The information in this article applies to Dropbox Protect admins.
This article answers frequently asked questions about Dropbox Protect, helping you quickly find solutions to common issues, including error messages and how to resolve them.
Learn how to manage Dropbox Protect.
Dropbox Protect is available only to Dropbox Protect admins. Users without a Protect license can’t view or manage Protect settings.
You should use Protect any time you want to review or manage access to company documents as part of ongoing access oversight and data governance efforts.
Company links make it easy to share documents broadly inside an organization, but they can also increase exposure if they’re shared more widely than intended. Protect helps admins find and manage documents that use company links so they can review or limit access when needed.
When a document has a company link:
Learn how to manage shared links in the Dropbox Protect dashboard.
Protect helps admins identify documents that have company or public links and remove or limit those links to reduce risk.
No. Dash access is limited to users with assigned licenses. Removing personal accounts, external vendors, or public links only changes access to specific documents. It doesn’t affect their ability to use Dash.
No. Users can only see documents they already have access to as collaborators or through previously accessed links. Cleaning up company links does not expand document access.
No. Protect admins are not automatically granted access to document contents. They can view access levels and metadata, such as collaborators and sharing links, but they can’t view document contents unless they already have access.
Note: Admins aren’t added as collaborators by default, but they can add themselves if needed. If a document has a company or public link, admins can also use that link to access the document.
No. The Remove collaborator action only removes collaborators, not owners. This prevents documents, folders, or drives from being left without an owner.
Protect supports the following apps:
Learn how to connect apps to Dropbox Protect.
No. Protect only lets you monitor files connected to Google Drive, Dropbox, Microsoft OneDrive, SharePoint, and Teams.
Content from apps that aren’t connected won’t appear in Protect.
Protect shows user accounts that have access to documents in the apps connected to Protect.
This includes:
Notes:
For Microsoft 365, Protect shows user accounts that have access to at least one document, drive, or SharePoint or Teams item.
This includes owners and collaborators.
Note: User accounts that exist in Azure but don’t have access to any content won’t appear because Protect displays accounts based on document access levels.
For Google Drive, account information is collected from the Google Workspace Directory.
Protect shows user accounts that have access to documents in My Drive or shared drives, based on directory and access level data.
Admins can limit which users are included using directory controls. Only accounts that have access to content will appear.
For Dropbox, Protect shows all Dropbox team member accounts returned by the Dropbox API.
These accounts appear if they have access to content or are part of the connected Dropbox team.
Some groups and service accounts don’t have associated email addresses, including Dropbox groups and certain Microsoft service accounts.
Because Protect relies on email domains to classify accounts as internal, outside, or personal, these accounts:
These limitations only apply to accounts with document access in the connected app.
A new user account will appear in Protect after the user creates a document or is granted access to a document in a connected app.
It can take up to about one hour for the account and its access levels to appear, depending on synchronization timing.
Protect displays files, folders, shared drives, and other shared containers across connected apps.
Items that don’t have an owner, collaborators, or sharing links are hidden from the interface.
App-specific exceptions include:
A file may not appear for several reasons:
Most updates appear within about one hour. If the file still doesn’t appear after that time, check that the app is connected and that the file has active access levels.
No. Deleted items aren’t displayed in Protect.
If an item was previously visible and then deleted, it can take up to about one hour for that change to appear due to synchronization timing.
Protect doesn’t update in real time. Data from connected apps is synchronized on a regular schedule.
Updates typically appear within about one hour after a change occurs in a connected app or after an action is run.
If you don’t see updates after more than one hour, refresh the page or check the status of the connected app.
Protect allows admins to manage document access across connected apps by taking the following actions:
Small actions may complete in seconds. Large bulk actions can take 30 minutes or longer, depending on how many items are affected.
Access levels are settings that come from a top-level folder, shared drive, site, or library in a connected app. When access levels are applied at a higher level, they automatically apply to all nested files and subfolders.
Dropbox Protect follows the access level model of each connected app, such as Google Drive, Dropbox, and Microsoft 365. Because the access levels are controlled by the source app, they can’t be changed on individual files or subfolders. If you try, you’ll see an error indicating that the access level is inherited and can’t be modified at that level.
Learn how to manage and fix errors with top-level access in Protect.
After an action runs, it can take up to about one hour for updates to appear while connected services confirm access level changes.
You can review results in Action history.
Learn how to use the Action history page in Dropbox Protect.
This usually means the filtered items didn’t include any public links, so no changes were made.
However, if the change was made recently, wait about an hour and try again.
You can automate document access management by using Policies. Policies allow admins to define rules based on access conditions, such as:
When a policy condition is met, Protect can send notifications to admins, automatically take actions such as removing links or access, or both.
How the policy responds depends on how it’s configured.
To learn more, see:
If a policy has alerting enabled, selected admins receive an email every 24 hours.
The email includes:
No. Slack notifications aren’t supported.
Shared with: Private means only the owner has access to the item.
However, Dropbox groups aren’t included in the Shared with count. Because of this, an item may appear as Private even if a Dropbox group has access.
For Dropbox, the Age column may be blank because creation date information isn’t always available through the API.
Filters let you narrow results based on document access and activity criteria.
Learn how to use filters on the Dropbox Protect dashboard.
In rare cases, connected app APIs may return inconsistent timestamps, especially after items are moved or ownership changes occur.
This can result in the Last modified date appearing older than the Age date.
The Owner field shows the account that owns the file in the connected app, such as Google Drive, Microsoft 365, or Dropbox.
This refers to file-level ownership in the source system, not Protect ownership or admin roles.
An item may display Unknown as the file owner when Dropbox Protect can’t retrieve ownership details from the connected app.
This can occur in cases such as:
In Dropbox, Team ownership means the file belongs to a Team folder rather than an individual user.
Team folders and their contents don’t have individual file owners. Instead, ownership is managed at the team level within Dropbox.
No. There are no file size limits in Protect. File size limits are determined by the connected app.
No. Protect doesn’t support file previews.
To protect sensitive information, admins can view access levels and metadata but can’t open or view file contents unless they already have access in the connected app.
Protect includes built-in reporting and export capabilities to help admins review document ownership and sharing across connected apps.
Admins can also export filtered results and report data to CSV.
Learn more:
The Action history page shows the results of actions run in Protect.
Each item included in an action may return a different result. Some items may be skipped update successfully, while others may return errors.
Each Action history entry includes a details pane that provides additional context about the action.
The details pane shows:
Yes, thanks!
Not really
Let us know how why it didn't help:
Thanks for letting us know!
Thanks for your feedback!