Protocol Access
Each user can be restricted to a specific set of data transmission protocols for connecting to Files.com. Controlling which protocols a user account can use helps you meet the security compliance regulations that apply to your business or industry.
Use the Protocol Access setting, within the user account's Privileges settings, to allow or disallow the selected user's access to FTP (including FTPS and FTPES), SFTP, WebDAV, the S3-Compatible Endpoint, Web Portal, Desktop App, and the Files.com API. Site Administrators manage these settings across the site. Workspace Administrators can change them for existing users in their own Workspace.
| Protocol Setting | API Attribute | Description |
|---|---|---|
| FTP | ftp_permission | Specifies whether the user account is allowed to connect using the FTP, FTPS or FTPES protocol. |
| SFTP | sftp_permission | Specifies whether the user account is allowed to connect using SFTP protocol. |
| WebDAV | dav_permission | Specifies whether the user account is allowed to connect using WebDAV or WebDAVS protocol. |
| S3-Compatible Endpoint | s3_compatible_endpoint_permission | Specifies whether the user account is allowed to connect using the S3-Compatible Endpoint. Defaults to allowed for new users. |
| Web, Desktop App, and API | restapi_permission | Specifies whether the user account is allowed to connect using the Files.com web portal, the Desktop App, or via the REST APIs using the HTTPS protocol. |
S3 access is independent of the combined Web, Desktop App, and API permission. An S3-only service account can have S3 allowed while other protocols are disallowed. Disabling Web, Desktop App, and API access does not block S3 connections, and changing S3 access does not change the other protocol permissions. S3 connections still require an S3-compatible API key and appropriate folder permissions.
When individual protocol permissions are in use, Site Administrators can select S3 access when creating a user, and All Supported Protocols includes S3. When a Site Administrator clones a user, the S3 selection is copied. Workspace Administrators configure protocol access on the user's details page after creating or cloning the user.
Site Administrator authority includes access to the Web Portal and API used to administer the site. The combined Web, Desktop App, and API permission therefore cannot be disabled for Site Administrators through user or group protocol settings. Use a non-administrator account when access must be limited to explicitly allowed protocols. FTP (including FTPS and FTPES), SFTP, WebDAV, and the S3-Compatible Endpoint can still be disallowed for Site Administrators.
This setting works in conjunction with the user's IP Whitelist setting and the user's Access Control by Country setting.
Group Protocol Access vs User Protocol Access
By default, protocol access can be assigned either through users or through groups. A user can connect with a protocol if it has been enabled for their user account, or if they are a member of a group with that protocol enabled.
Disallowing S3 on the user does not override a group's S3 grant. To remove the user's S3 access, remove every applicable grant, including access inherited from groups.
You can configure your site to manage all protocol access through groups. When you enable this setting, only users who are members of groups with a protocol enabled can use that protocol to connect. Protocol access for individual users is ignored, and only the group settings take effect.