Controls is the Admin Console section where you manage the settings that enforce policy, guide member behavior, and respond to risk. Some controls depend on your Dashlane plan or what you've set up in Configurations.
Configurations for professional plans
As an admin, you can turn on or off certain controls in your professional plan.
Controls are divided into three different sections. Browser detection and alerts, Access control, and Vault management. Select a policy to learn more.
Browser detection and alerts
Risk Detection
After Credential Risk Detection is turned on, Dashlane securely and silently monitors for weak or compromised passwords entered in company-managed desktop browsers. This tool monitors passwords entered by all employees, including those who haven't created a Dashlane account and those who have an account but are currently logged out.
Credential Protection deployment
After the deployment, you can turn on Risk Detection by going to the Admin Console, Controls, selecting the checkbox next to Risk Detection.
Risk Alerts and Notifications
Risk Notifications help admins automate risk response to secure compromised, weak, or reused plan member credentials. When you set up Risk Notifications for Slack, if a plan member has one or more compromised, weak, or reused passwords, Dashlane automatically sends them a message in Slack, encouraging them to create more secure, unique passwords.
Credential Risk Alerts are security alerts that employees receive when autofilling passwords on company-managed desktop browsers. These alerts help admins automate risk response by notifying plan members about compromised, weak, or reused passwords. Credential Risk Alerts work for logged-out or no-account users as well.
AI Phishing Alerts
AI Phishing Alerts warn employees when they access a suspicious website, even if they're logged out of Dashlane or don't have a Dashlane account. Dashlane uses AI Phishing Detection to analyze websites for suspicious patterns.
Custom rules
Custom rules: Hides Vault phishing alerts and AI Phishing Alerts for trusted domains to reduce false positives.
As an admin of an organization with Credential Protection, and if you've deployed the Dashlane extension, you can use Custom rules to hide Vault phishing alerts and AI Phishing Alerts from trusted domains and for all your organization's employees. This feature allows you to add trusted websites to reduce false positives and improve phishing alert accuracy.
Manage security alerts on your professional plan
Credential Protection deployment
To create a Custom rule:
- Open the Admin Console
-
Select Controls and select Custom rules. You can also select Phishing Alerts, Insights, and Create a rule.
-
Select Create a rule.
- Enter the domains you trust, and separate domains with a semi-colon.
- You can select Hide vault phishing alerts, Hide AI Phishing Alerts, or both based on the type of alert you want the rule to apply to.
-
You can then name the rule, give it a description, and select Save new rule.
In the Custom Rules menu, you'll be able to see all the rules you've created.
Each rule entry will include the rule name, the type of alerts it applies to, and the number of domains it covers.
From this menu, you can add new rules by selecting Create a rule or edit existing ones by clicking the pencil icon.
Tip: After a rule is created, it will be reflected in the Custom rules menu instantly, but it may take up to 60 minutes to take effect on employees' extensions.
Access control
Restrict Dashlane access to verified domains
As an admin of an organization with Credential Protection you can restrict Dashlane access to verified domains.
If you've previously deployed the Dashlane extension to company-managed devices and verified at least one domain, you can turn on this policy so users can only sign in to the extension with verified domains. This policy prevents Dashlane access from personal or unverified email accounts.
Credential Protection deployment
Domain verification for professional plans
Enforce 2-factor authentication (2FA)
Turn on the Enforce 2-factor authentication (2FA) policy to require all plan members to turn on 2FA whenever they log in from a new device. This policy is a simple yet powerful way to ensure that all members benefit from the added layer of security that 2FA provides. This policy affects all members who use a Master Password to log in.
After you turn on Enforce 2-factor authentication (2FA) for your organization, members need to turn on 2FA for their own Dashlane accounts.
Turn on 2FA for your Dashlane account
After you enforce 2FA, Dashlane prompts members who haven't turned it on the next time they log in to Dashlane.
More about 2-factor authentication
Tip: If a member loses access to their 2FA tokens, you can generate 2FA backup recovery codes for them.
More about generating 2FA recovery codes for your members
Auto-lock on exit
Turn on the Auto-lock on exit policy so that Dashlane locks automatically when anyone exits the app on iOS and Android.
Automatically log out members if inactive
Control of this policy isn't available to admins of the Dashlane Standard plan. Upgrade your plan for the advanced features and functions admins need to manage large teams.
For the Automatically log out members if inactive for policy, you can set when members are automatically logged out of Dashlane after a period of inactivity. You can choose 15, 30, or 60 minutes.
If a member's device enters a locked or screen saver state before the designated time, the policy won't activate, and Dashlane won't log out automatically.
Admin-assisted recovery
Admin-assisted recovery provides admins of professional plans with a simple, secure way to recover a member's Dashlane account if the member forgets their Master Password.
Manage admin-assisted recovery
Cryptography
Dashlane encrypts data using Argon2d. This encryption standard is on by default for all plan members and can't be changed.
Vault management
Business Space Domains
Some plans don't have Spaces or Smart Space Management. If your plan doesn't have Spaces, advise plan members to keep only work-related credentials in their accounts. By default, they can't export any data. If you want, you can allow members to export data in the Policies tab.
Turn on the Allow Export policy
You can force items into the Business Space using the Smart Space Management policy to define the domains associated with your organization.
Smart Space Management
Remove company items for revoked users
Turn off auto-login and autofill on these websites and IP addresses
Control of this policy isn't available to admins of the Dashlane Standard plan. Upgrade your plan for the advanced features and functions admins need to manage large teams.
Upgrade your plan
You can turn off auto-login and autofill on specific websites and IP addresses for all plan members. If a website in the list appears in a member's Personal Space, the member can use Dashlane auto-login autofill.
Turn off auto-login and autofill on these websites and IP addresses:
- Enter the website domain or IP numbers in the text box. To enter multiple domains or IP addresses, separate them by semicolons with no spaces between them.
- Select Save.
Members must log out and log back into their Dashlane accounts for this policy to take effect.
To allow all members to use Dashlane auto-login or autofill on these websites again, delete the domain in the text box. Then select Save.
Secure sharing
Admins can allow plan members to securely share logins, Secure Notes, and secrets through the Sharing Center in Dashlane. Secure sharing of these items is on by default. You can't allow members to share only one of the item types.
If you turn off this policy after members have already shared these items, the items remain shared.
Revoke access to a shared item
After you turn off secure sharing, members who try to share these items will receive a notification in the app that sharing has been turned off.
Allow sharing outside the company
The Allow sharing outside the company policy is off by default.
When turned on, Dashlane automatically allows sharing with people who aren't part of your plan. If turned off and a member attempts to share something outside of your plan, they'll receive an error message.
Admins can turn on Enable link sharing to allow members to generate a temporary public link to a login to share with non-Dashlane users, such as freelancers, contractors, or vendors. Allow sharing outside the company needs to be turned on first.
Admins can check the Activity Log for details. This log reveals the creator of each public link, the specific users who accessed those links, and expiration information.
Allow Export
By default, members can't export their logins. If you want to allow members to export logins, turn on Allow Export.
Vault phishing alerts
Alert members if a website or app doesn't match a saved vault item when they try to autofill or copy and paste a login. After a member trusts a site or app, they won't see the alert again.
Show rich icons for logins
Rich icons are the brand icons that appear next to logins in your Dashlane account. By default, rich icons are visible for all Dashlane customers, but customers can hide them in their Dashlane app.
As an admin, you can turn off the Show rich icons for logins policy. When off, no one on your plan can see rich icons in their app or turn the option on for their own accounts. Plan members will see the first two letters of the login name instead of the icon.
More about rich icons and privacy
Login list visibility
If you’re an admin of an organization with Password Management that doesn’t use self-hosted SSO, you can view the login list of your plan members. With login list visibility, you’ll see the plan member’s login names and the date they were created. This way you can check which business logins they need to share with other plan members before you remove them from the plan.
Additional activity logs
Control of this policy isn't available to admins of the Dashlane Standard plan. Upgrade your plan to access advanced features and functions that admins need to manage large teams.
Turn on the Additional activity logs policy to add additional activity to your Activity Log. Then, when your plan members add, share, edit, or delete logins in their Business Spaces, that information is included in your Activity Log. This additional information is also included when you download your Activity Log to a CSV file.
VPN
The VPN is available on all Dashlane apps for members of a Dashlane Team, Password Management, or Enterprise plan. The VPN isn't available to Dashlane Starter or Standard plans.
Dashlane no longer sells Team, Starter, or Standard plans. If you already have one of these plans, you can renew or switch to a Password Management, or Enterprise plan.
Compare Dashlane professional plans
Turn on the VPN policy to help members add an additional layer of privacy when browsing the internet on public networks.
More about our VPN
Upgrade your plan