meet the baseline every admin account should clear.
On Dropbox, Black Cat runs 4 checks in this area on every scan. Each one below lists its severity, how to fix it, and the compliance controls it satisfies where a control applies. See what access the Dropbox connector needs.
Checks (4)
severity: high EMM Not Required fix difficulty: hard #
Enable and enforce Enterprise Mobility Management (EMM) to ensure only managed devices access Dropbox
- Sign in to the Dropbox Admin Console as an administrator
- Navigate to Admin Console > Settings > Device approvals
- Enable the EMM setting and set it to required
- Configure your MDM solution to enroll team devices
- Communicate the new device requirement to all team members
- Set a grace period for enrollment before enforcement begins
Satisfies: ISO 27001:2022 A.5.15 SOC 2 Type II CC6.1 CIS Controls v8 CIS-06.1 NIST CSF 2.0 PR.AA-05 GDPR (SaaS Security) GDPR-25.2 HIPAA (SaaS Security) HIPAA-312.a NIS2 Directive NIS2-21.i.6 DORA (SaaS Security) DORA-9.13
severity: low Stale Web Session fix difficulty: easy #
Revoke Dropbox web sessions that have been inactive for over 30 days
- Sign in to the Dropbox Admin Console as an administrator
- Navigate to Admin Console > Members
- Select the affected member
- Under the Security tab, review active web sessions
- Revoke any sessions that have been inactive for more than 30 days
- Consider enabling automatic session expiry for the team
Satisfies: ISO 27001:2022 A.5.15 SOC 2 Type II CC6.1 CIS Controls v8 CIS-06.1 NIST CSF 2.0 PR.AA-05 GDPR (SaaS Security) GDPR-25.2 HIPAA (SaaS Security) HIPAA-312.a NIS2 Directive NIS2-21.i.6 DORA (SaaS Security) DORA-9.13
severity: low Stale Desktop Session fix difficulty: easy #
Revoke Dropbox desktop client sessions that have been inactive for over 90 days
- Sign in to the Dropbox Admin Console as an administrator
- Navigate to Admin Console > Members
- Select the affected member
- Under the Security tab, review active desktop client sessions
- Revoke any desktop sessions that have been inactive for more than 90 days
- Ask the member to re-authenticate on actively used devices
Satisfies: ISO 27001:2022 A.5.15 SOC 2 Type II CC6.1 CIS Controls v8 CIS-06.1 NIST CSF 2.0 PR.AA-05 GDPR (SaaS Security) GDPR-25.2 HIPAA (SaaS Security) HIPAA-312.a NIS2 Directive NIS2-21.i.6 DORA (SaaS Security) DORA-9.13
severity: medium Excessive Device Sessions fix difficulty: easy #
Revoke excess Dropbox device sessions for members with more than the recommended maximum
- Sign in to the Dropbox Admin Console as an administrator
- Navigate to Admin Console > Members
- Select the affected member
- Under the Security tab, review all active device sessions
- Identify and revoke sessions for devices the member no longer uses
- Consider enabling device approval limits for the team
Satisfies: ISO 27001:2022 A.5.15 SOC 2 Type II CC6.1 CIS Controls v8 CIS-06.1 NIST CSF 2.0 PR.AA-05 GDPR (SaaS Security) GDPR-25.2 HIPAA (SaaS Security) HIPAA-312.a NIS2 Directive NIS2-21.i.6 DORA (SaaS Security) DORA-9.13