Support mapping a single Microsoft Entra ID tenant to multiple Box enterprises (MPIP–Box Shield label integration)
Request: Allow a single Microsoft Entra ID tenant to be connected to multiple Box enterprises, so that MPIP sensitivity labels can be mapped to Box Shield classifications in each of them.
Background:Currently, the MPIP sensitivity label to Box Shield classification integration can only be established between one Microsoft Entra ID tenant and one Box enterprise (1:1).
However, many organizations operate a single Entra ID tenant while maintaining multiple separate Box enterprises — for example, group companies whose subsidiaries keep their content stores separated but share a single corporate identity provider and a single Purview governance policy.
Under the current 1:1 limitation, only one Box enterprise can inherit the organization's MPIP sensitivity labels. The remaining enterprises cannot consume them at all, so Shield classifications and policies must be maintained manually and separately, which undermines the value of centrally governed labeling.
This 1:N topology is already common with SSO — a single Entra ID tenant can serve as the IdP for multiple Box enterprises today, and many customers run exactly that configuration. Customers naturally expect the MPIP–Shield integration to follow the same model.