Help shape the future of Box
Welcome to Box Pulse, our product feedback tool powered by UserVoice. Got an idea for how to improve Box? Share it with us and gather support or vote on other people's ideas. Your feedback is essential to informing roadmap decisions and shaping the future of our products. Thanks for joining our community!
See user guide here.
402 results found
-
Need guest authentication by own AzureAD for external collaborators
We can require 2-FA for external users, but it’s not enough security level to some customers. So, please add the ability to require guest authentication by own AzureAD for external collaborators.
19 votes -
Box session timeout with SSO
We are currently considering implementing SSO. The SSO service we plan to use has a session timeout feature,
This feature allows us to control the session time of the IdP.
It would be great if we could log out the Box at the same time as the Idp session timeout.1 vote -
2FA - Option to select SMS or Email as opposed to both
Hi all,
We would like to have the option to select SMS as a 2FA method without having to have email as an option.
Back in April last year Box introduced the option to have email as a 2FA Method. Unfortunately we can’t have Authenticator app and SMS but no email as a setting. Either it’s Authenticator app only or we have to enable emails too.
On productions we go for the Authenticator app as that’s the most secure option, but one of our subsidiaries would like to give the option for SMS too.
Enabling emails is a major security…
3 votes -
Phone number format prompt
When setting 2FA by SMS, Box should update this part of the web site to specify exactly what format the phone number needs to be entered in.
E.g. "7797123456" and not +447797123456, 447797123456, +44(0)7797123456 etc.
Although it seems to work with or without a leading zero, it would be better to not include it as it is not part of the "phone number"1 vote -
UX switching 2FA method
Changing 2FA method requires removing first. This breaks existing shared feeds for others and is alarming.
The way you need to re-accept then go back and forth between pages refreshing each time before it shows as re-established is far from "Simple" or intuitive.1 vote -
Make 2FA by e-mail work for the accessible-site
Make 2FA by e-mail work for the accessible-site
1 vote -
Password updates
Login passwords currerntly enforce unnecessary format restrictions that are hindering the use of password generators. Characters < > cannot be used, and there also is a requiement to include at least two digits. Most hashing password generators use all printable characters (as they should), and ensure only the occurrence, but not the quantity, of character classes, i.e. 1 of each printable chartacter classes (uppercase, lowercase, numeric, special).
Suggestion: allowing all printable characters and only requiring a minimum of 1 character from each intended class (occirrence only) would make Box login passwords compliant with the vast majority of hashing password generators…
1 vote -
Whitelist domains on External Collab folders
We want the ability to be able to whitelist a domain on a specific folder for users for users of a business, within our External Collaboration folder which we use for our clients. EG, if the folder is to be collaborated with by our client "Acme", eg then:
FOLDER: External Collaboration > Customer > ACME
ACME Folder: Whitelist domain acme.com
1 vote -
Department of Defense (DoD) impact level 5
Department of Defense (DoD) impact level 5
1 vote -
"Remember me" added to login
The need to constantly log in multiple times throughout the day when using Box.com is just absolutely an awful experience. This is especially true with integrations. Every time I close a browser window and then click a link, I have to log in again. We use Box as a source for all of our content for an agency so the number of logins is high. And when we receive a link to a piece of content, we have to click "Go to my account" to log in again, which takes us to the homepage, forcing us to click the link…
2 votes -
Box Virus Scan turned on by default
Box Virus Scan turned on by default
1 vote -
password reset scheduling during holidays
I am writing to request consideration of scheduling password changes to avoid peak vacation times. As a citizen developer, I do not have a dedicated team to manage these changes and it can be difficult to find time to complete the updates while also taking time off for vacation.
I understand the importance of regularly updating passwords for security purposes, but I believe that scheduling these updates during times when fewer people are likely to be on vacation would minimize disruptions and make it easier for everyone to stay on top of this important task.
1 vote -
Provide easier ways to extend collaboration expiration
Similar to the existing post below but the request is a bit different.
https://pulse.box.com/forums/909778-help-shape-the-future-of-box/suggestions/36108211-bulk-extend-collaboration-shared-link-expirationWe have folders where there are over 100 collaborators to extend on a certain cadence and need to click the "clock" button over 100 times, which obviously is so painful. We would like to have the ability to click "checkbox" to select collaborators to extend and update them in one shot.
2 votes -
Require additional Multi-Factor Authentication for external collaborators using SSO
We can require 2-FA for external collaborators, but for external collaborators using SSO, Box does not check for whether users pass multi-factor authentication. Please add the ability to require additional multi-factor authentication for external collaborators using SSO.
4 votes -
Add collaborators automatically upon request from who wants the access.
When a new collaborator is identified but not added as a collaborator yet, he/she needs to wait until permission. To reduce this idol time, automatically permit access first upon request. Check the collaborators afterwards if required. Existing folder collaborators can designate the folder that needs this function.
1 vote -
Shared Link Password Policy
Much like the default link expiry policy we would also like one specific to forcing passwords for shared links and preferably being able to define that policy with minimum characters and complexity.
Bonus would be passwords that are auto-generated and viewable by the creator of the shared links to minimize the need for external tools.
67 votes -
Persistent cookies
Similar to Okta and Google Drive, we need the ability in Box to set use persistent cookie so the cookie doesn't expire when the browser is closed.
Google Drive allows this by default, and Okta lets us specify the policy for specific users:
( see usePersistentCookie according in https://developer.okta.com/docs/reference/api/policy/#signon-session-object)Workflow:
* launch browser, go to Okta, and log in (our IDP)
* open up the box link - everything works
* close the browser
* open the browser
* I'm still logged into Okta (since I have usePersistentCookie turned on)
* when I go to a Box link, I'm…2 votes -
Greater flexibility in watermarking configuration
Based on our documentation:
Rasterized watermarking only (default) - Provides increased security, but no resolution scaling, no searchability, no clickable links, a moderate file size overhead, and reduced usability. This watermark type can't be removed without damaging the underlying content.Customers that want to follow a higher level of security protocol when watermarking files currently have to choose which approach is more important at an EID level.
Watermarking configuration should have greater flexibility so that the choice of rasterized or vector based watermarking is done at either a folder level OR via the shield policy assignment OR both.
This provides…
2 votes -
"Automatically remove invited collaborators" - override/shorten
I have enabled "Automatically remove invited collaborators" specifically for External Collaborators, under Enterprise settings > Content & Sharing.
There are use cases (per folder) where the content owners/co-owners would like the ability to /override/ & shorten the expiration for an External Collaborator. This could be due to a contract or any other reason.
The only method to do this now, is to delete the entire folder and all content.
Example Use Case:
Enterprise settings:
- Content & Sharing > Invited collaborators expiration settings
-- Automatically remove invited collaborators
-- Remove after [ 90 ] days
-- Apply these settings to…3 votes -
Restrict the ability to create shared links for specific folders
I want to be able to disable the option to create a shared link on specific folders containing sensitive information. If I give access to an external collaborator, it means that I gave him an access with a username (his email) and password. i have the option to see if he downloaded or viewed the file. I don't want that external collaborator to create a shared link and send it to someone else.
4 votes
- Don't see your idea?