Disable Box Drive for External Users
Due to support or data privacy concerns, it would be beneficial to have the ability to prevent external users from utilizing Box Drive for files shared with them.
-
Masahiko
commented
Strongly agree — this is a real gap for security-first deployments.
We've disabled Box Drive across our entire tenant as a deliberate security control, and no one in our organization uses it. But that control only reaches our own users. External collaborators can still mount content we've shared with them via Box Drive on their own machines, and as admins we have no way to prevent it.
That's the problem. We have no visibility into how an external user's Windows device is managed — patch level, EDR coverage, disk encryption, local admin rights. Once our files are synced down to an endpoint like that, a compromise on their side becomes a compromise of our data, through no fault of our own controls. We can harden our devices; we can't harden theirs, and today we can't opt out of the risk either.
Security was the primary reason we standardized on Box, so it's frustrating that this one path is outside admin control. An enterprise-level setting to block Box Drive access for external collaborators (ideally with per-folder or per-collaboration granularity) would close it. This is a high-priority need on our side, and I'd expect it matters to any customer in a regulated or security-sensitive industry.