- All of your organization’s managed users
- All of your organization’s external collaborators, or just for specific external collaborators based on their domains or their email addresses
Making changes to your multi-factor authentication settings for managed users is considered a “critical action” in the Admin Console. For security reasons it is restricted to Admins, who must complete their own MFA to proceed. Co-admins are limited to read-only access for these settings.
Configuring Multi-Factor Authentication for your Managed Users
- Go to Admin Console > Enterprise Settings > Security.
- In the Multi-Factor Authentication section, enable Require multi-factor authentication for all managed users. If SSO Required is turned on, this setting will be hidden.
- Configure the Authentication Method and Authentication Frequency. See the Multi-Factor Authentication section in Enterprise Settings: Security Tab for details.
- Select Save.
When you enable and save this setting, Box sends email notifications to your existing managed users if SSO is in test mode and users do not have MFA enabled. This alerts them to log in and complete the setup of multi-factor authentication for their account. - Use MFA to authenticate this change:
- If you are already enrolled in the MFA, you need to authenticate the change using your chosen MFA method
- If you are not enrolled in any MFA, Box will send you a verification code by email. Use this code to authenticate
- When you enter the correct code, your configuration or other changes are saved. If the code is incorrect, you receive an error message.
When you enable multi-factor authentication for logins, people must log in again through the Box web app to set up the association with their mobile phone. If they do not first log into their account through the Box web app, they can’t use any mobile device to access Box.After the initial successful login, Box will remember the browser and you will not be prompted for MFA within the defined authentication frequency if you need to log in again. Only clearing the browser’s cache and cookies will re-prompt MFA.
When you enable and save this setting, Box sends email notifications to all of your existing managed users, alerting them to log in and complete the setup of multi-factor authentication for their account.
Configuring 2-step login verification for external collaborators
After you enforce 2FA, external collaborators must enroll in 2FA with Box to access your enterprise’s shared content. External collaborators who are already enrolled in 2FA with Box, or who are using an SSO provider to access their Box account, can continue to access the shared content.Making changes to your multi-factor authentication settings for managed users is considered a “critical action” in the Admin Console. For security reasons it is restricted to Admins, who must complete their own MFA to proceed. Co-admins are limited to read-only access for these settings.
- Go to Admin Console > Enterprise Settings > Security.
- In the Multi-Factor Authentication section, under External Users, select Configure or Edit Configuration.
- In the 2-Step Verification for External Collaborators dialog box, select whether to disable 2-step login, enable 2-step login for all external collaborators, or enable for - or except for - a defined set of external collaborators. If you enable 2-step login, select when it will be enforced. For more details, see the External Collaborators section in Enterprise Settings: Security Tab.
- Click Save.
- Use MFA to authenticate this change, using the method described in Multi-Factor Authentication Required for Admin Console Critical Actions.
- At the top of the page, click Save.
The External Collaborator’s experience with 2FA for External Collaborators
It is important to know how 2FA affects external collaborators. When you enforce 2FA, external collaborators can have different experiences, as summarized in this table:| External collaborator | Experience | To gain access to shared content |
|---|---|---|
| Is enrolled in 2FA with Box. | Can access shared content if enrolled with required authentication method. | N/A |
| Uses SSO to log into Box. | Can access shared content. | N/A |
|
| In the Box account window, set up 2FA from the pending invitations panel under ACTION REQUIRED in the Files page, or from the Account Settings page. |
|
| In the Box account window, set up 2FA from the pending invitations panel under ACTION REQUIRED in the Files page, or from the Account Settings page. |
| Receives an invitation email to accept the collaboration invite by signing up for a new Box account. |
|
Email Notifications when setting up 2FA for External Collaborators
Email notifications will be sent if:- Users’ EIDs have SSO in Test Mode and users do not already have 2FA enabled, or
- Users’ EIDs do not have SSO set up and users do not already have 2FA enabled
- Users are in an SSO-Required EID, and/or
- Users already have 2FA
The managed user’s experience with 2FA for external collaborators
Content owners who have active collaborations with external collaborators receive an email notification when an external collaborator accepts the collaboration and enables 2FA. This applies only when SSO is in Test Mode. External collaborators who use an SSO provider in Required Mode can continue to access the shared content. When you enable 2FA for external collaborators, Box evaluates existing file and folder collaborations with external users. If an external collaborator does not meet your 2FA requirements, Box places those collaborations in a pending state. The collaborator must enable a 2FA method that meets your enterprise’s requirements to regain access. For example, if you require security keys, SMS does not meet the requirement. After they meet the requirement, Box automatically accepts all pending collaborations from your enterprise and sends invitation-acceptance emails to the relevant content owners.Box does not remove an external collaborator from a file or folder only because 2FA requirements change. If the collaborator already had access, the collaboration remains. They must update or verify their security settings, such as enabling the required 2FA method, to regain active access.An external collaborator loses the collaboration only if the content owner deletes the content, the content owner revokes access, or a pending invitation expires after 30 days.
Automatically re-accepting collaborations can generate a large number of email notifications. Communicate this change before you enforce it, and review existing collaborations first.