SaaS ITGC チェック

ツール一覧 › Dropbox

Dropbox のアクセス管理機能(SSO・MFA・IP制限・監査ログ)

公式資料によると、Dropbox は MFA・SSO・2FA・監査ログ に対応しています。IP制限 は公式資料に記載がありませんでした。(資料の取得日 2026-10-04)

判定(かんたん基準)

Step1:MFA(0.99) / SSO(1.00) + 監査ログ(1.00)|許可
最終|許可

かんたん基準:Step1 は「MFA か SSO」に対応し、かつ監査ログを取得できれば許可。Step2 は「2FA か IP制限」に対応し、かつ監査ログを取得できれば許可。どちらも満たさなければ、個人情報・取引情報・財務情報・機密情報を扱うかどうかで決まります。括弧内は「対応している」確率です。

項目ごとの読み取り

項目公式資料の記載確率根拠
MFA対応と記載0.99How to require multi
SSO対応と記載1.00How to enable single sign-on (SSO) for your team
2FA対応と記載1.00How to require multi
IP制限公式資料に記載なし0.01Network control
監査ログ対応と記載1.00View team activity in the admin console

「公式資料に記載なし」は、その要素の公式ページを読んだが記載がなかったもの。「未収集」は、公式ページをまだ見つけられていないもの(機能がないという意味ではありません)。

根拠(公式資料の原文)

SSO:How to enable single sign-on (SSO) for your team - Dropbox Help

https://help.dropbox.com/security/sso-admin

How to enable single sign-on (SSO) for your team - Dropbox Help

How to enable single sign-on for your team

Admins Updated Feb 13, 2026

続きを読む(ほか 52 段落)

In this article

The information in this article applies to certain types of admins on Dropbox Advanced, Business Plus, and Enterprise.

If you're an admin of a Dropbox team on Advanced, Business Plus, or Enterprise, you can turn on single sign-on (SSO) for your team. Single sign-on lets team members access Dropbox by logging in to a central identity provider, so they don't need a separate password.

How to turn on single sign-on

Go to your identity provider's site and follow the instructions to set up single sign-on.

Many identity providers offer preconfigured settings for Dropbox. If your identity provider isn't supported, you can configure your own identity provider solution for SSO.

Download a copy of the X.509 certificate and make a note of the log in URL, you’ll need both later.

Log in to dropbox.com using your admin credentials.

Click Admin console in the left sidebar.

Under Team, click Settings.

Click the Security tab.

Under Authentication, click the dropdown next to Single sign-on (SSO) and select either:

Optional (for testing): Your team can log in to Dropbox using SSO or their Dropbox password.

Required (for production): Team members must log in to Dropbox using SSO, and their Dropbox password will no longer work. Admins can still use their Dropbox admin credentials to log in.

Note: To turn off single sign-on, click the dropdown next to Single-sign on (SSO) and select Off.

Click Add next to Identity provider sign-in URL, enter the copied login URL, then click Done.

Click Add next to X.509 certificate.

Select your X.509 certificate from your hard drive and click Upload.

After you turn on single sign-on, you can share these instructions for the rest of your team.

All devices that are linked to Dropbox accounts will continue to work. Admins can't reset passwords through Dropbox or require two-factor authentication since passwords and log in-related security are now managed by your identity provider.

How to find your team’s custom SSO sign-in URL

If team members have already logged in to your identity provider, they can go directly to their Dropbox account using the custom link.

To find your team’s custom SSO sign-in URL:

Click Settings.

Under Authentication, go to SSO sign-in URL and click Copy link.

Seeing a SAML assertion error when you log in?

Learn how to resolve the error message: “Could not validate SAML assertion.”

Was this article helpful?

Let us know how why it didn't help:

Thanks for letting us know!

The article didn't answer my question

The steps in the article didn't work for me

I found this article confusing and difficult to read

Please enter feedback before submitting.

Submit feedback

Thanks for your feedback!

Related Articles

Change admin rights

Customize Dropbox team security settings

Data classification

Dropbox Paper: admin settings for Dropbox teams

Community answers

Dropbox Backup won't restore or download and no option to copy Dropbox Backup to regular Dropbox

Posted by: Liberty1991

2025, LET'S GO 🚀!

Posted by: Theresa

How Do You Enable Two-Step Verification on Your Dropbox Account?

Can't link Team Account with Personal (Basic) Account

Posted by: piecheck

Other ways to get help

Contact support

Social media support

MFA:How to require multi-factor authentication for Dropbox teams

https://help.dropbox.com/security/two-step-verification

How to require two-factor authentication for teams - Dropbox Help

How to require two-factor authentication for Dropbox teams

Admins Updated Aug 13, 2025

続きを読む(ほか 53 段落)

In this article

The information in this article applies to admins on Dropbox team accounts.

Two-factor authentication adds an extra layer of protection to your team’s Dropbox accounts, making it much harder for anyone else to access an account, even if they know the password.

Dropbox team admins can require all or some team members to use two-factor authentication. You can do this through the admin console or through your identity management provider if you use single sign-on (SSO).

Note: Each team member must enable two-factor authentication on their own account.

How to require two-factor authentication for team member

Log in to dropbox.com with your admin credentials.

Click Admin console in the left sidebar.

Click Settings.

Click the Security tab.

Under Authentication, select Required from the dropdown next to 2-step verification.

Note: Team members won't be protected until they set up two-factor authentication.

How will required two-factor authentication affect my team?

Newly invited members will be required to enable two-factor authentication after accepting the invitation to join your team.

Existing members will be required to enable two-factor authentication the next time they log in. Requiring two-factor authentication won't log your team member out of their devices or web sessions, and won't interrupt their workflow. Existing team members who try to connect a new computer or mobile device as their first log-in after two-factor authentication is enabled will be directed to the Dropbox website to log in (and set up two-factor authentication).

What will a team member see when setting up two-factor authentication?

When team members log in to Dropbox, they will see a Get Started prompt.

Team members can choose to receive verification codes via text message, or to use an authenticator app, and then click Send code.

Team members will next be required to verify that two-factor authentication is working— they will receive a text message to the phone number entered, or else need to enter the two-factor authentication code generated via the authenticator app.

Lastly, team members will receive an emergency backup code, which can be used if they ever lose their mobile phone.

Alternatively, team admins can reset two-factor authentication for team members as needed

Click Turn on 2-factor authentication.

How to add users to the exception list

If you require two-factor authentication for your team, but want to exclude certain members, you can add them to the exception list.

Click Add to the right of Exceptions.

Enter the emails or names of users you’d like to add.

Was this article helpful?

Let us know how why it didn't help:

Thanks for letting us know!

The article didn't answer my question

The steps in the article didn't work for me

I found this article confusing and difficult to read

Please enter feedback before submitting.

Submit feedback

Thanks for your feedback!

Related Articles

Change admin rights

Customize Dropbox team security settings

Data classification

Dropbox Paper: admin settings for Dropbox teams

Community answers

Active account disabled with no warning, all my work files are locked inside

Posted by: beguido_backup

Is there a place where I can access the login history for my account?

Posted by: DiagramUser

Two-factor authentication methods used on my account are no longer accessible and I can't sign in

Posted by: bridgette1

My password was changed by someone else. What are the next steps?

Posted by: mathetesbl

[tips] 3 easy ways to protect your company's data

Other ways to get help

Contact support

Social media support

2FA:How to require multi-factor authentication for Dropbox teams

https://help.dropbox.com/security/two-step-verification

How to require two-factor authentication for teams - Dropbox Help

How to require two-factor authentication for Dropbox teams

Admins Updated Aug 13, 2025

続きを読む(ほか 53 段落)

In this article

The information in this article applies to admins on Dropbox team accounts.

Two-factor authentication adds an extra layer of protection to your team’s Dropbox accounts, making it much harder for anyone else to access an account, even if they know the password.

Dropbox team admins can require all or some team members to use two-factor authentication. You can do this through the admin console or through your identity management provider if you use single sign-on (SSO).

Note: Each team member must enable two-factor authentication on their own account.

How to require two-factor authentication for team member

Log in to dropbox.com with your admin credentials.

Click Admin console in the left sidebar.

Click Settings.

Click the Security tab.

Under Authentication, select Required from the dropdown next to 2-step verification.

Note: Team members won't be protected until they set up two-factor authentication.

How will required two-factor authentication affect my team?

Newly invited members will be required to enable two-factor authentication after accepting the invitation to join your team.

Existing members will be required to enable two-factor authentication the next time they log in. Requiring two-factor authentication won't log your team member out of their devices or web sessions, and won't interrupt their workflow. Existing team members who try to connect a new computer or mobile device as their first log-in after two-factor authentication is enabled will be directed to the Dropbox website to log in (and set up two-factor authentication).

What will a team member see when setting up two-factor authentication?

When team members log in to Dropbox, they will see a Get Started prompt.

Team members can choose to receive verification codes via text message, or to use an authenticator app, and then click Send code.

Team members will next be required to verify that two-factor authentication is working— they will receive a text message to the phone number entered, or else need to enter the two-factor authentication code generated via the authenticator app.

Lastly, team members will receive an emergency backup code, which can be used if they ever lose their mobile phone.

Alternatively, team admins can reset two-factor authentication for team members as needed

Click Turn on 2-factor authentication.

How to add users to the exception list

If you require two-factor authentication for your team, but want to exclude certain members, you can add them to the exception list.

Click Add to the right of Exceptions.

Enter the emails or names of users you’d like to add.

Was this article helpful?

Let us know how why it didn't help:

Thanks for letting us know!

The article didn't answer my question

The steps in the article didn't work for me

I found this article confusing and difficult to read

Please enter feedback before submitting.

Submit feedback

Thanks for your feedback!

Related Articles

Change admin rights

Customize Dropbox team security settings

Data classification

Dropbox Paper: admin settings for Dropbox teams

Community answers

Active account disabled with no warning, all my work files are locked inside

Posted by: beguido_backup

Is there a place where I can access the login history for my account?

Posted by: DiagramUser

Two-factor authentication methods used on my account are no longer accessible and I can't sign in

Posted by: bridgette1

My password was changed by someone else. What are the next steps?

Posted by: mathetesbl

[tips] 3 easy ways to protect your company's data

Other ways to get help

Contact support

Social media support

IP制限:Network control - Dropbox Help

https://help.dropbox.com/security/network-control

Network control - Dropbox Help

Network control

Admins Updated Aug 13, 2025

続きを読む(ほか 55 段落)

In this article

This article discusses a feature that is only available to customers on Dropbox Enterprise.

Network control is a security and access feature available to customers on Dropbox Enterprise. With this feature, IT admins can manage which Dropbox accounts can be used on their corporate network. Using your proxy or CASB vendor, you can specify which team member accounts can log in and sync via dropbox.com or the Dropbox desktop app.

Who can use network control?

Network control is available exclusively to Enterprise teams. Admins can set up network control to help manage how members of their team access Dropbox.

How do I get started with network control?

To set up network control, contact the Dropbox account manager for your Enterprise account. They can give you early access to this feature and detailed instructions regarding the setup.

Once the Dropbox account manager for your Enterprise account has given you early access, follow these instructions to get started:

Log in to dropbox.com with your admin credentials.

Click Admin console in the left sidebar.

Click Settings.

Click the Security tab.

Under Network control, toggle the Restricted Dropbox traffic toggle to On.

Configure your proxy or CASB vendor to add a custom HTTP header to Dropbox traffic from your web browser and desktop client.

Learn more about the domains that Dropbox uses in an official capacity.

Dropbox will now block traffic that's not associated with the correct Enterprise team.

Note: If the Dropbox desktop app doesn’t automatically update after enabling network control, add the following registry key with any value [HKLM\SOFTWARE\Dropbox\IgnoreUnknownRevocationErrors]. This registry key only works if network control is already enabled.

Who are your network control providers?

While there are many preferred proxy or cloud access security broker (CASB) providers, we’ve confirmed that the following will support Dropbox at this time:

Cisco Web Security Appliance

Blue Coat Systems - ProxySG

Intel Security / McAfee

Skyhigh Networks

Symantec CloudSOC CASB

What should I do if I can't use Dropbox on my network?

If you’re a member of an Enterprise team and you're having trouble accessing Dropbox, contact your company's IT help.

If you're not a member of an Enterprise team and you see the error ”Your company now manages Dropbox traffic”, contact Dropbox support.

Was this article helpful?

Let us know how why it didn't help:

Thanks for letting us know!

The article didn't answer my question

The steps in the article didn't work for me

I found this article confusing and difficult to read

Please enter feedback before submitting.

Submit feedback

Thanks for your feedback!

Related Articles

Change admin rights

Customize Dropbox team security settings

Data classification

Dropbox Paper: admin settings for Dropbox teams

Community answers

Accessing the Dropbox site disables my internet connection

Posted by: Jack420

Dropbox Tenancy Header Insertion

Posted by: npaul

Can new files in a network folder automatically update and sync to other devices with Dropbox?

Posted by: Mark_Royle

Dropbox upload on a device only with max 600kb/s. (Upload)

Posted by: Skyfay

Re-linking using Obj-C SDK fails with network error

Posted by: Mark R.5

Other ways to get help

Contact support

Social media support

監査ログ:View team activity in the admin console - Dropbox Help

https://help.dropbox.com/account-access/view-activity

View team activity in the admin console - Dropbox Help

View team activity in the admin console

The information in this article applies to certain types of admins on Dropbox Standard, Business, Advanced, Business Plus, and Enterprise.

続きを読む(ほか 57 段落)

The following activities are logged: Signed in, Linked app for member, and Created shared link.

The following activities are not logged: Deleted a screenshot, Deleted a recording, Made a Comment, Deleted a comment, and Trimmed a Recording.

Activities performed during a Microsoft co-authoring session won't be recorded in team activity logs.

Third-party integration activity in Sign won’t be tracked in your Dropbox team’s activity log.

Learn more about the features of the admin dashboard.

For more detailed insights, the Activity section of the admin console shows specific team activity and lets you generate reports based on that data.

View team activity

To view your team’s activity:

Log in to dropbox.com using your admin credentials.

Click Admin console in the left sidebar.

Click Activity in the left sidebar.

Under Products, click the dropdown to the left of Dropbox.

Click Security.

Click the Activity filter.

Filter results to view the activity you’d like to see. You can filter by Date, Activities, People, Participants, and Content type.

To view activity for a specific time period, enter a start and end date under Date.

To filter by activities, click Activities.

To view recent activity of a specific team member or multiple team members, click People, then enter the name(s).

To find files, folders, or Paper docs, click the search field below Content and type in a keyword.

Usage data is available, beginning January 2017 or when your team began using Dropbox.

You may see a "processing" message when trying to view dates for which we're still processing the data.

If you’d like to see more detailed activity on your team, you can also view team sharing activity.

File types that preview as a link

If your saved website has one of the following extensions, it will preview as a shortcut to the website.

Create and export an activity report

To create and export an activity report:

Use the filters to select the type of data and the time period you’d like to export.

Click Create report to the right of your filters.

Select the report type you want to generate.

Click Generate.

The report will be saved as a CSV in a folder named Dropbox Business reports. You’ll receive an email when the report is ready.

What can I see in activity reports?

Each entry in the activity report shows:

Date: The exact date that an action took place

Member: The member that initiated the action

Activity: Details of the event itself

Content: The type of file

Generally, a team member's actions appear in activity logs in a few hours. At most, actions appear within 24 hours.

Admins have the following events available in their team activity reports:

File operations (Dropbox Business Plus, Advanced and Enterprise only)

Signature activity†

Two-factor authentication

*These events are only available to customers on Dropbox Business and Business Plus.

†These events are only available to customers on a paid Dropbox Sign plan or Dropbox Standard, Advanced, Business, or Business Plus.

As a team admin, you'll see events for files owned by your team and files shared with your team members. If you're a team admin on a Dropbox Business Plus, Advanced, or Enterprise account, you'll also see file-level activity including adding, editing, moving, and deleting files.

You can use these events to investigate and troubleshoot problems, such as accidental file deletions, misplaced files or folders, or information security audits.

Replay in the activity report

The report now allows admins to review their team’s Replay activity, including:

When a team member logs in to Replay for the first time or connects their Dropbox account to Replay

When a team member uploads a file to Replay, including the file name and the uploader

When a team member deletes a file, including the file name and who deleted it

Any changes to team policies for Replay content

When links are created or modified for files in Replay, including:

What file it links to

Why do I see "Dropbox" in the Name column?

A team member deleted a nested shared folder

When a team member deletes a nested shared folder, the name of the person who deleted it appears as “Dropbox.” Certain types of admins can see the name of the team member by following these steps:

この結果について

確認状況
未確認(自動判定)
資料の取得日
2026-10-04
判定日
2026-10-04
判定モデル
TypeSafe Jev(jev-1.13.0)。公式資料の原文から各項目の記載を読み取り、判定の木はプログラムで計算しています。