Encrypted team folders are team folders that are end-to-end encrypted. Only folder members have access to the encryption key, while excluding anyone else, including Dropbox. Admins can also create recovery keys for encrypted folders, in case of user access issues.
Organizational data can be categorized into nonsensitive, sensitive, and highly sensitive. Nonsensitive data can be safely migrated to the cloud, while sensitive data sometimes requires additional protection measures. Highly sensitive data demands the highest level of protection, in some cases with strict adherence to regulatory requirements. End-to-end encryption is recommended for highly sensitive data, while alternative solutions, such as Advanced Key Management or standard Dropbox encryption, may suffice for less sensitive data. Understanding these categories helps organizations safeguard data and maintain compliance.
Encrypted team folders act like normal team folders, but they can only be accessed by authorized folder members. While the metadata remains in plain text, the content of the files in an encrypted folder is always encrypted. Encrypted team folders display as a blue folder with a key inside a shield icon. Learn more about file and folder icons.
How to activate team folder encryption
If you’re a team admin, you can activate team folder encryption for your team. To do so:
- Log in to dropbox.com with your admin credentials.
- Click Admin console in the left sidebar.
- Click the dropdown beside Dropbox, under Products.
- Click Security.
- Select Encryption options.
- Click Get started next to End-to-end encryption.
- Click Start on the pop-up window to confirm your choice.
- Click Generate recovery key.
- Notes:
- You won’t be able to recover your encrypted data if you get locked out and don’t have this recovery key.
- The recovery key won’t be displayed again, so make sure to save it physically or digitally.
- Confirm that you have stored the recovery key by entering the last five characters for verification.
- Review your device registration. You can choose either automatic device registration (recommended) or the manual option with manual key verification.
- If you selected automatic device registration, click Finish to complete the activation process.
- If you selected manual key verification, confirm this by clicking Set up manual on the next screen. Your team code will then be generated, which you can copy, store, and share with team members. Click Finish to complete the activation process. Click Next to complete the activation process.
- Click Create encrypted folder to create an encrypted team folder, or click Dismiss to close the pop-up window and go back to your account.
How to create an encrypted team folder
If you’re a team admin, you can create encrypted team folders for your team. To do so:
- Log in to dropbox.com with your admin credentials.
- Click Admin console in the left sidebar.
- Click the dropdown beside Dropbox, under Products.
- Select Content.
- Click Create team folder.
- Select Encrypt this folder end-to-end.
How to add and manage recovery keys
Recovery keys make sure data can always be retrieved and decrypted, even in the event of key loss or user access issues. Team admins can create and manage multiple recovery keys for different admins or storage locations.