Encrypted team folders: an overview
End-to-end encryption is a feature available for teams on Dropbox Business Plus, Advanced, and Enterprise, and is subject to additional terms.
Encrypted team folders are team folders that are end-to-end encrypted. Only folder members have access to the encryption key, while excluding anyone else, including Dropbox. Admins can also create recovery keys for encrypted folders, in case of user access issues.
Organizational data can be categorized into nonsensitive, sensitive, and highly sensitive. Nonsensitive data can be safely migrated to the cloud, while sensitive data sometimes requires additional protection measures. Highly sensitive data demands the highest level of protection, in some cases with strict adherence to regulatory requirements. End-to-end encryption is recommended for highly sensitive data, while alternative solutions, such as Advanced Key Management or standard Dropbox encryption, may suffice for less sensitive data. Understanding these categories helps organizations safeguard data and maintain compliance.
Encrypted team folders act like normal team folders, but they can only be accessed by authorized folder members. While the metadata remains in plain text, the content of the files in an encrypted folder is always encrypted. Encrypted team folders display as a blue folder with a key inside a shield icon. Learn more about file and folder icons.
How to activate team folder encryption
If you’re a team admin, you can activate team folder encryption for your team. To do so:
- Log in to dropbox.com with your admin credentials.
- Click Admin console in the left sidebar.
- Click Security.
- Select Encryption options.
- Click Get started next to End-to-end encryption.
- Click Start on the pop-up window to confirm your choice.
- Click Generate recovery key.
- Notes:
- You won’t be able to recover your encrypted data if you get locked out and don’t have this recovery key.
- The recovery key won’t be displayed again, so make sure to save it physically or digitally.
- You won’t be able to recover your encrypted data if you get locked out and don’t have this recovery key.
- Notes:
- Confirm that you have stored the recovery key by entering the last five characters for verification.
- Review your device registration. You can choose either automatic device registration (recommended) or the manual option with manual key verification.
- If you selected automatic device registration, click Finish to complete the activation process.
- If you selected manual key verification, confirm this by clicking Set up manual on the next screen. Your team code will then be generated, which you can copy, store, and share with team members. Click Finish to complete the activation process. Click Next to complete the activation process.
- Click Create encrypted folder to create an encrypted team folder, or click Dismiss to close the pop-up window and go back to your account.
How to create an encrypted team folder
If you’re a team admin, you can create encrypted team folders for your team. To do so:
- Log in to dropbox.com with your admin credentials.
- Click Admin console in the left sidebar.
- Click Settings.
- Select Content.
- Click Create team folder.
- Select End-to-end encryption.
How to add and manage recovery keys
Recovery keys make sure data can always be retrieved and decrypted, even in the event of key loss or user access issues. Team admins can create and manage multiple recovery keys for different admins or storage locations.
Note: You won’t be able to recover your encrypted data if all team members get locked out and you don’t have a recovery key, so you must store it somewhere safe, digitally or physically.
To create an additional recovery key:
- Log in to dropbox.com with your admin credentials.
- Click Admin console in the left sidebar.
- Click Security.
- Select Additional encryption.
- Click Manage.
- Click Add new key next to Manage keys, in the End-to-end encryption section.
- Enter any of your existing recovery keys.
- Click Generate.
- Click Copy or Print to copy your recovery key, and store it somewhere safe.
- Note: The recovery key won’t be displayed again, so make sure to save it physically or digitally.
- Click Next to complete the activation process.
- Click Manage keys to manage your existing keys, or click Done to close the pop-up window and go back to your account.
To edit or delete existing recovery keys:
- Log in to dropbox.com with your admin credentials.
- Click Admin console in the left sidebar.
- Click Security.
- Select Additional encryption.
- Click the Manage button next to Manage keys, in the End-to-end encryption section.
- A list of your recovery keys will pop up.
- Click the Delete button (trash can icon) next to a recovery key to delete it permanently. Click Delete to confirm your choice.
How to manage device registration
If manual device registration is activated, a key verification process is required. This process is a two-way process. The admin needs to verify the device's code, while the user needs to verify the team code. The team code is shown to the admin during the end-to-end encryption activation process. The admin can then share the team code with team members via email. On the user's side, both the team and client codes are displayed in the sync notifications. The user verifies that the displayed team code matches the code provided by the admin.
To verify that the device code shared by the user matches the value displayed to the admin in the admin console:
- Click Settings.
- Click Encryption options.
- Click Review pending devices.
- Click Accept to register the devices.
FAQs about encrypted team folders
Can anyone in the team create encrypted team folders?
No, only team admins can create and manage encrypted team folders.
Can I share an encrypted team folder with someone from another team?
Yes, you can share an encrypted folder with another team. Both teams must enable end-to-end encryption on their accounts to share encrypted folders.
Which features are limited when working with encrypted team folders?
While end-to-encryption offers an additional security level, there is a downside on usability. This means that the following features and functionalities are not available for encrypted files and folders:
- Server-side processing, including:
- Search indexing (for example in Dash)
- Thumbnail generation
- Preview generation
- Usability restrictions, including:
- Dropbox Transfer
- Content search
- Shared links
- File requests
- Workflow automation
Encrypted team folders don’t support:
- Cloud content (like Dropbox Paper, Google Docs)
- Data governance (legal holds, content scanning)
- Note: Legal holds aren't available for Send and track or encrypted folders.
- Ransomware detection
- Data classification
- Dropbox AI
- Upload and download via Dropbox API
- Pre-built components for third-party developers (Chooser, Saver, Embedder)
- Shared folders
Important note: End-to-end encryption is currently not available for the Dropbox mobile app. To access encrypted files on your mobile device, use the Dropbox website through your mobile browser.
What happens if I move or copy files to another location outside an encrypted folder?
When files are copied to a location outside the encrypted team folder, they’ll lose their encryption and will be stored in an unencrypted state in the new location.
Where can I track encrypted team folder activity?
All events related to encrypted team folders will be logged in the activity log.
Logged events related to end-to-end encryption:
- Team enrollment
- Device enrollment
- Device key removal
- Recovery key enrollment
- Recovery key removal
- Key rotation
Isn’t Dropbox already encrypted?
Dropbox provides a high level of security for data, but end-to-end encryption adds an additional layer of privacy. You’ll have exclusive control over encryption keys, ensuring limited access. However, it's important to note that end-to-end encryption may restrict certain functionalities (like sharing files with users outside of your team) and may not be suitable for all files in a Dropbox account.