Help shape the future of Box
Welcome to Box Pulse, our product feedback tool powered by UserVoice. Got an idea for how to improve Box? Share it with us and gather support or vote on other people's ideas. Your feedback is essential to informing roadmap decisions and shaping the future of our products. Thanks for joining our community!
See user guide here.
210 results found
-
File criteria exclusion list for Box Shield classification policies
When setting up classification policies, Omnicell, Inc., would like to be able to create a list of custom terms to exclude, in addition to the existing ability to designate file criteria that will trigger application of a classification label. This would reduce the number of documents that will incorrectly have a classification applied when auto-classification is enabled. For example, Omnicell has a lot of content with dummy PHI in their environment - this content is allowed to be stored in Box and should not be classified; however, they also want to protect actual PHI that may be stored in Box,…
2 votes -
Shield Malware Threat Detection False Positives on Excel Documents with Macros
Multiplan (160k ARR) turned on Malware Deep Scan and was getting 3-5 false positives per day because users across multiple departments often work on Excel Documents with Macros. Due to their process, users need to upload new versions of these Excel documents daily (they cannot use Version Control to handle this). So the IT team is being pinged every time a new version is added. This has been so overwhelming that the IT team has turned off Malware Detection. They will enable again if Macros are not accidentally flagged as potentially malicious.
38 votesThe team is evaluating the current model supporting Deep Scan to understand ways to improve detection on Microsoft file types.
-
Allow Shield Location Rule Restriction By Folder
Currently Shield's Location Restriction rule is applied to the entire EID by user/groups. It would be helpful to be able to set this up by specific folder(s) or folder structure.
Ex. Team A is not allowed to view specific content while in Location X, however Team B is able to. Currently the restriction would be set on the EID level and both teams would be under this restriction.
We could exclude group B or other groups from the rule however Group A would still be restricted from accessing other content within the EID.
1 vote -
Provide an exportable report for Shield Admin for each Anomalous Download alert
Every time an anomalous download alert is received, IT would ideally want to share a readily available report (XLSX / CSV) with the affected user's manager as they would know far more about the content and whether this is abnormal behavior. As it stands today, if the alert is not big then a manual list of folders / files is provided, or we have to run a User Activity Report (which can take some time) and then filter and cut down accordingly.
5 votes -
Folder path for Malware
Add folder path to the exclusions of the malware scan with Shield. Use case is around safe samples of Malware being housed in Box
15 votes -
Applying folder exceptions/exclusions to Classification policies
Would like to apply folder exceptions/exclusions to Classification Policies. Currently, we can apply to a selected group of folders, but we have an organizational need to be able to apply a classification policy to all content and add a small selection of folders to exclude from that classification policy.
1 vote -
Additional info in Anomalous Download Shield e-mail notifications
It would be very helpful to see "Previous weekly download amount", "anomalous download amount" and the "delta" on Anomalous download e-mail notifications. We use these to identify notifications that require further investigation, but these are only available by clicking into the reports which make this kind of detection difficult to scale and manage.
1 vote -
Separate download and print restrictions
We would like to use download and print restrictions in Access Policy separately.
Flexible configurations are required, when we handling sensitive files in Box.ex. We don't want to allow them to edit, but I do want to allow them to print.
5 votes -
Allow for exceptions on the Download and Print Restriction security control.
Allow for exceptions on the Download and Print Restriction security control.
We want to restrict users from downloading files that have been identified as having PII. However, we would like a mechanism to allow users that have a business reason to download files. Either through a 'User Justification' similar to the 'External Collaborators Restriction' security policy or an approval workflow.
1 vote -
Allow groups to be specified as 'notified to' in Box Shield Threat Detection Rules
Only user accounts can be specified for the 'Notification Destination' of the Threat Detection rules in Box Shield.
Since maintenance is required when the person in charge changes, it should be possible to specify a group.■In Japanese:
Box shieldに存在する検出ルールの「通知の送信先」は、ユーザーアカウントのみが指定できます。
担当者が変わったときメンテナンスが必要になるので、グループを指定できるようにしてください。1 vote -
Anomalous Download Alerts for external users
For the Anomalous Download Alerts, I would like it to apply to external users too so that if they are invited to our tenant's folder and they start downloading a lot I get an alert.
14 votes -
Whitelisting file types in Malicious Content scanning in Box Shield
We are currently seeing a large number of non-malicious files being marked by Deep Scan as malicious, resulting in a lot of false positives. These are files such as .gif or .doc. The primary way to reduce the false positive rate would be to improve Deep Scan's scanning capability. However, I think it would also be beneficial to be able to exclude certain file types that are unlikely to include malware (e.g. .gif) from being scanned.
3 votes -
Shield access policy to restrict shared link creation
Have the option to restrict shared link creation with Box Shield access policy
1 vote -
Shield alert to show more than 90 days
Currently the Shield dashboard only show up to 90 days of alerts.
I would like to have the option to have all of the past alert and be able to filter it by custom date filter.31 votes -
Display settings for classification labels
We would like to be able to temporarily not display (not disclose) classification labels within a tenant after they are created, but in that case, we need to delete all classification label settings, and it is time-consuming to set them each time, so we would like to be able to select whether to show or hide them.
2 votes -
Better information on Alert Information for Location Detection Rules
Please add the country below the IP on a Shield Alert Email for Allowed countries Detection rules notification. This keeps us from having to log into box to see what country the violation occurred in..
3 votes -
Export Control (ITAR/EAR) support by Box Shield (Increase the maximum number of Shield Classifications & Applying a classification label to
In the case of having global offices/teams, contents related to Export control are dispersed globally. However, the contents need to be in compliance for Export control.
The following two enhancements work well for supporting ITAR/EAR with dispersed contents in one Box entity:
1. Increase the maximum number of Shield Classifications - There is a limitation Classification (it's 25) now. To create combination label via country-base for ITAR/EAR, it requires a larger number of classifications.
2. Applying a classification label to a specific group - this ability is required to support large number of Classification (above enhancement).23 votes -
Ability to configure Box shield alerts
Be able to set Shield alert priority based on the severity (quantity, amount, % change) of the Box Shield anomalous behavior. Today the Shield alerts are static and apply to the category as whole and not related to a quantifiable measure of risk. a 100% increase is treated the same as a 10,000% increase.
4 votes -
Secure admin only download of 'malicious' files for analysis
Admins should be able to download Box Shield tagged malware without marking the file safe for everyone. That way a security admin could download the file and scan it with their own security tools. That’s the only real way to diagnose if a file is malicious or just a false positive.
Asking us to mark it safe by chatting with the user is far from best practice
1 vote -
Allow bulk action on Shield malicious content alerts
Allow bulk action on BoxShield malicious content alerts. We have seen an extremely high rate of positives. Individually marking files as safe is not scalable, and need to be able to do bulk updates.
24 votes
- Don't see your idea?