File Access Sits Behind The Policy You Already Run
People sign in to Files.com through Duo, so Duo's MFA and device-trust checks happen before anyone reaches a file. An unmanaged laptop is stopped at sign-in, not after it has your files.
Connect Files.com to Cisco Duo with SAML. Now Duo's MFA and device-trust checks run before anyone opens a file. The access policy your security team already uses can now cover file transfer too. And Files.com adds its own 2FA on SFTP, FTP, and WebDAV.
No credit card required · 7-day free trial · Live in minutes



Real companies. Real file flows. Real results.





















Your security team already runs Cisco Duo for strong sign-in and device trust. Connect Files.com to Duo, and signing in to your files runs through that same policy.
People sign in to Files.com through Duo, so Duo's MFA and device-trust checks happen before anyone reaches a file. An unmanaged laptop is stopped at sign-in, not after it has your files.
Duo's MFA runs in front of every sign-in. Some accounts aren't managed by Duo. For those, Files.com adds its own 2FA, including hardware keys and authenticator apps.
Strong sign-in doesn’t stop at the website. Files.com can require its own 2FA on the file-transfer protocols too. A partner connecting over SFTP gets the same check as someone signing in on the web, so the protocol nobody usually guards is locked down like everything else.
Files.com connects to Duo through Duo's Generic SAML Service Provider. That's the standard sign-in method. Turn on SCIM and it syncs your users automatically too.
Duo handles strong sign-in: who the person is, and whether their device is trusted. It doesn't decide which folders that person can open once inside. Files.com adds that part. You get folder-by-folder access and a full record of every sign-in and sync.
Set access per person or group, folder by folder. You get nine levels, the option to block a folder, and fenced-off admins. Your Duo groups feed straight into Files.com folder permissions, so nobody sets file access by hand.
Every sign-in, sync, and permission change is captured in the Files.com audit log. The SCIM sync gets its own detailed log. It’s the record a compliance review asks for.
Files.com uses hardware keys and authenticator apps as the main 2FA methods. SMS and email are backups only. It's the same approach your Duo security team already takes.
4,000+ organizations rely on Files.com, and SSO against Duo, Okta, Entra ID, or any SAML provider is how enterprise deployments keep file access tied to sign-in policy.
With SCIM 2.0, Duo creates, updates, and turns off Files.com users and groups on its own. Group memberships sync too, and Files.com maps them to folder permissions and admin roles. Nobody has to touch Files.com.
For accounts Duo doesn't manage, Files.com 2FA covers Yubikey (WebAuthn and Native OTP), other hardware keys, authenticator apps, SMS, and email. Yubikey Native OTP and authenticator-app codes work over SFTP, FTP, and WebDAV. That's strong sign-in on the file-transfer protocols, not just the browser.
This is the main connection. Add Files.com as an app in Duo through its Generic SAML Service Provider, then point Files.com back at Duo. Now your team signs in through Duo, and Duo’s MFA runs as part of that login. Your people get one less password to manage, and you get one place to enforce the policy.
Turn on SCIM to have Duo create, update, and remove Files.com users and groups by itself. This is what shuts off access automatically when someone leaves.
There's nothing extra to set up. When SCIM is off, Files.com creates the account the first time a person signs in through Duo. It's good for getting started fast. JIT can't remove people, so add SCIM when you need that.
A person clicks Sign in with Duo, passes Duo's MFA check, and lands in Files.com. Strong sign-in is confirmed before they reach any file.
Assign someone to Files.com in Duo. SCIM creates their account, puts them in the right groups, and applies their folder permissions. All on its own.
Turn someone off in Duo and the next sync shuts off their Files.com account across the web, SFTP, and the Desktop App at once. There’s no second user list to clean up.
A partner account that Duo doesn't manage can be required to use a Yubikey for 2FA. The Yubikey works on their SFTP connection too.
The folder-by-folder access, with nine levels, that your Duo groups feed into.
Learn MoreWhere every Duo sign-in, sync, and permission change is recorded, ready to export for a compliance review.
Learn MoreHow 2FA and folder permissions reach SFTP, FTP, and WebDAV, not just the browser a person signs into.
Learn MoreRules that decide how long files stick around once someone has put them in Files.com.
Learn MoreA two-partner model gave the manufacturer a repeatable way to move each counterparty off its self-hosted SFTP server while automating delivery, archiving, and expiration.
Read The Story
Files.com preserved the factory’s existing SFTP workflow while giving the manufacturer directory-driven access, directional permissions, and unified logging.
Read The Story
Files.com is the stable client-facing endpoint, with self-service password resets, key-based SFTP, and MFA, so the bank rearranges the infrastructure behind it without a client call.
Read The Story
“Files.com's strengths are simplicity, ease of use, and the cloud connectors. We don't have to invent custom infrastructure for every partner.”

“Files.com is versatile — it can manage many different situations from a single platform. We've consolidated multiple tools onto it.”

“Files.com is robust and scales to a large enterprise. We get multiple files per minute, per second — and we're a 24/7 organization, so everything has to always be up.”

Here’s how sign-in, provisioning, and 2FA work once Duo sits in front of your Files.com site.
Yes. Files.com connects to Cisco Duo over SAML, set up through Duo's Generic SAML Service Provider. Your team signs in through Duo, so Duo's MFA runs before they reach Files.com.
Yes. Duo's MFA check runs as part of the sign-in, before the person is let into Files.com. For outside accounts Duo doesn't manage, Files.com can also require its own 2FA, which covers SFTP, FTP, and WebDAV.
Yes. With SCIM 2.0, Duo creates, updates, and turns off Files.com users and groups on its own. If you don't turn on SCIM, Files.com instead makes accounts on first login (JIT), but JIT can't turn people off.
Files.com supports Yubikey WebAuthn (recommended), Yubikey Native OTP, other WebAuthn hardware keys, authenticator apps, SMS, and email. Hardware keys and authenticator apps are the main methods; SMS and email are backups. Yubikey Native OTP and authenticator-app codes work over SFTP, FTP, and WebDAV.
No. Signing in through Duo works for the website and the Files.com Desktop App. SFTP, FTP, and WebDAV connections authenticate with an SSH key, an API key, or a password. Password sign-ins on those protocols can still be required to carry a Files.com 2FA code.
Files.com connects to Cisco Duo through Duo's Generic SAML Service Provider application. Files.com publishes its SAML metadata: the entity ID and ACS URL. Paste those into the Duo app, then copy Duo's IdP metadata back into Files.com's SSO settings. Once linked, every Files.com web and Desktop App login routes through Duo and its MFA.
Yes. When Duo provisions users into Files.com over SCIM 2.0, it syncs group memberships, and Files.com maps those groups to folder permissions and admin roles. Access follows the groups you already manage in Duo, with no per-user setup inside Files.com.
Yes. Every login lands in the immutable Files.com audit log with its authentication context, alongside every file action that session performed. The record covers who got in, how, and what they touched.
Yes. Internal users sign in through Duo while outside partners use local Files.com credentials scoped to their own folders. Files.com 2FA can be required on those partner accounts too.
Start a 7-day free trial. Connect Duo with SAML, sign in with an MFA challenge, and see your file transfer sit behind the same access policy as everything else.
No credit card required • 7-day free trial • Live in minutes