ツール一覧 › Dropbox
Dropbox のアクセス管理機能(SSO・MFA・IP制限・監査ログ)
公式資料によると、Dropbox は MFA・SSO・2FA・監査ログ に対応しています。IP制限 は公式資料に記載がありませんでした。(資料の取得日 2026-10-04)
判定(かんたん基準)
Step1:MFA(0.99) / SSO(1.00) + 監査ログ(1.00)|許可 最終|許可
かんたん基準:Step1 は「MFA か SSO」に対応し、かつ監査ログを取得できれば許可。Step2 は「2FA か IP制限」に対応し、かつ監査ログを取得できれば許可。どちらも満たさなければ、個人情報・取引情報・財務情報・機密情報を扱うかどうかで決まります。括弧内は「対応している」確率です。
項目ごとの読み取り
| 項目 | 公式資料の記載 | 確率 | 根拠 |
|---|---|---|---|
| MFA | 対応と記載 | 0.99 | How to require multi |
| SSO | 対応と記載 | 1.00 | How to enable single sign-on (SSO) for your team |
| 2FA | 対応と記載 | 1.00 | How to require multi |
| IP制限 | 公式資料に記載なし | 0.01 | Network control |
| 監査ログ | 対応と記載 | 1.00 | View team activity in the admin console |
「公式資料に記載なし」は、その要素の公式ページを読んだが記載がなかったもの。「未収集」は、公式ページをまだ見つけられていないもの(機能がないという意味ではありません)。
根拠(公式資料の原文)
SSO:How to enable single sign-on (SSO) for your team - Dropbox Help
https://help.dropbox.com/security/sso-admin
How to enable single sign-on (SSO) for your team - Dropbox Help
How to enable single sign-on for your team
Admins Updated Feb 13, 2026
続きを読む(ほか 52 段落)
In this article
The information in this article applies to certain types of admins on Dropbox Advanced, Business Plus, and Enterprise.
If you're an admin of a Dropbox team on Advanced, Business Plus, or Enterprise, you can turn on single sign-on (SSO) for your team. Single sign-on lets team members access Dropbox by logging in to a central identity provider, so they don't need a separate password.
How to turn on single sign-on
Go to your identity provider's site and follow the instructions to set up single sign-on.
Many identity providers offer preconfigured settings for Dropbox. If your identity provider isn't supported, you can configure your own identity provider solution for SSO.
Download a copy of the X.509 certificate and make a note of the log in URL, you’ll need both later.
Log in to dropbox.com using your admin credentials.
Click Admin console in the left sidebar.
Under Team, click Settings.
Click the Security tab.
Under Authentication, click the dropdown next to Single sign-on (SSO) and select either:
Optional (for testing): Your team can log in to Dropbox using SSO or their Dropbox password.
Required (for production): Team members must log in to Dropbox using SSO, and their Dropbox password will no longer work. Admins can still use their Dropbox admin credentials to log in.
Note: To turn off single sign-on, click the dropdown next to Single-sign on (SSO) and select Off.
Click Add next to Identity provider sign-in URL, enter the copied login URL, then click Done.
Click Add next to X.509 certificate.
Select your X.509 certificate from your hard drive and click Upload.
After you turn on single sign-on, you can share these instructions for the rest of your team.
All devices that are linked to Dropbox accounts will continue to work. Admins can't reset passwords through Dropbox or require two-factor authentication since passwords and log in-related security are now managed by your identity provider.
How to find your team’s custom SSO sign-in URL
If team members have already logged in to your identity provider, they can go directly to their Dropbox account using the custom link.
To find your team’s custom SSO sign-in URL:
Click Settings.
Under Authentication, go to SSO sign-in URL and click Copy link.
Seeing a SAML assertion error when you log in?
Learn how to resolve the error message: “Could not validate SAML assertion.”
Was this article helpful?
Let us know how why it didn't help:
Thanks for letting us know!
The article didn't answer my question
The steps in the article didn't work for me
I found this article confusing and difficult to read
Please enter feedback before submitting.
Submit feedback
Thanks for your feedback!
Related Articles
Change admin rights
Customize Dropbox team security settings
Data classification
Dropbox Paper: admin settings for Dropbox teams
Community answers
Dropbox Backup won't restore or download and no option to copy Dropbox Backup to regular Dropbox
Posted by: Liberty1991
2025, LET'S GO 🚀!
Posted by: Theresa
How Do You Enable Two-Step Verification on Your Dropbox Account?
Can't link Team Account with Personal (Basic) Account
Posted by: piecheck
Other ways to get help
Contact support
Social media support
MFA:How to require multi-factor authentication for Dropbox teams
https://help.dropbox.com/security/two-step-verification
How to require two-factor authentication for teams - Dropbox Help
How to require two-factor authentication for Dropbox teams
Admins Updated Aug 13, 2025
続きを読む(ほか 53 段落)
In this article
The information in this article applies to admins on Dropbox team accounts.
Two-factor authentication adds an extra layer of protection to your team’s Dropbox accounts, making it much harder for anyone else to access an account, even if they know the password.
Dropbox team admins can require all or some team members to use two-factor authentication. You can do this through the admin console or through your identity management provider if you use single sign-on (SSO).
Note: Each team member must enable two-factor authentication on their own account.
How to require two-factor authentication for team member
Log in to dropbox.com with your admin credentials.
Click Admin console in the left sidebar.
Click Settings.
Click the Security tab.
Under Authentication, select Required from the dropdown next to 2-step verification.
Note: Team members won't be protected until they set up two-factor authentication.
How will required two-factor authentication affect my team?
Newly invited members will be required to enable two-factor authentication after accepting the invitation to join your team.
Existing members will be required to enable two-factor authentication the next time they log in. Requiring two-factor authentication won't log your team member out of their devices or web sessions, and won't interrupt their workflow. Existing team members who try to connect a new computer or mobile device as their first log-in after two-factor authentication is enabled will be directed to the Dropbox website to log in (and set up two-factor authentication).
What will a team member see when setting up two-factor authentication?
When team members log in to Dropbox, they will see a Get Started prompt.
Team members can choose to receive verification codes via text message, or to use an authenticator app, and then click Send code.
Team members will next be required to verify that two-factor authentication is working— they will receive a text message to the phone number entered, or else need to enter the two-factor authentication code generated via the authenticator app.
Lastly, team members will receive an emergency backup code, which can be used if they ever lose their mobile phone.
Alternatively, team admins can reset two-factor authentication for team members as needed
Click Turn on 2-factor authentication.
How to add users to the exception list
If you require two-factor authentication for your team, but want to exclude certain members, you can add them to the exception list.
Click Add to the right of Exceptions.
Enter the emails or names of users you’d like to add.
Was this article helpful?
Let us know how why it didn't help:
Thanks for letting us know!
The article didn't answer my question
The steps in the article didn't work for me
I found this article confusing and difficult to read
Please enter feedback before submitting.
Submit feedback
Thanks for your feedback!
Related Articles
Change admin rights
Customize Dropbox team security settings
Data classification
Dropbox Paper: admin settings for Dropbox teams
Community answers
Active account disabled with no warning, all my work files are locked inside
Posted by: beguido_backup
Is there a place where I can access the login history for my account?
Posted by: DiagramUser
Two-factor authentication methods used on my account are no longer accessible and I can't sign in
Posted by: bridgette1
My password was changed by someone else. What are the next steps?
Posted by: mathetesbl
[tips] 3 easy ways to protect your company's data
Other ways to get help
Contact support
Social media support
2FA:How to require multi-factor authentication for Dropbox teams
https://help.dropbox.com/security/two-step-verification
How to require two-factor authentication for teams - Dropbox Help
How to require two-factor authentication for Dropbox teams
Admins Updated Aug 13, 2025
続きを読む(ほか 53 段落)
In this article
The information in this article applies to admins on Dropbox team accounts.
Two-factor authentication adds an extra layer of protection to your team’s Dropbox accounts, making it much harder for anyone else to access an account, even if they know the password.
Dropbox team admins can require all or some team members to use two-factor authentication. You can do this through the admin console or through your identity management provider if you use single sign-on (SSO).
Note: Each team member must enable two-factor authentication on their own account.
How to require two-factor authentication for team member
Log in to dropbox.com with your admin credentials.
Click Admin console in the left sidebar.
Click Settings.
Click the Security tab.
Under Authentication, select Required from the dropdown next to 2-step verification.
Note: Team members won't be protected until they set up two-factor authentication.
How will required two-factor authentication affect my team?
Newly invited members will be required to enable two-factor authentication after accepting the invitation to join your team.
Existing members will be required to enable two-factor authentication the next time they log in. Requiring two-factor authentication won't log your team member out of their devices or web sessions, and won't interrupt their workflow. Existing team members who try to connect a new computer or mobile device as their first log-in after two-factor authentication is enabled will be directed to the Dropbox website to log in (and set up two-factor authentication).
What will a team member see when setting up two-factor authentication?
When team members log in to Dropbox, they will see a Get Started prompt.
Team members can choose to receive verification codes via text message, or to use an authenticator app, and then click Send code.
Team members will next be required to verify that two-factor authentication is working— they will receive a text message to the phone number entered, or else need to enter the two-factor authentication code generated via the authenticator app.
Lastly, team members will receive an emergency backup code, which can be used if they ever lose their mobile phone.
Alternatively, team admins can reset two-factor authentication for team members as needed
Click Turn on 2-factor authentication.
How to add users to the exception list
If you require two-factor authentication for your team, but want to exclude certain members, you can add them to the exception list.
Click Add to the right of Exceptions.
Enter the emails or names of users you’d like to add.
Was this article helpful?
Let us know how why it didn't help:
Thanks for letting us know!
The article didn't answer my question
The steps in the article didn't work for me
I found this article confusing and difficult to read
Please enter feedback before submitting.
Submit feedback
Thanks for your feedback!
Related Articles
Change admin rights
Customize Dropbox team security settings
Data classification
Dropbox Paper: admin settings for Dropbox teams
Community answers
Active account disabled with no warning, all my work files are locked inside
Posted by: beguido_backup
Is there a place where I can access the login history for my account?
Posted by: DiagramUser
Two-factor authentication methods used on my account are no longer accessible and I can't sign in
Posted by: bridgette1
My password was changed by someone else. What are the next steps?
Posted by: mathetesbl
[tips] 3 easy ways to protect your company's data
Other ways to get help
Contact support
Social media support
IP制限:Network control - Dropbox Help
https://help.dropbox.com/security/network-control
Network control - Dropbox Help
Network control
Admins Updated Aug 13, 2025
続きを読む(ほか 55 段落)
In this article
This article discusses a feature that is only available to customers on Dropbox Enterprise.
Network control is a security and access feature available to customers on Dropbox Enterprise. With this feature, IT admins can manage which Dropbox accounts can be used on their corporate network. Using your proxy or CASB vendor, you can specify which team member accounts can log in and sync via dropbox.com or the Dropbox desktop app.
Who can use network control?
Network control is available exclusively to Enterprise teams. Admins can set up network control to help manage how members of their team access Dropbox.
How do I get started with network control?
To set up network control, contact the Dropbox account manager for your Enterprise account. They can give you early access to this feature and detailed instructions regarding the setup.
Once the Dropbox account manager for your Enterprise account has given you early access, follow these instructions to get started:
Log in to dropbox.com with your admin credentials.
Click Admin console in the left sidebar.
Click Settings.
Click the Security tab.
Under Network control, toggle the Restricted Dropbox traffic toggle to On.
Configure your proxy or CASB vendor to add a custom HTTP header to Dropbox traffic from your web browser and desktop client.
Learn more about the domains that Dropbox uses in an official capacity.
Dropbox will now block traffic that's not associated with the correct Enterprise team.
Note: If the Dropbox desktop app doesn’t automatically update after enabling network control, add the following registry key with any value [HKLM\SOFTWARE\Dropbox\IgnoreUnknownRevocationErrors]. This registry key only works if network control is already enabled.
Who are your network control providers?
While there are many preferred proxy or cloud access security broker (CASB) providers, we’ve confirmed that the following will support Dropbox at this time:
Cisco Web Security Appliance
Blue Coat Systems - ProxySG
Intel Security / McAfee
Skyhigh Networks
Symantec CloudSOC CASB
What should I do if I can't use Dropbox on my network?
If you’re a member of an Enterprise team and you're having trouble accessing Dropbox, contact your company's IT help.
If you're not a member of an Enterprise team and you see the error ”Your company now manages Dropbox traffic”, contact Dropbox support.
Was this article helpful?
Let us know how why it didn't help:
Thanks for letting us know!
The article didn't answer my question
The steps in the article didn't work for me
I found this article confusing and difficult to read
Please enter feedback before submitting.
Submit feedback
Thanks for your feedback!
Related Articles
Change admin rights
Customize Dropbox team security settings
Data classification
Dropbox Paper: admin settings for Dropbox teams
Community answers
Accessing the Dropbox site disables my internet connection
Posted by: Jack420
Dropbox Tenancy Header Insertion
Posted by: npaul
Can new files in a network folder automatically update and sync to other devices with Dropbox?
Posted by: Mark_Royle
Dropbox upload on a device only with max 600kb/s. (Upload)
Posted by: Skyfay
Re-linking using Obj-C SDK fails with network error
Posted by: Mark R.5
Other ways to get help
Contact support
Social media support
監査ログ:View team activity in the admin console - Dropbox Help
https://help.dropbox.com/account-access/view-activity
View team activity in the admin console - Dropbox Help
View team activity in the admin console
The information in this article applies to certain types of admins on Dropbox Standard, Business, Advanced, Business Plus, and Enterprise.
続きを読む(ほか 57 段落)
The following activities are logged: Signed in, Linked app for member, and Created shared link.
The following activities are not logged: Deleted a screenshot, Deleted a recording, Made a Comment, Deleted a comment, and Trimmed a Recording.
Activities performed during a Microsoft co-authoring session won't be recorded in team activity logs.
Third-party integration activity in Sign won’t be tracked in your Dropbox team’s activity log.
Learn more about the features of the admin dashboard.
For more detailed insights, the Activity section of the admin console shows specific team activity and lets you generate reports based on that data.
View team activity
To view your team’s activity:
Log in to dropbox.com using your admin credentials.
Click Admin console in the left sidebar.
Click Activity in the left sidebar.
Under Products, click the dropdown to the left of Dropbox.
Click Security.
Click the Activity filter.
Filter results to view the activity you’d like to see. You can filter by Date, Activities, People, Participants, and Content type.
To view activity for a specific time period, enter a start and end date under Date.
To filter by activities, click Activities.
To view recent activity of a specific team member or multiple team members, click People, then enter the name(s).
To find files, folders, or Paper docs, click the search field below Content and type in a keyword.
Usage data is available, beginning January 2017 or when your team began using Dropbox.
You may see a "processing" message when trying to view dates for which we're still processing the data.
If you’d like to see more detailed activity on your team, you can also view team sharing activity.
File types that preview as a link
If your saved website has one of the following extensions, it will preview as a shortcut to the website.
Create and export an activity report
To create and export an activity report:
Use the filters to select the type of data and the time period you’d like to export.
Click Create report to the right of your filters.
Select the report type you want to generate.
Click Generate.
The report will be saved as a CSV in a folder named Dropbox Business reports. You’ll receive an email when the report is ready.
What can I see in activity reports?
Each entry in the activity report shows:
Date: The exact date that an action took place
Member: The member that initiated the action
Activity: Details of the event itself
Content: The type of file
Generally, a team member's actions appear in activity logs in a few hours. At most, actions appear within 24 hours.
Admins have the following events available in their team activity reports:
File operations (Dropbox Business Plus, Advanced and Enterprise only)
Signature activity†
Two-factor authentication
*These events are only available to customers on Dropbox Business and Business Plus.
†These events are only available to customers on a paid Dropbox Sign plan or Dropbox Standard, Advanced, Business, or Business Plus.
As a team admin, you'll see events for files owned by your team and files shared with your team members. If you're a team admin on a Dropbox Business Plus, Advanced, or Enterprise account, you'll also see file-level activity including adding, editing, moving, and deleting files.
You can use these events to investigate and troubleshoot problems, such as accidental file deletions, misplaced files or folders, or information security audits.
Replay in the activity report
The report now allows admins to review their team’s Replay activity, including:
When a team member logs in to Replay for the first time or connects their Dropbox account to Replay
When a team member uploads a file to Replay, including the file name and the uploader
When a team member deletes a file, including the file name and who deleted it
Any changes to team policies for Replay content
When links are created or modified for files in Replay, including:
What file it links to
Why do I see "Dropbox" in the Name column?
A team member deleted a nested shared folder
When a team member deletes a nested shared folder, the name of the person who deleted it appears as “Dropbox.” Certain types of admins can see the name of the team member by following these steps: