No matter how big your team is, as a Dropbox team admin you have plenty of options for managing Dropbox access.
13 minute read
Managing made easy
Whether you’re adding or removing members of your team, Dropbox team accounts make user management easy.
Managing members vs. groups
If you have a big team, creating custom groups is a great way to organize your team members. From the admin console, you can manage permissions to ensure only the right people have access to the right files, both at the individual and group level.
Know your group types
There are two types of groups you can use:
Company-managedgroups can only be created be admins. Team members can’t join or leave these groups voluntarily.
User-managed groups are enabled by default and can be created by admins and team members. People can request to join or voluntarily leave the groups. Both admins and group managers can add or remove members to or from a group.
Admins can disable user-managed groups through the admin console or change a user-managed group to a company-managed group when you want to take control of it.
Manage members
When it comes to managing the members of your Dropbox team account, you have several controls available.
You can:
Reset passwords.
Suspend or delete members.
View individual activity logs. To do so, click Members in the admin console.
See what everyone’s up to
As an admin, the activity log is your new best friend. From here, you can see what's happening across all members on your account. This includes when, what, and with whom your members share, when they log into their accounts or change their passwords, and when they've linked third-party apps or new devices. It also lets you see whenever a user is added to or removed from the team.
To access activity logs, click Activity in the admin console.
Review member access with reports
When you manage access across a team, reports can help you see what members can access and where you may need to follow up.
Use a:
Member access report to see which folders a specific member can access.
Member data report to review each member’s usage, storage limits, and file access.
Team storage report to see what’s using team storage across team folders, shared folders, and member folders.
Team folders report to review storage and access details for team folders and subfolders, including active and archived content.
Shared folders report to review storage, access, and sharing details for shared folders, including whether folders are internal, external, or orphaned.
Note: The reports available to you depend on your admin role and team plan.
Manage groups
With Groups you can create lists of people who should have access to the same files and folders. It’s especially helpful if you want to organize team members by department or function.
Another benefit is that you can share folders instantly with the entire group, and decide whether they have edit or view-only access.
To create and edit groups, click Groups in the admin console.
Know your group types
There are two types of groups you can use:
Company-managedgroups can only be created be admins. Team members can’t join or leave these groups voluntarily.
User-managed groups are enabled by default and can be created by admins and team members. People can request to join or voluntarily leave the groups. Both admins and group managers can add or remove members to or from a group.
Admins can disable user-managed groups through the admin console or change a user-managed group to a company-managed group when you want to take control of it.
Manage members
When it comes to managing the members of your Dropbox team account, you have several controls available.
You can:
Reset passwords.
Suspend or delete members.
View individual activity logs. To do so, click Members in the admin console.
See what everyone’s up to
As an admin, the activity log is your new best friend. From here, you can see what's happening across all members on your account. This includes when, what, and with whom your members share, when they log into their accounts or change their passwords, and when they've linked third-party apps or new devices. It also lets you see whenever a user is added to or removed from the team.
To access activity logs, click Activity in the admin console.
Review member access with reports
When you manage access across a team, reports can help you see what members can access and where you may need to follow up.
Use a:
Member access report to see which folders a specific member can access.
Member data report to review each member’s usage, storage limits, and file access.
Team storage report to see what’s using team storage across team folders, shared folders, and member folders.
Team folders report to review storage and access details for team folders and subfolders, including active and archived content.
Shared folders report to review storage, access, and sharing details for shared folders, including whether folders are internal, external, or orphaned.
Note: The reports available to you depend on your admin role and team plan.
Manage groups
With Groups you can create lists of people who should have access to the same files and folders. It’s especially helpful if you want to organize team members by department or function.
Another benefit is that you can share folders instantly with the entire group, and decide whether they have edit or view-only access.
To create and edit groups, click Groups in the admin console.
Know your group types
There are two types of groups you can use:
Company-managedgroups can only be created be admins. Team members can’t join or leave these groups voluntarily.
User-managed groups are enabled by default and can be created by admins and team members. People can request to join or voluntarily leave the groups. Both admins and group managers can add or remove members to or from a group.
Admins can disable user-managed groups through the admin console or change a user-managed group to a company-managed group when you want to take control of it.
Get everyone on board
Do you use Active Directory? Great! You can use the Dropbox AD Connector to easily provision, de-provision, and manage users and groups in Dropbox.
Note: The Dropbox AD Connector is available to Dropbox teams on an Advanced or Enterprise plan.
Changes in your AD Connector are reflected in Dropbox, but won’t alter any files or content in your Dropbox account. This is also known as one-way sync.
Tip: Set up a user sync and a separate group sync when you set up your AD with Dropbox. This will offer you more flexibility when it comes to provisioning users.
With Dropbox, there are many ways to provision users, in addition to the AD Connector, such as the admin console and IAM/IdP. Choose what’s best for you (and know that some of these methods require a little bit of technical knowledge, too).
Identify yourself
If you’re already using an identity management provider or have a complex, multi-forest Active Directory you want to keep, you can connect them to your Dropbox account.
Identity managers (IDMs)
Identity management offers admins a robust set of tools designed to simplify user lifecycle operations, including creating and removing Dropbox accounts.
Single sign-on (SSO) is available to Dropbox teams on an Advanced or Enterprise plan.
SSO lets your team log in to Dropbox with a central identity provider. This makes life easier for your users—it gives them one less password to remember. If you’re already using an identity provider you trust and one that Dropbox supports, setting this up is easy. If you also manage SSO with your Cloud IDM, you can easily manage everything with your IDM provider.
Suspend user and remote wipe
There are two ways to remove a user’s access to your Dropbox team, and methods are accessible through the admin console.
Suspend users
Suspending a user means that they instantly lose access to their Dropbox team account and Paper docs. Only an admin can remove the suspension.
Suspending an account doesn’t free up a license, or delete any files. The account still exists, which means it’s still using that license. To free up the license, you’ll need to delete the account.
Remote wipe
Remote wipe lets you delete a Dropbox team account from a team member’s linked devices. With this feature, you can delete data from a device even if your team member loses it.
Once you unlink a device and use remote wipe, that device will immediately stop syncing.
Restore deleted
Did you accidentally remove a team member? Didn’t mean to delete someone? No problem!
Restoring a member reactivates the account with the same files and permissions, so the account is exactly as it was before deletion.
It’s like nothing even happened.
Note: Team admins and user management admins can restore deleted users.
How to merge Dropbox teams
If there’s more than one Dropbox team in your organization, or maybe you’re working closely with another team, you might want to merge these two separate teams into one.
How to add existing Dropbox users to your team
Invite your team member as you would any new member. If they choose to join the team, they’ll be prompted to decide what they want to do with their existing files: merge their files with the Dropbox team account or create a separate personal Dropbox account for their files.
Also, keep in mind that if that team member is part of an existing Dropbox team, they can’t join a second team (using the same email address.)