Box access control & privilege security checks
Admin roles, standing privileges, permission scopes and policy enforcement — the settings that decide how much damage one compromised account can do.
On Box, Black Cat runs 7 checks in this area on every scan. Each one below lists its severity, how to fix it, and the compliance controls it satisfies where a control applies. See what access the Box connector needs.
Checks (7)
severity: high Excessive Admin Users fix difficulty: easy #
Reduce the number of Box admin and co-admin users to the minimum necessary
- Sign in to the Box Admin Console as an administrator
- Navigate to Admin Console > Users & Groups > Users
- Filter by role to identify all admin and co-admin accounts
- Review each elevated account and determine if the role is still required
- For accounts that no longer need admin access, click the user and change the role to a standard user
- Document the justification for any remaining admin accounts
Satisfies: ISO 27001:2022 A.5.15 SOC 2 Type II CC6.1 CIS Controls v8 CIS-06.1 NIST CSF 2.0 PR.AA-05 GDPR (SaaS Security) GDPR-25.2 HIPAA (SaaS Security) HIPAA-312.a NIS2 Directive NIS2-21.i.1 DORA (SaaS Security) DORA-9.2
severity: medium Inactive User Account fix difficulty: easy #
Deactivate or remove Box user accounts that have been inactive for over 90 days
- Sign in to the Box Admin Console as an administrator
- Navigate to Admin Console > Users & Groups > Users
- Sort or filter users by last activity date to identify inactive accounts
- For each inactive user, verify with their manager whether the account is still needed
- If the account is no longer needed, select the user and click Deactivate or Delete
- If the account must remain, document the business justification
Satisfies: ISO 27001:2022 A.5.15 SOC 2 Type II CC6.1 CIS Controls v8 CIS-06.1 NIST CSF 2.0 PR.AA-05 GDPR (SaaS Security) GDPR-25.2 HIPAA (SaaS Security) HIPAA-312.a NIS2 Directive NIS2-21.i.1 DORA (SaaS Security) DORA-9.2
severity: high External Collaboration Not Restricted fix difficulty: medium #
Enable external collaboration restrictions on admin accounts to limit data exposure
- Sign in to the Box Admin Console as an administrator
- Navigate to Admin Console > Enterprise Settings > Content & Sharing
- Under External Collaboration, review the settings for restricting external collaboration
- Enable the option to restrict external collaboration for admin and co-admin users
- Save the settings and notify affected admins of the change
Satisfies: ISO 27001:2022 A.5.15 SOC 2 Type II CC6.1 CIS Controls v8 CIS-06.1 NIST CSF 2.0 PR.AA-05 GDPR (SaaS Security) GDPR-25.2 HIPAA (SaaS Security) HIPAA-312.a NIS2 Directive NIS2-21.i.1 DORA (SaaS Security) DORA-9.2
severity: high Platform Access Only Admin fix difficulty: medium #
Remove admin privileges from platform-only (service account) users
- Sign in to the Box Admin Console as an administrator
- Navigate to Admin Console > Users & Groups > Users
- Locate the flagged platform-only user account
- Review whether administrative access is required for platform operations
- If not required, change the user role to a non-admin role
- If required, document the justification and restrict the account to necessary permissions only
Satisfies: ISO 27001:2022 A.5.15 SOC 2 Type II CC6.1 CIS Controls v8 CIS-06.1 NIST CSF 2.0 PR.AA-05 GDPR (SaaS Security) GDPR-25.2 HIPAA (SaaS Security) HIPAA-312.a NIS2 Directive NIS2-21.i.1 DORA (SaaS Security) DORA-9.2
severity: high User Exempt from Login Verification fix difficulty: easy #
Remove login verification exemptions to enforce authentication controls for all users
- Sign in to the Box Admin Console as an administrator
- Navigate to Admin Console > Users & Groups > Users
- Locate the flagged user and open their account settings
- Under the Security tab, find the login verification exemption setting
- Remove the exemption unless there is a documented and approved business reason
- Ensure the user is enrolled in the enterprise MFA or SSO solution
Satisfies: ISO 27001:2022 A.5.15 SOC 2 Type II CC6.1 CIS Controls v8 CIS-06.1 NIST CSF 2.0 PR.AA-05 GDPR (SaaS Security) GDPR-25.2 HIPAA (SaaS Security) HIPAA-312.a NIS2 Directive NIS2-21.i.1 DORA (SaaS Security) DORA-9.2
severity: medium User Account Deactivated But Not Removed fix difficulty: easy #
Remove deactivated Box user accounts after verifying content transfer is complete
- Sign in to the Box Admin Console as an administrator
- Navigate to Admin Console > Users & Groups > Users
- Filter by status to find users with inactive status
- Verify that the user's content has been transferred to an active owner
- Delete the inactive user account to free the license
- Document the removal in the offboarding log
Satisfies: NIS2 Directive NIS2-21.i.1 DORA (SaaS Security) DORA-9.2
severity: critical Admin Exempt From Login Verification fix difficulty: easy #
Remove login verification exemption from admin accounts to enforce strong authentication on privileged users
- Sign in to the Box Admin Console as an administrator
- Navigate to Admin Console > Users & Groups > Users
- Locate the flagged admin or co-admin user
- Open their account settings and navigate to the Security tab
- Remove the login verification exemption
- Ensure the admin user is enrolled in enterprise MFA or SSO
Satisfies: NIS2 Directive NIS2-21.i.1 DORA (SaaS Security) DORA-9.2