Overview
Admins can configure recipient authentication enforcement in the Additional Recipient Verification section of the Box Sign tab in the Admin Console. From the Required Recipient Verification drop-down list, admins can choose the specific method to enforce. The list includes the following options:- Box Login – recipients log in to their Box account before signing.
- SMS Authentication – recipients verify their identity through an SMS text message.
- CAC/PIV Card – recipients authenticate with a Common Access Card (CAC) or Personal Identity Verification (PIV) smartcard. Available only with the Box Sign CAC/PIV Add-On Pack.

This setting does not apply to 21 CFR Part 11 requests. Those requests continue to use Box Login as the verification method. For more information, see 21 CFR Part 11 compliance support.
Requirements for CAC/PIV
CAC/PIV smartcard authentication is available on Enterprise Plus and Enterprise Advanced plans only and requires the Box Sign CAC/PIV Add-On Pack. For more information, see CAC/PIV e-signature authentication. To enforce CAC/PIV for a user, both of the following must be true:- The user has permissions enabled for CAC/PIV.
- The user has permissions enabled for Required Recipient Verification.
Enforcing a verification method
To enforce a recipient verification method:- In the Admin Console, go to Enterprise Settings > Box Sign.
- In the Additional Recipient Verification section, next to Required Recipient Verification, select Edit Configuration.
- Choose whether the enforcement applies to all users or to a specific list of selected users and groups.
- From the Required Recipient Verification drop-down list, select the method you want to enforce.
- Select Save.
Sender experience
When a recipient authentication method is selected for a sender, that sender’s experience changes as follows:- Box automatically applies the enforced authentication method to every recipient in a new signature request.
- The sender cannot send the request until the requirements for the enforced authentication method are complete.
Revising a request
Requests sent before you enforce an authentication method are not affected. When modifying an in-flight signature request, users cannot change the authentication method to one that the admin setting does not enforce. If they attempt to do so, a red banner and a validation error indicate that the sender must use the enforced verification method. The same behavior applies to shared requests. For more information, see Sharing signature requests.Templates
Creating a template
When an authentication method is enforced, the following changes occur to template creation:- Box automatically sets each placeholder and recipient to the enforced method.
- When a creator edits a template, Box displays a validation error if the creator tries to save the template with a method other than the enforced one.
- Unlocked template – the template automatically defaults to the enforced method.
- Locked template – the creator cannot save the document as a template if the recipient fields are locked.
Using a template
Authentication methods configured within a template can be modified unless the template creator locks the template. When a template’s method differs from the one you enforce, the template user’s experience depends on whether the template is locked:- Unlocked template – if a recipient does not have an authentication method configured within the template, Box automatically sets it to the enforced method and informs the sender. If a recipient is set to any other method, the sender receives an error when they select Send, indicating that they must change the method to the enforced one.
- Locked template – the sender is blocked from using a template if it contains a verification method that they are not permitted to use.