This setting is available for Enterprise accounts only.
What content is covered
Covered content includes:- AI sessions in AI Home
- Box Automate definitions and executions
- Box Extract agents
- Content uploaded into an AI session
- An AI session saved as a Box Note in its default location
What is not covered
This setting does not change collaboration or shared link behavior for a user’s general files and folders. Those continue to follow:- Enterprise Collaboration settings
- Enterprise Shared Link settings
- Folder-level collaboration and sharing settings
- Other enterprise controls, such as Information Barriers or Shield Access Policies, where configured
Setting options
Admins choose one of three options. The selected option can only narrow collaboration and sharing relative to your enterprise’s primary external collaboration configuration. It does not expand what would otherwise be allowed. Existing collaborations are not automatically removed when a restrictive option is selected. Users cannot add new collaborations or create new shared links that violate the selected option.No additional restriction on collaboration and shared links (default)
- This is the default for every enterprise.
- No extra restriction is applied beyond what is already configured for the enterprise.
No external collaboration and no public shared links
Users cannot share covered content with people outside the enterprise, and public (open) shared links are not allowed for that content. Blocked for covered content:- External collaborators (using the same enterprise definition of ‘external’ used elsewhere in Box)
- Public / open shared links
- Collaboration with users inside the enterprise
- Non-public shared links permitted by enterprise policy
Shared link restrictions based on email domains are not part of this feature. ‘External’ is evaluated using your enterprise’s standard definition of external users. To limit collaboration by email domain, see Limit collaboration to allowlisted domains.
Restrict all collaboration and shared links
Users cannot collaborate on or create shared links for covered content with anyone - internal or external. When a user tries to invite collaborators, Box displays an error that the invite could not be sent. Error messaging can vary by product surface.Configure the setting
- Sign in to the Admin Console.
- Go to Enterprise Settings.
- Open the Content & Sharing tab.
- Locate the Additional collaboration configuration section.
- Select one of the three options:
- No additional restriction on collaboration and shared links
- No external collaboration and no public shared links
- Restrict all collaboration and shared links
- Select Save.
How this setting relates to External collaboration
The primary External collaboration setting controls sharing for your enterprise’s general files and folders. Products such as Box Automate and AI Home store owned content outside the folder structure on the Files page, so enterprises need this additional control to close the gap.
Use this setting when you want application-managed content to be more restricted than users’ files and folders. Do not use it as a replacement for your primary collaboration policy. For the primary control, see Enterprise Settings: Content & Sharing Tab.
Recommended configurations
Also review related Content & Sharing controls so overall policy stays consistent:
- External collaboration
- Shared link settings for your enterprise
- Any Shield Access Policies that further restrict sharing by classification
How this setting affects sharing
What users see depends on the selected option and the product surface:- Default: Sharing and collaboration for Automate, AI sessions, and similar items follow the same enterprise external collaboration rules users already know.
- No external / no public links: External invites and public shared links for covered content fail. Internal sharing can still succeed if otherwise allowed.
- Restrict all: Invite and shared link attempts for covered content fail with an on-screen error.