Skip to content

Dropbox identity, MFA & sign-in security checks

Who can sign in, how strongly they authenticate, and whether sessions, passwords and sign-in locations meet the baseline every admin account should clear.

On Dropbox, Black Cat runs 4 checks in this area on every scan. Each one below lists its severity, how to fix it, and the compliance controls it satisfies where a control applies. See what access the Dropbox connector needs.

Checks (4)

severity: high EMM Not Required fix difficulty: hard #

Enable and enforce Enterprise Mobility Management (EMM) to ensure only managed devices access Dropbox

  1. Sign in to the Dropbox Admin Console as an administrator
  2. Navigate to Admin Console > Settings > Device approvals
  3. Enable the EMM setting and set it to required
  4. Configure your MDM solution to enroll team devices
  5. Communicate the new device requirement to all team members
  6. Set a grace period for enrollment before enforcement begins

Vendor docs ↗

Satisfies: ISO 27001:2022 A.5.15 SOC 2 Type II CC6.1 CIS Controls v8 CIS-06.1 NIST CSF 2.0 PR.AA-05 GDPR (SaaS Security) GDPR-25.2 HIPAA (SaaS Security) HIPAA-312.a NIS2 Directive NIS2-21.i.6 DORA (SaaS Security) DORA-9.13

severity: low Stale Web Session fix difficulty: easy #

Revoke Dropbox web sessions that have been inactive for over 30 days

  1. Sign in to the Dropbox Admin Console as an administrator
  2. Navigate to Admin Console > Members
  3. Select the affected member
  4. Under the Security tab, review active web sessions
  5. Revoke any sessions that have been inactive for more than 30 days
  6. Consider enabling automatic session expiry for the team

Vendor docs ↗

Satisfies: ISO 27001:2022 A.5.15 SOC 2 Type II CC6.1 CIS Controls v8 CIS-06.1 NIST CSF 2.0 PR.AA-05 GDPR (SaaS Security) GDPR-25.2 HIPAA (SaaS Security) HIPAA-312.a NIS2 Directive NIS2-21.i.6 DORA (SaaS Security) DORA-9.13

severity: low Stale Desktop Session fix difficulty: easy #

Revoke Dropbox desktop client sessions that have been inactive for over 90 days

  1. Sign in to the Dropbox Admin Console as an administrator
  2. Navigate to Admin Console > Members
  3. Select the affected member
  4. Under the Security tab, review active desktop client sessions
  5. Revoke any desktop sessions that have been inactive for more than 90 days
  6. Ask the member to re-authenticate on actively used devices

Vendor docs ↗

Satisfies: ISO 27001:2022 A.5.15 SOC 2 Type II CC6.1 CIS Controls v8 CIS-06.1 NIST CSF 2.0 PR.AA-05 GDPR (SaaS Security) GDPR-25.2 HIPAA (SaaS Security) HIPAA-312.a NIS2 Directive NIS2-21.i.6 DORA (SaaS Security) DORA-9.13

severity: medium Excessive Device Sessions fix difficulty: easy #

Revoke excess Dropbox device sessions for members with more than the recommended maximum

  1. Sign in to the Dropbox Admin Console as an administrator
  2. Navigate to Admin Console > Members
  3. Select the affected member
  4. Under the Security tab, review all active device sessions
  5. Identify and revoke sessions for devices the member no longer uses
  6. Consider enabling device approval limits for the team

Vendor docs ↗

Satisfies: ISO 27001:2022 A.5.15 SOC 2 Type II CC6.1 CIS Controls v8 CIS-06.1 NIST CSF 2.0 PR.AA-05 GDPR (SaaS Security) GDPR-25.2 HIPAA (SaaS Security) HIPAA-312.a NIS2 Directive NIS2-21.i.6 DORA (SaaS Security) DORA-9.13

More Dropbox checks

The information on this page is provided for general informational purposes and is believed to be accurate as of its most recent update. Product names, logos, and trademarks are the property of their respective owners and are used for identification purposes only; their use does not imply any affiliation with or endorsement by those owners. Descriptions of third-party applications and of compliance frameworks are based on publicly available documentation and may change over time.

See these checks run on your stack

Start a free 14-day trial — no credit card required.

Start Free Trial