Skip to content

Help shape the future of Box

Welcome to Box Pulse, our product feedback tool powered by UserVoice. Got an idea for how to improve Box? Share it with us and gather support or vote on other people's ideas. Your feedback is essential to informing roadmap decisions and shaping the future of our products. Thanks for joining our community!

See user guide here.

  • Hot ideas
  • Top ideas
  • New ideas
  • My feedback

378 results found

  1. pdf on box is downloadable, so the hard work of authors is not protected and can be distributed. Box must prevent this.

    I was able to download a protected pdf on box. I obtained it from Cambridge. I am a school teacher, they gave me a box link to their book which they said I can use for a free months. But I was able to download the pdf. Box must make its embedded pdfs more protected to prevent illegal distribution of ebooks.

    1 vote

    We're glad you're here

    Please sign in to leave feedback

    Signed in as (Sign out)

    We’ll send you updates on this idea

    0 comments  ·  Security  ·  Admin →
    How important is this to you?

    We're glad you're here

    Please sign in to leave feedback

    Signed in as (Sign out)
  2. Enforcing Security on Public shared link

    Public link is a good option to share a file with ones who can not have box account for various reasons.

    However to share a sensitive file with such parties, Whether the password and expiry can be enforced to set on a public shared link via security policy for a given file classification?

    6 votes

    We're glad you're here

    Please sign in to leave feedback

    Signed in as (Sign out)

    We’ll send you updates on this idea

    2 comments  ·  Security  ·  Admin →
    How important is this to you?

    We're glad you're here

    Please sign in to leave feedback

    Signed in as (Sign out)
  3. Box.COM doesn’t identify PaloAlto Traps as an Enterprise AV/EDR vendor for Mac devices

    Box.COM doesn’t identify PaloAlto Traps as an Enterprise AV/EDR vendor for Mac devices

    1 vote

    We're glad you're here

    Please sign in to leave feedback

    Signed in as (Sign out)

    We’ll send you updates on this idea

    0 comments  ·  Security  ·  Admin →
    How important is this to you?

    We're glad you're here

    Please sign in to leave feedback

    Signed in as (Sign out)
  4. capture admin role changes in event stream

    currently we receive the same event (‘Change admin role: privilege Admin role for user’) in event stream for any admin role change,
    although we performed a different action
    we would like a more detailed log
    i.e. activities like remove/add and providing the specific role as well

    1 vote

    We're glad you're here

    Please sign in to leave feedback

    Signed in as (Sign out)

    We’ll send you updates on this idea

    0 comments  ·  Security  ·  Admin →
    How important is this to you?

    We're glad you're here

    Please sign in to leave feedback

    Signed in as (Sign out)
  5. Shared Links Expiration and Turn Off

    Create the ability exist to mass update shared link expiration dates and/or turn off the shared links, using folder and file ids.

    5 votes

    We're glad you're here

    Please sign in to leave feedback

    Signed in as (Sign out)

    We’ll send you updates on this idea

    2 comments  ·  Security  ·  Admin →
    How important is this to you?

    We're glad you're here

    Please sign in to leave feedback

    Signed in as (Sign out)
  6. (Drop) Box Vault - Password Protect File Feature

    Enable password protection for individual files or at master level for sensitive data (ie: Dropbox Vault).

    https://www.dropbox.com/features/security/vault

    1 vote

    We're glad you're here

    Please sign in to leave feedback

    Signed in as (Sign out)

    We’ll send you updates on this idea

    0 comments  ·  Security  ·  Admin →
    How important is this to you?

    We're glad you're here

    Please sign in to leave feedback

    Signed in as (Sign out)
  7. Send a "here's how your items are shared" report to each user periodically

    One of the most common sources of security breaches is due to a user inadvertently sharing an item more broadly or for longer than they intended.

    A simple way to help limit those sorts of security breaches would be for Box to email every user a report periodically (configurable by the admin, but roughly monthly) that said "Here's how everything you own is shared with other people, and here's a link to the KB article that'll tell you how to fix it if it's not what you want", then showed a report of their folders, files, and shared links, with…

    80 votes

    We're glad you're here

    Please sign in to leave feedback

    Signed in as (Sign out)

    We’ll send you updates on this idea

    not planned  ·  4 comments  ·  Security  ·  Admin →
    How important is this to you?

    We're glad you're here

    Please sign in to leave feedback

    Signed in as (Sign out)
  8. Device Pinning, "Last Check-In"

    instead of "install time" for device pinning, the customer would like to see "Last check in".

    1 vote

    We're glad you're here

    Please sign in to leave feedback

    Signed in as (Sign out)

    We’ll send you updates on this idea

    0 comments  ·  Security  ·  Admin →
    How important is this to you?

    We're glad you're here

    Please sign in to leave feedback

    Signed in as (Sign out)
  9. Add more details in device trust logs

    If device trust is checking for a setting (for example OS version), then the logs should show the actual version detected. This should be for every setting Box enables you to validate. It should also have more detail about the login attempt (hostname (not just IP address), OS, Box Drive vs Box web vs etc).

    Further there should be a new event in the logs, DEVICETRUSTCHECKPASSED, with similar details so that we know the check happened and what values Box found when authorizing the device. Only having DEVICETRUSTCHECKFAILED provides no audit trail for showing…

    1 vote

    We're glad you're here

    Please sign in to leave feedback

    Signed in as (Sign out)

    We’ll send you updates on this idea

    0 comments  ·  Security  ·  Admin →
    How important is this to you?

    We're glad you're here

    Please sign in to leave feedback

    Signed in as (Sign out)
  10. In China we have to use (redacted) as box.com is blocked, and after few weeks not logining (Box Alternate domain)

    One of our vendor can’t login box with his own company email account. And then can’t share file with him to update.

    I found he can’t see the “i’m not a robot” after login (Box Alternate domain) to fill in password as he doesn’t have VPN enabled

    after i use his account to login and validated this, he can then login normally.

    Looks if you don’t use box for few weeks, it will ask you to validate via this google authentication way which he can’t see it without VPN.

    How to fix this for china users if they can't use…

    2 votes

    We're glad you're here

    Please sign in to leave feedback

    Signed in as (Sign out)

    We’ll send you updates on this idea

    0 comments  ·  Security  ·  Admin →
    How important is this to you?

    We're glad you're here

    Please sign in to leave feedback

    Signed in as (Sign out)
  11. Get details on shared link without owner

    Airbnb and other companies when going through a large
    deprovision of accounts run into issues where someone shares a link of the file after the owner is
    no longer there and the collaboration is removed. But with just the file link, there is no way for the admin to get anymore details on the file.

    The feature request is the ability to get more details on a file through the link.

    1 vote

    We're glad you're here

    Please sign in to leave feedback

    Signed in as (Sign out)

    We’ll send you updates on this idea

    0 comments  ·  Security  ·  Admin →
    How important is this to you?

    We're glad you're here

    Please sign in to leave feedback

    Signed in as (Sign out)
  12. Add support to get Security logs event using Box Eventlog API

    Currently Eventlog API doesn't logs event related to enterprise setting changes by admins. These logs are available using Security report (https://app.box.com/master/reports/security) but are not available through API.
    For reference (https://community.box.com/t5/Platform-and-Development-Forum/How-to-get-security-logs-using-Box-Eventlog-API/m-p/79313#M7447)

    8 votes

    We're glad you're here

    Please sign in to leave feedback

    Signed in as (Sign out)

    We’ll send you updates on this idea

    0 comments  ·  Security  ·  Admin →
    How important is this to you?

    We're glad you're here

    Please sign in to leave feedback

    Signed in as (Sign out)
  13. Box lock security

    We just discovered that a user with viewer-uploader permissions can unlock files which our team believes is an unacceptable security flaw. The viewer-uploader level of security is required for a user to create a folder within a folder that we have granted them access to, but other than that level of editing our external invited partners should not have the ability to manage a security feature such as unlocking a file or folder.

    1 vote

    We're glad you're here

    Please sign in to leave feedback

    Signed in as (Sign out)

    We’ll send you updates on this idea

    0 comments  ·  Security  ·  Admin →
    How important is this to you?

    We're glad you're here

    Please sign in to leave feedback

    Signed in as (Sign out)
  14. Force external collaborators to sign in using 2-step verification or dual authentication for access to specified shares.

    Force external collaborators to sign in using 2-step verification or dual authentication for access to specified shares.

    2 votes

    We're glad you're here

    Please sign in to leave feedback

    Signed in as (Sign out)

    We’ll send you updates on this idea

    1 comment  ·  Security  ·  Admin →
    How important is this to you?

    We're glad you're here

    Please sign in to leave feedback

    Signed in as (Sign out)
  15. True Client IP vs Accelerator IP in Audit Logs

    To improve download speeds, Box automatically leverages "accelerator" hosts on various cloud/hosting providers around the world. When this happens, the "client IP address" recorded in the audit logs is the accelerator IP address, and not the true endpoint IP address. This results in false positives in "impossible travel" analytics, and could result in false negatives. We request that the audit logs be enhanced to capture the true client IP and accelerator IP (where applicable) as separate fields in the logs.

    2 votes

    We're glad you're here

    Please sign in to leave feedback

    Signed in as (Sign out)

    We’ll send you updates on this idea

    0 comments  ·  Security  ·  Admin →
    How important is this to you?

    We're glad you're here

    Please sign in to leave feedback

    Signed in as (Sign out)
  16. Set default permission to Previewer

    We would like the ability to set the default permission to Previewer. Most users are not changing the default permission we have setup when sharing. Being able to set the default permission to Previewer helps us manage security even better.

    4 votes

    We're glad you're here

    Please sign in to leave feedback

    Signed in as (Sign out)

    We’ll send you updates on this idea

    1 comment  ·  Security  ·  Admin →
    How important is this to you?

    We're glad you're here

    Please sign in to leave feedback

    Signed in as (Sign out)
  17. Allow SSO users to remove their external password again

    Since I as a user can set up an external password for my SSO account, I'd like to also be able to remove that external password when I no longer need it. This a) removes an unnecessary login method and therefore improves security and b) alleviates the need for me to regularly change a password I no longer have any use for.

    Currently this requires going through Box support (and potentially an enterprise's own internal support hierarchy before that, as in my case), whereas it could also be a simple link/button next to the "Change Password" link in my account…

    1 vote

    We're glad you're here

    Please sign in to leave feedback

    Signed in as (Sign out)

    We’ll send you updates on this idea

    0 comments  ·  Security  ·  Admin →
    How important is this to you?

    We're glad you're here

    Please sign in to leave feedback

    Signed in as (Sign out)
  18. Cylance

    Please add Cylance to the list of Antivirus vendors as part of the Box Device Trust settings!

    2 votes

    We're glad you're here

    Please sign in to leave feedback

    Signed in as (Sign out)

    We’ll send you updates on this idea

    0 comments  ·  Security  ·  Admin →
    How important is this to you?

    We're glad you're here

    Please sign in to leave feedback

    Signed in as (Sign out)
  19. Can we get a report that shows WHY a device failed Device Trust?

    Can we get a report that shows WHY a device failed Device Trust?

    1 vote

    We're glad you're here

    Please sign in to leave feedback

    Signed in as (Sign out)

    We’ll send you updates on this idea

    0 comments  ·  Security  ·  Admin →
    How important is this to you?

    We're glad you're here

    Please sign in to leave feedback

    Signed in as (Sign out)
  20. Include types of virus for Virus alert email

    Include which type of virus contained in virus notification alert email. If types of virus includes in alert, admin is able to identify that alert email was accurate.

    3 votes

    We're glad you're here

    Please sign in to leave feedback

    Signed in as (Sign out)

    We’ll send you updates on this idea

    0 comments  ·  Security  ·  Admin →
    How important is this to you?

    We're glad you're here

    Please sign in to leave feedback

    Signed in as (Sign out)
1 2 6 8 10 18 19
  • Don't see your idea?

Feedback and Knowledge Base