Skip to main content
Admins can enforce a required recipient verification method for the users and groups they choose. When a verification method is enforced, senders must use that method for every recipient on a signature request. This helps enterprises maintain consistent security and compliance across the organization.

Overview

Admins can configure recipient authentication enforcement in the Additional Recipient Verification section of the Box Sign tab in the Admin Console. From the Required Recipient Verification drop-down list, admins can choose the specific method to enforce. The list includes the following options:
  • Box Login – recipients log in to their Box account before signing.
  • SMS Authentication – recipients verify their identity through an SMS text message.
  • CAC/PIV Card – recipients authenticate with a Common Access Card (CAC) or Personal Identity Verification (PIV) smartcard. Available only with the Box Sign CAC/PIV Add-On Pack.
For details about each method, see Additional recipient authentication. Admins can enforce a verification method for all users in your enterprise or for a selected list of users and groups.
Admin Console Box Sign tab with the Additional Recipient Verification section and the Required Recipient Verification drop-down list open, showing Box Login, SMS Authentication, and CAC/PIV Card options.
This setting does not apply to 21 CFR Part 11 requests. Those requests continue to use Box Login as the verification method. For more information, see 21 CFR Part 11 compliance support.

Requirements for CAC/PIV

CAC/PIV smartcard authentication is available on Enterprise Plus and Enterprise Advanced plans only and requires the Box Sign CAC/PIV Add-On Pack. For more information, see CAC/PIV e-signature authentication. To enforce CAC/PIV for a user, both of the following must be true:
  • The user has permissions enabled for CAC/PIV.
  • The user has permissions enabled for Required Recipient Verification.
If you turn on enforcement but a user does not have the matching CAC/PIV permission, the enforcement does not apply to that user. The Admin Console indicates this condition so you can correct the user’s permissions.

Enforcing a verification method

To enforce a recipient verification method:
  1. In the Admin Console, go to Enterprise Settings > Box Sign.
  2. In the Additional Recipient Verification section, next to Required Recipient Verification, select Edit Configuration.
  3. Choose whether the enforcement applies to all users or to a specific list of selected users and groups.
  4. From the Required Recipient Verification drop-down list, select the method you want to enforce.
  5. Select Save.

Sender experience

When a recipient authentication method is selected for a sender, that sender’s experience changes as follows:
  • Box automatically applies the enforced authentication method to every recipient in a new signature request.
  • The sender cannot send the request until the requirements for the enforced authentication method are complete.

Revising a request

Requests sent before you enforce an authentication method are not affected. When modifying an in-flight signature request, users cannot change the authentication method to one that the admin setting does not enforce. If they attempt to do so, a red banner and a validation error indicate that the sender must use the enforced verification method. The same behavior applies to shared requests. For more information, see Sharing signature requests.

Templates

Creating a template

When an authentication method is enforced, the following changes occur to template creation:
  • Box automatically sets each placeholder and recipient to the enforced method.
  • When a creator edits a template, Box displays a validation error if the creator tries to save the template with a method other than the enforced one.
When a creator saves a document as a template:
  • Unlocked template – the template automatically defaults to the enforced method.
  • Locked template – the creator cannot save the document as a template if the recipient fields are locked.

Using a template

Authentication methods configured within a template can be modified unless the template creator locks the template. When a template’s method differs from the one you enforce, the template user’s experience depends on whether the template is locked:
  • Unlocked template – if a recipient does not have an authentication method configured within the template, Box automatically sets it to the enforced method and informs the sender. If a recipient is set to any other method, the sender receives an error when they select Send, indicating that they must change the method to the enforced one.
  • Locked template – the sender is blocked from using a template if it contains a verification method that they are not permitted to use.

Batch send

When a template is set to the enforced verification method and a user runs a batch send signature request with it, the CSV file uploaded to start the batch send request must include the details for that method. Box displays a validation error if those details are missing or if a value does not match the enforced method. For more information, see Using batch send templates. Ready-sign links do not support additional recipient verification methods. If a template is set to an enforced verification method, you cannot generate a ready-sign link from that template. For more information, see Using ready-sign links.

API

When you set the authentication method through the API, Box validates the method against the sender’s permissions. If the sender belongs to an enterprise with an enforced verification method and attempts to select a different authentication method, Box returns a validation error.
Last modified on July 27, 2026