Force user email validation for external collaborators
In the case that Person P from Company B is laid off and p@b.com mailbox is turned off , the Box.com External Account is still active with whatever security it had. Person P can keep accessing Box.com and CNMLLP content without CNMLLP or Company B knowing about it. Also, external bad actors can guess passwords and gain access, and there's no visibility. If we can force an external collaborator to click a link in a email, for instance in a browser-initiated Password Reset that sends an email right away, then it proves that Person P still has access to P@C.com and is probably that person
1
vote
Anonymous
shared this idea