Forced termination of suspicious outbound collaboration
We request implementation of a method for administrators to forcibly cancel invitations received by users under their management.
While outbound collaboration in Box is free and convenient, it is also highly dangerous.
It can be exploited by attackers seeking to misplace files or spread malicious files by sending invitations, or by employees planning to leave who receive invitations from their personal accounts to extract information.
While inbound collaboration allows logging, outbound collaboration does not even permit this, leaving administrators virtually powerless.
Currently, administrators can only take the following two actions against these highly dangerous behaviors:
① Control “future” outbound collaboration via Box Governance domain whitelisting
② Generate a list of outbound collaborations via reports
Option ① cannot address outbound collaborations that have already occurred.
Option ② only allows for advisory notifications to the affected users.
Implementation of a response method for cases where your company's users have already been invited is required.
At the very least, please enable the output of collaboration IDs in the outbound collaboration report. With this alone, you can use the API to revoke access.