Skip to content

Help shape the future of Box

Welcome to Box Pulse, our product feedback tool powered by UserVoice. Got an idea for how to improve Box? Share it with us and gather support or vote on other people's ideas. Your feedback is essential to informing roadmap decisions and shaping the future of our products. Thanks for joining our community!

See user guide here.

  • or

528 results found

  1. 2FA - Option to select SMS or Email as opposed to both

    Hi all,

    We would like to have the option to select SMS as a 2FA method without having to have email as an option.

    Back in April last year Box introduced the option to have email as a 2FA Method. Unfortunately we can’t have Authenticator app and SMS but no email as a setting. Either it’s Authenticator app only or we have to enable emails too.

    On productions we go for the Authenticator app as that’s the most secure option, but one of our subsidiaries would like to give the option for SMS too.

    Enabling emails is a major security…

    3 votes

    We're glad you're here

    Please sign in to leave feedback

    Signed in as (Sign out)

    We’ll send you updates on this idea

    1 comment  ·  Security  ·  Admin →
    How important is this to you?

    We're glad you're here

    Please sign in to leave feedback

    Signed in as (Sign out)
  2. Require 2FA for certain content only (not globally)

    Force 2-factor / MFA based on the type of content, folder, user. etc. - natively in Box or support this functionality through IdP

    11 votes

    We're glad you're here

    Please sign in to leave feedback

    Signed in as (Sign out)

    We’ll send you updates on this idea

    not planned  ·  3 comments  ·  Security  ·  Admin →
    How important is this to you?

    We're glad you're here

    Please sign in to leave feedback

    Signed in as (Sign out)
  3. Button in the Admin Console to remove the existing 2FA without logging in as that User

    We currently have to search for the user in the admin console, log in as them, go to their personal settings, remove their existing method, then return to the admin console. If there was a button in the admin console to remove the existing 2FA without logging in as that person, it would be really handy

    1 vote

    We're glad you're here

    Please sign in to leave feedback

    Signed in as (Sign out)

    We’ll send you updates on this idea

    0 comments  ·  Admin Console  ·  Admin →
    How important is this to you?

    We're glad you're here

    Please sign in to leave feedback

    Signed in as (Sign out)
  4. Hardware security token for 2FA / MFA / Yubikey

    With the broader support of passkeys , I would like to suggest a phishing resistant WebAuthn based Authentication option for Box.

    This would open up future possibilites for convenient and secure FaceID/TouchID/Yubikey/etc authentication.

    Insurance companies are requesting it and I am sure all Box customers would benefit.

    1 vote

    We're glad you're here

    Please sign in to leave feedback

    Signed in as (Sign out)

    We’ll send you updates on this idea

    0 comments  ·  Security  ·  Admin →
    How important is this to you?

    We're glad you're here

    Please sign in to leave feedback

    Signed in as (Sign out)
  5. Your email reminders to setup 2FA are too aggressive

    Over the course of 6 hours (during the night), I received 5 emails asking me to 'Set up 2 Factor Authentication'. This is quite aggressive.

    2 votes

    We're glad you're here

    Please sign in to leave feedback

    Signed in as (Sign out)

    We’ll send you updates on this idea

    How important is this to you?

    We're glad you're here

    Please sign in to leave feedback

    Signed in as (Sign out)
  6. 2 factor authentication

    Just been chatting with the support guys ... When turning on 2FA, the first log in prompts for the auth code. However, every login after that drops back to just asking for username/password. (unless you clear your browser down every time !)

    for 2fa to be effective, the system should ask for the auth code at every login otherwise there is no point in enabling it.

    7 votes

    We're glad you're here

    Please sign in to leave feedback

    Signed in as (Sign out)

    We’ll send you updates on this idea

    on roadmap  ·  3 comments  ·  Security  ·  Admin →
    How important is this to you?

    We're glad you're here

    Please sign in to leave feedback

    Signed in as (Sign out)
  7. Authy 2 Factor Authentication.

    Include Vietnam in 2-FA or remove it from the list of countries in the menu when trying to add 2FA.

    2 votes

    We're glad you're here

    Please sign in to leave feedback

    Signed in as (Sign out)

    We’ll send you updates on this idea

    0 comments  ·  Security  ·  Admin →
    How important is this to you?

    We're glad you're here

    Please sign in to leave feedback

    Signed in as (Sign out)
  8. 2MFA Exempt

    Allow co-admins to "exempt" users from 2FA - having it solely with primary owner is not practical

    1 vote

    We're glad you're here

    Please sign in to leave feedback

    Signed in as (Sign out)

    We’ll send you updates on this idea

    How important is this to you?

    We're glad you're here

    Please sign in to leave feedback

    Signed in as (Sign out)
  9. 0 votes

    We're glad you're here

    Please sign in to leave feedback

    Signed in as (Sign out)

    We’ll send you updates on this idea

    0 comments  ·  Web App  ·  Admin →
    How important is this to you?

    We're glad you're here

    Please sign in to leave feedback

    Signed in as (Sign out)
    not planned  ·  dfisher responded

    This is not currently planned. We will revisit this with additional use case data.

  10. Two-factor authentication with authenticator apps

    It should be possible for 2FA login to be via an authenticator app as opposed to SMS. This is arguably more secure and more convenient and something competitors offer.

    3 votes

    We're glad you're here

    Please sign in to leave feedback

    Signed in as (Sign out)

    We’ll send you updates on this idea

    1 comment  ·  Security  ·  Admin →
    How important is this to you?

    We're glad you're here

    Please sign in to leave feedback

    Signed in as (Sign out)
  11. SSO exception

    Ability to have exceptions for SSO for specific amdin accounts/test users. Use case: there's a series of admin accounts we use that own folders/content in Box but aren't actual users. Now when we want to turn on SSO - we now have to have OKTA accounts for those accounts and test users, when we'd prefer to just do Box 2FA for those vs. SSO enabled for all

    28 votes

    We're glad you're here

    Please sign in to leave feedback

    Signed in as (Sign out)

    We’ll send you updates on this idea

    0 comments  ·  Security  ·  Admin →
    How important is this to you?

    We're glad you're here

    Please sign in to leave feedback

    Signed in as (Sign out)
  12. Need guest authentication by own AzureAD for external collaborators

    We can require 2-FA for external users, but it’s not enough security level to some customers. So, please add the ability to require guest authentication by own AzureAD for external collaborators.

    19 votes

    We're glad you're here

    Please sign in to leave feedback

    Signed in as (Sign out)

    We’ll send you updates on this idea

    0 comments  ·  Security  ·  Admin →
    How important is this to you?

    We're glad you're here

    Please sign in to leave feedback

    Signed in as (Sign out)
  13. advance generation of 2nd factor authentication codes

    provide an option to generate a one time code for 2 factor authentication in advance.

    We have a use case where an external organisation has provided a PC in their site where our users can log in to box, however our users are not allowed to bring their own devices (phones or laptops) onto the site.

    To continue using 2FA it would be useful if a user could generate a one time code in advance print it then use it as the 2nd factor when logging in to the machine proved by the external organisation.
    (similar to google authenticator backup…

    1 vote

    We're glad you're here

    Please sign in to leave feedback

    Signed in as (Sign out)

    We’ll send you updates on this idea

    0 comments  ·  Security  ·  Admin →
    How important is this to you?

    We're glad you're here

    Please sign in to leave feedback

    Signed in as (Sign out)
  14. Phone number format prompt

    When setting 2FA by SMS, Box should update this part of the web site to specify exactly what format the phone number needs to be entered in.
    E.g. "7797123456" and not +447797123456, 447797123456, +44(0)7797123456 etc.

    Although it seems to work with or without a leading zero, it would be better to not include it as it is not part of the "phone number"

    1 vote

    We're glad you're here

    Please sign in to leave feedback

    Signed in as (Sign out)

    We’ll send you updates on this idea

    0 comments  ·  Security  ·  Admin →
    How important is this to you?

    We're glad you're here

    Please sign in to leave feedback

    Signed in as (Sign out)
  15. Need multiple options for 2-factor authentication

    Please allow multiple options to receive a 2-factor authentication code. If I were to lose access to my cell phone or change the phone #, then I would be unable to receive a code via SMS and be locked out of Box.

    In addition, please ensure the options other than 2FA code via SMS actually are viable options. Right now, the authenticator option doesn't work - no QR code is generated by Box for me to scan with my phone. The e-mail option also doesn't work - I keep getting an error message that the default e-mail is invalid ...…

    1 vote

    We're glad you're here

    Please sign in to leave feedback

    Signed in as (Sign out)

    We’ll send you updates on this idea

    0 comments  ·  Security  ·  Admin →
    How important is this to you?

    We're glad you're here

    Please sign in to leave feedback

    Signed in as (Sign out)
  16. Check the details of SSO for external collaborators

    We can require 2-FA for external collaborators, but for external collaborators using SSO, Box does not check for whether users pass multi-factor authentication.
Please add the ability what kind of authentications(ID/Pass, MFA, Device check, IP address limitation, etc) does external collaborators passed on SSO.

    20 votes

    We're glad you're here

    Please sign in to leave feedback

    Signed in as (Sign out)

    We’ll send you updates on this idea

    0 comments  ·  Security  ·  Admin →
    How important is this to you?

    We're glad you're here

    Please sign in to leave feedback

    Signed in as (Sign out)
  17. Change primary email address but not login user

    We are a large University with affiliate organizations leveraging our Box service. These affiliate organizations do not use the University primary email address domain.
    Specifically for BoxSign, we would like be able to change some users' primary email address to their linked email address WITHOUT changing their email address used for login into Box (because they have to use SSO and 2FA).

    Would you be able to implement a fix or workaround for this scenario? Thank you.

    1 vote

    We're glad you're here

    Please sign in to leave feedback

    Signed in as (Sign out)

    We’ll send you updates on this idea

    0 comments  ·  Box Sign  ·  Admin →
    How important is this to you?

    We're glad you're here

    Please sign in to leave feedback

    Signed in as (Sign out)
  18. email MFA with FTP

    FTP only supports SMS MFA, this is a very restricting security setting, and quite frankly is a bad idea.

    PER BOX'S OWN DOCUMENTATION ( https://support.box.com/hc/en-us/articles/360043697154-Multi-Factor-Authentication-Set-Up-for-Your-Account):

    "SMS may not be available because a user is traveling, offline, or in a country that does not support 2FA through SMS."

    AS WELL AS:

    "There are known SMS security vulnerabilities, such as SIM swapping."

    Please allow us to use AT LEAST email MFA when uploading/downloading via FTP.

    1 vote

    We're glad you're here

    Please sign in to leave feedback

    Signed in as (Sign out)

    We’ll send you updates on this idea

    0 comments  ·  Security  ·  Admin →
    How important is this to you?

    We're glad you're here

    Please sign in to leave feedback

    Signed in as (Sign out)
  19. Query 2+ Metadata templates together

    I am interested in querying 2+ metadata templates together via the MD Query API. Right now, I can only query 1 template at a time.

    47 votes

    We're glad you're here

    Please sign in to leave feedback

    Signed in as (Sign out)

    We’ll send you updates on this idea

    not planned  ·  8 comments  ·  Metadata  ·  Admin →
    How important is this to you?

    We're glad you're here

    Please sign in to leave feedback

    Signed in as (Sign out)
  20. Require additional Multi-Factor Authentication for external collaborators using SSO

    We can require 2-FA for external collaborators, but for external collaborators using SSO, Box does not check for whether users pass multi-factor authentication. Please add the ability to require additional multi-factor authentication for external collaborators using SSO.

    4 votes

    We're glad you're here

    Please sign in to leave feedback

    Signed in as (Sign out)

    We’ll send you updates on this idea

    0 comments  ·  Security  ·  Admin →
    How important is this to you?

    We're glad you're here

    Please sign in to leave feedback

    Signed in as (Sign out)
  • Don't see your idea?

Feedback and Knowledge Base