Skip to main content

Authentication & Access Configuration

Files.com provides robust tools to help customers configure user authentication and access in alignment with their own policies. This article covers authentication methods, password policies, IP restrictions, session timeouts, and two-factor authentication (2FA/MFA). These features are reviewed annually as part of our SOC 2 Type II audit.

User Passwords & Authentication

Customer-managed users can authenticate with username and password credentials. Passwords are stored in a salted and encrypted format using PBKDF2 with SHA-512, and cannot be viewed or exported—hashed or unhashed.

Customers can define password requirements, including:

  • Minimum length and complexity
  • Change intervals and expiration
  • Forced resets on next login

A password strength meter aligned with the NIST SP 800-63B standard helps guide secure password creation.

Files.com supports password import in hashed formats such as raw MD5, SHA-1, or SHA-2. On first use, these are converted to our internal format.

API access is authenticated using access keys rather than passwords.

Idle Timeout & Session Management

By default, web sessions time out after 6 hours of inactivity. Customers can adjust this value using the session expiration setting in the Files.com interface.

Restricting Access by IP or Location

Customers can restrict account access based on IP address or country, either per-user or site-wide. Files.com also publishes a list of outbound IP addresses used for services such as webhooks and LDAP, which customers can whitelist internally.

Two-Factor / Multi-Factor Authentication (2FA/MFA) Configuration

Files.com supports multiple 2FA/MFA options on all plan levels, including SMS codes, Yubikey and U2F devices, and authenticator apps like Google Authenticator.

Customers on Power, Premier, and Enterprise plans can enforce 2FA/MFA requirements across all users. Files.com also supports external identity providers—such as Okta, Azure AD, and OneLogin—that may enforce 2FA policies as part of their authentication flow.

Get Instant Access to Files.com

The button below will take you to our Free Trial signup page. Click on the white "Start My Free Trial" button, then fill out the short form on the next page. Your account will be activated instantly. You can dive in and start yourself or let us help. The choice is yours.

Start My Free Trial