The Available Without Login setting in the NetSuite File Cabinet is one of the most misused file access controls. While it is essential for websites, images, and online forms, incorrect usage can unintentionally expose files externally.
This article explains how the setting works, when to use it, and the risks administrators should understand before enabling it.
What Does “Available Without Login” Do?
The Available Without Login checkbox allows a file stored in the File Cabinet to be accessed externally without requiring NetSuite authentication.
Common examples include:
- Website images
- Logos
- Online form assets
- Public PDFs
- CSS and JavaScript files
- Marketing content
If this setting is enabled, users can access the file directly through its generated URL.
Common Use Cases
Use Case | Should “Available Without Login” Be Enabled? |
|---|
Website logo | Yes |
Public marketing PDF | Yes |
Online form image assets | Yes |
Internal process documents | No |
Employee attachments | No |
Financial exports | No |
Admin Best Practices
1. Separate Public and Internal Files
Create dedicated folders for:
- Public website assets
- Marketing downloads
- Internal operational files
- Employee attachments
Avoid mixing public and confidential files in the same folder structure.
2. Review Website Hosting Folders Regularly
NetSuite documentation recommends understanding how the following system folders behave:
- Web Site Hosting Files
- SuiteBundles
- Attachments Received
- Attachments Sent
Periodic reviews help identify files unintentionally exposed externally.
3. Avoid Storing Sensitive Files Publicly
Do not enable Available Without Login for:
- Payroll exports
- Customer financial files
- Integration credentials
- Audit documents
- Internal process documentation
Even if links are difficult to guess, public URLs should never be treated as secure storage.
4. Review File Cabinet Permissions
Only users with appropriate permissions should manage sensitive File Cabinet folders. The documentation notes that File Cabinet access depends on the Documents and Files permission and administrator access.
Additional Tips for Administrators
- Use descriptive folder names for public content
- Periodically audit externally accessible files
- Validate website assets after changing preferences
- Test changes in Sandbox before modifying production preferences
- Document which folders are intentionally public
If your organization uses SuiteCommerce or external online forms, coordinate with web developers before changing these preferences globally.
Have any tips to share with the community? Share them in the NetSuite Admin Corner.