- All of your organization’s managed users
- All of your organization’s external collaborators, or just for specific external collaborators based on their domains or their email addresses
NoteMaking changes to your multi-factor authentication settings for managed users is considered a “critical action” in the Admin Console. For security reasons it is restricted to Admins, who must complete their own MFA to proceed. Co-admins are limited to read-only access for these settings.
Configuring Multi-Factor Authentication for your Managed Users
- Go to Admin Console > Enterprise Settings > Security.
- In the Multi-Factor Authentication section, enable Require multi-factor authentication for all managed users. If SSO Required is turned on, this setting will be hidden.
- Configure the Authentication Method and Authentication Frequency. See the Multi-Factor Authentication section in Enterprise Settings: Security Tab for details.
- Select Save.
When you enable and save this setting, Box sends email notifications to your existing managed users if SSO is in test mode and users do not have MFA enabled. This alerts them to log in and complete the setup of multi-factor authentication for their account. - Use MFA to authenticate this change:
- If you are already enrolled in the MFA, you need to authenticate the change using your chosen MFA method
- If you are not enrolled in any MFA, Box will send you a verification code by email. Use this code to authenticate
- When you enter the correct code, your configuration or other changes are saved. If the code is incorrect, you receive an error message.
Note When you enable multi-factor authentication for logins, people must log in again through the Box web app to set up the association with their mobile phone. If they do not first log into their account through the Box web app, they can’t use any mobile device to access Box.After the initial successful login, Box will remember the browser and you will not be prompted for MFA within the defined authentication frequency if you need to log in again. Only clearing the browser’s cache and cookies will re-prompt MFA.
Note When you enable and save this setting, Box sends email notifications to all of your existing managed users, alerting them to log in and complete the setup of multi-factor authentication for their account.
Configuring 2-step login verification for external collaborators
After you enforce 2FA, external collaborators must enroll in 2FA with Box to access your enterprise’s shared content. External collaborators who are already enrolled in 2FA with Box, or who are using an SSO provider to access their Box account, can continue to access the shared content.NoteMaking changes to your multi-factor authentication settings for managed users is considered a “critical action” in the Admin Console. For security reasons it is restricted to Admins, who must complete their own MFA to proceed. Co-admins are limited to read-only access for these settings.
- Go to Admin Console > Enterprise Settings > Security.
- In the Multi-Factor Authentication section, under External Users, select Configure or Edit Configuration.
- In the 2-Step Verification for External Collaborators dialog box, select whether to disable 2-step login, enable 2-step login for all external collaborators, or enable for - or except for - a defined set of external collaborators. If you enable 2-step login, select when it will be enforced. For more details, see the External Collaborators section in Enterprise Settings: Security Tab.
- Click Save.
- Use MFA to authenticate this change, using the method described in Multi-Factor Authentication Required for Admin Console Critical Actions.
- At the top of the page, click Save.
The External Collaborator’s experience with 2FA for External Collaborators
It is important to know how 2FA affects external collaborators. When you enforce 2FA, external collaborators can have different experiences, as summarized in this table:| External collaborator | Experience | To gain access to shared content |
|---|---|---|
| Is enrolled in 2FA with Box | Can access shared content if enrolled with required authentication method | N/A |
| Uses SSO to log into Box | Can access shared content | N/A |
|
|
|
|
|
|
| Receives an invitation email to accept the collaboration invite by signing up for a new Box account
|
|
Email Notifications when setting up 2FA for External Collaborators
Email notifications will be sent if:- Users’ EIDs have SSO in Test Mode and users do not already have 2FA enabled, or
- Users’ EIDs do not have SSO set up and users do not already have 2FA enabled
- Users are in an SSO-Required EID, and/or
- Users already have 2FA