AdminKaitlin K
(Admin, Box)
My feedback
47 results found
-
17 votes
AdminKaitlin K
(Admin, Box)
shared this idea
·
-
4 votes
AdminKaitlin K
(Admin, Box)
shared this idea
·
-
52 votes
AdminKaitlin K
(Admin, Box)
shared this idea
·
-
10 votes
AdminKaitlin K
(Admin, Box)
supported this idea
·
-
12 votes
AdminKaitlin K
(Admin, Box)
supported this idea
·
-
1 vote
AdminKaitlin K
(Admin, Box)
shared this idea
·
-
20 votes
AdminKaitlin K
(Admin, Box)
shared this idea
·
-
17 votes
AdminKaitlin K
(Admin, Box)
supported this idea
·
-
71 votes
AdminKaitlin K
(Admin, Box)
supported this idea
·
-
6 votes
AdminKaitlin K
(Admin, Box)
supported this idea
·
-
74 votes
Support for FIDO2/WebAuthn security key for authentication into Box is currently in development
An error occurred while saving the comment
AdminKaitlin K
(Admin, Box)
supported this idea
·
-
32 votes
AdminKaitlin K
(Admin, Box)
supported this idea
·
-
82 votes
AdminKaitlin K
(Admin, Box)
supported this idea
·
-
12 votes
AdminKaitlin K
(Admin, Box)
supported this idea
·
-
38 votes
This is currently under review for inclusion in our roadmap for 2026. We will update the status of this request toward the end of 2025 when our review is finalized.
AdminKaitlin K
(Admin, Box)
supported this idea
·
-
15 votes
AdminKaitlin K
(Admin, Box)
supported this idea
·
-
166 votes
Instead of “require password” security control, we intend to support “Require OTP” requirement for public links (via SMS, Email, or TOTP). I wanted to share where we are headed. We do not plan on delivering this ask as is, but we do intend to solve the security use case behind it.
Please comment if you disagree.
AdminKaitlin K
(Admin, Box)
supported this idea
·
-
50 votes
AdminKaitlin K
(Admin, Box)
supported this idea
·
-
136 votes
AdminKaitlin K
(Admin, Box)
supported this idea
·
-
7 votes
AdminKaitlin K
(Admin, Box)
supported this idea
·
Box only supports MFA and TOTOP options for 2FA external users. There is a need for FIDO2 (phising-resistant) requirements as an option for external sharing.
This process is not only secure but also user-friendly. There's no need for users to remember extra passwords or carry around additional hardware tokens. There is no need to install additional software; all the major browser support this out of the box. The device and browser do all the heavy lifting.
Per the updated guidelines from the National Institute of Standards and Technology (NIST), the requirement is that internal users must use phishing-resistant MFA, while external users should be given the option to use such a method. While TOTP and SMS codes provide an extra layer of security, they can be susceptible to phishing attacks and thus are not considered phishing-resistant and as such do not meet the requirement.