Skip to content

Box access control & privilege security checks

Admin roles, standing privileges, permission scopes and policy enforcement — the settings that decide how much damage one compromised account can do.

On Box, Black Cat runs 7 checks in this area on every scan. Each one below lists its severity, how to fix it, and the compliance controls it satisfies where a control applies. See what access the Box connector needs.

Checks (7)

severity: high Excessive Admin Users fix difficulty: easy #

Reduce the number of Box admin and co-admin users to the minimum necessary

  1. Sign in to the Box Admin Console as an administrator
  2. Navigate to Admin Console > Users & Groups > Users
  3. Filter by role to identify all admin and co-admin accounts
  4. Review each elevated account and determine if the role is still required
  5. For accounts that no longer need admin access, click the user and change the role to a standard user
  6. Document the justification for any remaining admin accounts

Vendor docs ↗

Satisfies: ISO 27001:2022 A.5.15 SOC 2 Type II CC6.1 CIS Controls v8 CIS-06.1 NIST CSF 2.0 PR.AA-05 GDPR (SaaS Security) GDPR-25.2 HIPAA (SaaS Security) HIPAA-312.a NIS2 Directive NIS2-21.i.1 DORA (SaaS Security) DORA-9.2

severity: medium Inactive User Account fix difficulty: easy #

Deactivate or remove Box user accounts that have been inactive for over 90 days

  1. Sign in to the Box Admin Console as an administrator
  2. Navigate to Admin Console > Users & Groups > Users
  3. Sort or filter users by last activity date to identify inactive accounts
  4. For each inactive user, verify with their manager whether the account is still needed
  5. If the account is no longer needed, select the user and click Deactivate or Delete
  6. If the account must remain, document the business justification

Vendor docs ↗

Satisfies: ISO 27001:2022 A.5.15 SOC 2 Type II CC6.1 CIS Controls v8 CIS-06.1 NIST CSF 2.0 PR.AA-05 GDPR (SaaS Security) GDPR-25.2 HIPAA (SaaS Security) HIPAA-312.a NIS2 Directive NIS2-21.i.1 DORA (SaaS Security) DORA-9.2

severity: high External Collaboration Not Restricted fix difficulty: medium #

Enable external collaboration restrictions on admin accounts to limit data exposure

  1. Sign in to the Box Admin Console as an administrator
  2. Navigate to Admin Console > Enterprise Settings > Content & Sharing
  3. Under External Collaboration, review the settings for restricting external collaboration
  4. Enable the option to restrict external collaboration for admin and co-admin users
  5. Save the settings and notify affected admins of the change

Vendor docs ↗

Satisfies: ISO 27001:2022 A.5.15 SOC 2 Type II CC6.1 CIS Controls v8 CIS-06.1 NIST CSF 2.0 PR.AA-05 GDPR (SaaS Security) GDPR-25.2 HIPAA (SaaS Security) HIPAA-312.a NIS2 Directive NIS2-21.i.1 DORA (SaaS Security) DORA-9.2

severity: high Platform Access Only Admin fix difficulty: medium #

Remove admin privileges from platform-only (service account) users

  1. Sign in to the Box Admin Console as an administrator
  2. Navigate to Admin Console > Users & Groups > Users
  3. Locate the flagged platform-only user account
  4. Review whether administrative access is required for platform operations
  5. If not required, change the user role to a non-admin role
  6. If required, document the justification and restrict the account to necessary permissions only

Vendor docs ↗

Satisfies: ISO 27001:2022 A.5.15 SOC 2 Type II CC6.1 CIS Controls v8 CIS-06.1 NIST CSF 2.0 PR.AA-05 GDPR (SaaS Security) GDPR-25.2 HIPAA (SaaS Security) HIPAA-312.a NIS2 Directive NIS2-21.i.1 DORA (SaaS Security) DORA-9.2

severity: high User Exempt from Login Verification fix difficulty: easy #

Remove login verification exemptions to enforce authentication controls for all users

  1. Sign in to the Box Admin Console as an administrator
  2. Navigate to Admin Console > Users & Groups > Users
  3. Locate the flagged user and open their account settings
  4. Under the Security tab, find the login verification exemption setting
  5. Remove the exemption unless there is a documented and approved business reason
  6. Ensure the user is enrolled in the enterprise MFA or SSO solution

Vendor docs ↗

Satisfies: ISO 27001:2022 A.5.15 SOC 2 Type II CC6.1 CIS Controls v8 CIS-06.1 NIST CSF 2.0 PR.AA-05 GDPR (SaaS Security) GDPR-25.2 HIPAA (SaaS Security) HIPAA-312.a NIS2 Directive NIS2-21.i.1 DORA (SaaS Security) DORA-9.2

severity: medium User Account Deactivated But Not Removed fix difficulty: easy #

Remove deactivated Box user accounts after verifying content transfer is complete

  1. Sign in to the Box Admin Console as an administrator
  2. Navigate to Admin Console > Users & Groups > Users
  3. Filter by status to find users with inactive status
  4. Verify that the user's content has been transferred to an active owner
  5. Delete the inactive user account to free the license
  6. Document the removal in the offboarding log

Vendor docs ↗

Satisfies: NIS2 Directive NIS2-21.i.1 DORA (SaaS Security) DORA-9.2

severity: critical Admin Exempt From Login Verification fix difficulty: easy #

Remove login verification exemption from admin accounts to enforce strong authentication on privileged users

  1. Sign in to the Box Admin Console as an administrator
  2. Navigate to Admin Console > Users & Groups > Users
  3. Locate the flagged admin or co-admin user
  4. Open their account settings and navigate to the Security tab
  5. Remove the login verification exemption
  6. Ensure the admin user is enrolled in enterprise MFA or SSO

Vendor docs ↗

Satisfies: NIS2 Directive NIS2-21.i.1 DORA (SaaS Security) DORA-9.2

More Box checks

The information on this page is provided for general informational purposes and is believed to be accurate as of its most recent update. Product names, logos, and trademarks are the property of their respective owners and are used for identification purposes only; their use does not imply any affiliation with or endorsement by those owners. Descriptions of third-party applications and of compliance frameworks are based on publicly available documentation and may change over time.

See these checks run on your stack

Start a free 14-day trial — no credit card required.

Start Free Trial