Dropbox stores files you cannot afford to lose โ documents, photos, backups, and sensitive personal and business data. A compromised Dropbox account can expose all of this content to an attacker, and because Dropbox syncs across devices, a breach can happen silently without any obvious signs. Two-step verification (Dropbox's name for 2FA) adds a critical extra layer of security to your account.
How to Enable 2FA on Dropbox
- Sign in to dropbox.com and click your avatar in the top right corner.
- Click Settings.
- Click the Security tab.
- Under "Two-step verification", click Enable.
- Click Get started and enter your Dropbox password to confirm.
- Choose your method: Use a mobile app (recommended) or Use SMS.
- For the mobile app option: scan the QR code with your authenticator app, enter the 6-digit code to verify, then click Next.
- Dropbox asks you to add a backup phone number for SMS recovery โ enter one and verify it.
- Dropbox provides a 16-digit emergency backup code. Write it down or save it securely before clicking Done.
Dropbox 2FA Methods
Mobile Authenticator App (Recommended)
Dropbox works with any TOTP-compatible authenticator: Google Authenticator, Authy, Microsoft Authenticator, 1Password, and many others. After entering your password, Dropbox asks for the 6-digit code currently displayed in your app. The code rotates every 30 seconds and works without an internet connection. This is the most secure everyday option.
SMS Text Message
Dropbox can send a verification code to your registered phone number. This works as a fallback but is less secure than an authenticator app, primarily because SMS codes can be intercepted through SIM-swap attacks. Use SMS only if you have no other option.
Hardware Security Keys
Dropbox supports security keys via FIDO2/WebAuthn for personal and Business accounts. You plug in or tap a hardware key when prompted. This is the most phishing-resistant option and is recommended for business accounts or anyone with highly sensitive files.
Two-Step Verification for Dropbox Business Teams
Dropbox Business admins can enforce two-step verification for all team members. In the Admin Console, go to Security โ Two-step verification and select the enforcement level: optional, required for admins only, or required for all users. When enforcement is turned on, users who have not yet enabled 2FA will be prompted to do so the next time they sign in.
Dropbox App Passwords
If you use older third-party apps that connect to Dropbox and do not handle 2FA prompts correctly, Dropbox allows you to generate app-specific passwords. These bypass 2FA for that specific app while keeping your main account protected. You can create and revoke app passwords from the Security tab in your account settings.
Lost Access to Dropbox 2FA?
At the sign-in screen, click Trouble signing in? to access recovery options. You can use your backup phone number (SMS recovery), your 16-digit emergency backup code, or contact Dropbox support. For Business accounts, your team admin may also be able to reset 2FA for your account. If none of these work, Dropbox support requires identity verification before granting access.
Dropbox 2FA Security Considerations
Dropbox asks for your two-step code only in specific situations: when you sign in from a new device or browser, when you reinstall the desktop app, and occasionally when you sign in from an unfamiliar location or IP address. On devices and browsers you have marked as trusted, you will not be prompted every time. Whenever a code is entered, Dropbox also sends a notification email to your account address, so you can spot a sign-in attempt you did not make. Keep your 16-digit emergency code in a password manager rather than inside Dropbox itself โ if your account is ever compromised, backup codes stored in it are compromised too. Adding a backup phone number is worthwhile even when you use an authenticator app, because it gives Dropbox a second recovery path if your phone is lost or replaced. For Business accounts, admins can enforce two-step verification team-wide, which prevents individual members from turning it off.
Common Dropbox 2FA Mistakes to Avoid
The most common mistake is choosing SMS as your only method. SMS codes can be intercepted through SIM-swap attacks, where an attacker convinces your mobile carrier to transfer your number to a SIM card they control. A second frequent error is failing to update the backup phone number after changing numbers โ an outdated recovery number is useless in an emergency. Users also often ignore the 16-digit emergency code until they need it, only to discover they never saved it anywhere. If you switch authenticator apps, remember that most apps cannot transfer TOTP secrets between them automatically, so you must disable two-step verification and re-enable it with the new app. Finally, never share your emergency code or backup phone with anyone, and do not remove 2FA "temporarily" when connecting a third-party app โ use an app password instead. App passwords are generated from the Security tab and can be revoked at any time without weakening your main account.
A Day in the Life of Dropbox 2FA: What to Expect
After you enable two-step verification, the code prompt appears only on devices Dropbox does not recognise. Your current browser and the Dropbox desktop app keep working without interruption, and the desktop client only asks again if you reinstall it, sign out, or log in from a different machine. On the mobile app you will be asked for a code periodically; enter the 6-digit figure from your authenticator while it is still current, since the code refreshes every 30 seconds.
Codes work offline, so you can still sign in when your phone has no signal โ the TOTP calculation happens on the device itself. Every time a code is accepted, Dropbox emails you a notification, which doubles as a monitoring channel: a code entry you did not make means someone has your password and should trigger the steps in the compromised-account section below.
Keeping Shared Links and Team Spaces Safe
Two-step verification protects the login, not the files themselves. Anyone who already has a shared link to a folder can still open it, so set link passwords and expiry dates for sensitive content, and use the "Only people you invite" sharing mode for anything confidential. On Business accounts, team admins can restrict link sharing to the team and require approval before external members join team folders.
Review the Apps linked section of your Dropbox account periodically. A third-party app you authorised years ago can upload, download, or delete files through its connection. Revoke anything you do not recognise or no longer use โ revocation is instant and does not affect the files themselves.
What to Do If You Spot an Unknown Sign-In on Dropbox
The notification email that accompanies every code entry is your first alert. If it shows a login you did not make, change your Dropbox password immediately, then open the Security tab and sign out of all devices โ this kills every active session, including the attacker's. Next, check the Devices list and remove anything you do not recognise, then review linked apps as described above.
After securing the account, check whether the same password was used elsewhere and change it there too. Re-enable two-step verification if it was switched off, generate a fresh emergency code, and watch for phishing emails in the following weeks โ attackers often follow a successful login with a message claiming your account is "suspended" in order to harvest the new credentials.
Dropbox 2FA Questions, Answered
Can I turn 2FA off once it is on? Yes, from the Security tab, after re-entering your password. On Business accounts the admin may lock the setting so individual members cannot disable it.
Is the 16-digit code a backup code? Yes. It is single-use and replaces a missing authenticator or phone number, so store it outside Dropbox โ a password manager or a printed copy.
Does 2FA slow down file sync? No. Sync continues in the background on trusted devices without any code prompts.
Do I need separate 2FA for Dropbox on every device? No. The protection is account-wide; new devices simply prompt once and can be marked as trusted.
Do I need to enter my 2FA code every time I open the Dropbox app? No. Dropbox only prompts on new or untrusted devices; once a device is marked as trusted, the app opens straight to your files with no code request.
Can I set up 2FA if I do not have a smartphone? Yes โ use SMS, or a hardware security key if you have one. A browser-based tool can also generate codes if you store the TOTP secret somewhere secure and enter it manually.
Does 2FA protect a Dropbox Family plan? The two-step verification you enable protects your own account sign-in, and each member of a Family plan has a separate login of their own to secure.