SaaS ITGC チェック

ツール一覧 › Box

Box のアクセス管理機能(SSO・MFA・IP制限・監査ログ)

公式資料によると、Box は MFA・SSO・2FA・監査ログ に対応しています。IP制限 は公式ページをまだ見つけられていません。(資料の取得日 2026-10-04)

判定(かんたん基準)

Step1:MFA(1.00) / SSO(0.99) + 監査ログ(0.96)|許可
最終|許可

かんたん基準:Step1 は「MFA か SSO」に対応し、かつ監査ログを取得できれば許可。Step2 は「2FA か IP制限」に対応し、かつ監査ログを取得できれば許可。どちらも満たさなければ、個人情報・取引情報・財務情報・機密情報を扱うかどうかで決まります。括弧内は「対応している」確率です。

項目ごとの読み取り

項目公式資料の記載確率根拠
MFA対応と記載1.00Configuring Multi-Factor Authentication
SSO対応と記載0.99Logging in with Single Sign On (SSO)
2FA対応と記載1.00Configuring Multi-Factor Authentication
IP制限未収集——
監査ログ対応と記載0.96User Activity Report

「公式資料に記載なし」は、その要素の公式ページを読んだが記載がなかったもの。「未収集」は、公式ページをまだ見つけられていないもの(機能がないという意味ではありません)。

根拠(公式資料の原文)

SSO:Logging in with Single Sign On (SSO) – Box Support

https://support.box.com/hc/en-us/articles/360044195153-Logging-in-with-Single-Sign-On-SSO

Logging in with Single Sign On (SSO) – Box Support

Product Guides are now only available at docs.box.com. Check out all the details on what's changed.

Product Utilization

続きを読む(ほか 45 段落)

Single sign on authentication

Single sign on authentication (or SSO authentication) allows you to log in to multiple applications using a single set of credentials. If your administrator has enabled or required SSO for your organization, you can use your company credentials to log in to Box.

Follow these steps to log into your Box account using SSO authentication:

Enter the email address affiliated with your Box account.

In the bottom right, click Sign in with SSO:

You are redirected to your company's login page. Then enter your company credentials to gain access to your Box account.

From Company Branded Subdomain (yourSubdomain.box.com)

If you are logging in via your company's branded Box subdomain (that is, yourSubdomain.box.com), and your enterprise has enabled or required SSO, the following prompt displays:

Click Continue. You are redirected to your company's login page. Then enter your company credentials to gain access to your Box account.

SSO on mobile devices

If SSO is enabled for your account, to login to Box using SSO authentication on any mobile device, tap Sign in with SSO underneath the Log In button:

If your admin requires SSO for your account, you'll first need to sign in to Box, and then sign in to your account:

After signing in, on the next page, enter the email address associated with your Box account. Clicking "Log In" will redirect you to your company or university login page. Enter your company or university credentials to log into Box.

Using SSO to log in to 3rd-party mobile apps

A majority of 3rd party applications and our OneCloud partners now support SSO and have a dedicated SSO login button labelled - Use Single Sign On (SSO). If your company has SSO required, you can click on the SSO log in button and then enter your Box specific email address. This should then redirect you to your company login page, where you will need to log in with your company credentials.

Follow these steps to log in with SSO:

Inside of the application you want to use, locate Box by looking for "App Integrations" or "Server Connections" and select the "Box" connection.

Depending on the application, you may be asked to enter your username (email address) before you can see the SSO login button.

Select "Use Single Sign On (SSO)"

Enter your Box specific email address

You will be redirected to your company company login page. Enter your company credentials in order to gain access to your Box account

SSO passkey authentication support

Passkey authentication as part of an SSO login flow is supported in the Box.com web application, but is not currently supported in the native Box mobile application.

If your enterprise requires passkey authentication as part of its SSO flow on mobile devices, the current workaround is to enable the Mobile Native Browser Auth setting. This setting routes mobile SSO authentication through the device's native browser instead of the in-app browser, which supports passkeys.

The Mobile Native Browser Auth setting is not compatible with Device Trust. If your enterprise has any Device Trust settings in place, these must be removed before Mobile Native Browser Auth can be enabled.

To enable Mobile Native Browser Auth, contact Box Product Support.

While the Box API supports SSO login, because of the customization that goes into setting up SSO, occasionally there are apps or SSO configurations that are not optimized for SSO login on mobile. If it does not work for an app, you will need to create a Box-specific password in your account settings to login with.

SSO won't work for any app using FTP

3rd Party App developers must also optimized their apps for SSO login, so you may see issues on an app by app basis

If you are not able to log into your Box account from within a third party application your admin may have disabled this application for the Enterprise from within the Admin Settings. You would have to contact your admin to have them enable the application for the Enterprise from within the Apps tab of the Admin Console.

tech_writers_swarm_kb

Related articles

Multi-Factor Authentication Set Up for Your Account

Setting Up Single Sign-On (SSO) for Your Organization

Logging in to Box

Enrolling in 2FA for External Collaboration

Domain Management, Verification, and Auto Enrollment

Articles in this section

Security Key MFA Troubleshooting

Logging in with Single Sign On (SSO)

Logging in on a Device That Is Not Yours

Creating a Password

Changing Your Password

Reset My Box Account Password

Box + SSO: Working with External Passwords

MFA:Configuring Multi-Factor Authentication – Box Support

https://support.box.com/hc/en-us/articles/360044195853-Configuring-Multi-Factor-Authentication

Configuring Multi-Factor Authentication – Box Support

Box multi-factor authentication (MFA), sometimes known as two-factor authentication (2FA), enables you to increase your content security and better protect your enterprise's content from unauthorized external access. It requires users to periodically authenticate with more than one method when they log in to Box. You can enable or disable multi-factor authentication for:

All of your organization's managed users

続きを読む(ほか 22 段落)

All of your organization's external collaborators, or just for specific external collaborators based on their domains or their email addresses

This topic describes how to configure multi-factor authentication for your managed users and for your external collaborators.

Making changes to your multi-factor authentication settings for managed users is considered a "critical action" in the Admin Console. For security reasons it is restricted to Admins, who must complete their own MFA to proceed. Co-admins are limited to read-only access for these settings.

Configuring Multi-Factor Authentication for your Managed Users

Go to Admin Console > Enterprise Settings > Security.

In the Multi-Factor Authentication section, enable Require multi-factor authentication for all managed users. If SSO Required is turned on, this setting will be hidden.

Configure the Authentication Method and Authentication Frequency. See the Multi-Factor Authentication section in Enterprise Settings: Security Tab for details.

When you enable and save this setting, Box sends email notifications to your existing managed users if SSO is in test mode and users do not have MFA enabled. This alerts them to log in and complete the setup of multi-factor authentication for their account.

Use MFA to authenticate this change:

If you are already enrolled in the MFA, you need to authenticate the change using your chosen MFA method

If you are not enrolled in any MFA, Box will send you a verification code by email. Use this code to authenticate

When you enter the correct code, your configuration or other changes are saved. If the code is incorrect, you receive an error message.

When you enable multi-factor authentication for logins, people must log in again through the Box web app to set up the association with their mobile phone. If they do not first log into their account through the Box web app, they can't use any mobile device to access Box.

After the initial successful login, Box will remember the browser and you will not be prompted for MFA within the defined authentication frequency if you need to log in again. Only clearing the browser's cache and cookies will re-prompt MFA.

If Single Sign On (SSO) is enabled for your account in Required Mode, you will not be able to enable multi-factor authentication here because it is configured by your SSO provider. Go to Admin Console > Enterprise Settings > User Settings tab to access single sign-on settings. MFA will still be available if SSO is configured in Test Mode. See Setting up Single Sign-On for more information.

When you enable and save this setting, Box sends email notifications to all of your existing managed users, alerting them to log in and complete the setup of multi-factor authentication for their account.

If someone loses their phone or for some other reason cannot access the confirmation codes sent to their mobile device, you can exempt this individual from the multi-factor authentication requirement. People who are exempt are able to log in successfully with only their Box password.

Configuring 2-step login verification for external collaborators

After you enforce 2FA, external collaborators must enroll in 2FA with Box to access your enterprise's shared content. External collaborators who are already enrolled in 2FA with Box, or who are using an SSO provider to access their Box account, can continue to access the shared content.

In the Multi-Factor Authentication section, under External Users, select Configure or Edit Configuration.

Configuring Multi-Factor Authentication

Multi-Factor Authentication Required for Admin Console Critical Actions

2FA:Configuring Multi-Factor Authentication – Box Support

https://support.box.com/hc/en-us/articles/360044195853-Configuring-Multi-Factor-Authentication

Configuring Multi-Factor Authentication – Box Support

Box multi-factor authentication (MFA), sometimes known as two-factor authentication (2FA), enables you to increase your content security and better protect your enterprise's content from unauthorized external access. It requires users to periodically authenticate with more than one method when they log in to Box. You can enable or disable multi-factor authentication for:

All of your organization's external collaborators, or just for specific external collaborators based on their domains or their email addresses

続きを読む(ほか 47 段落)

Making changes to your multi-factor authentication settings for managed users is considered a "critical action" in the Admin Console. For security reasons it is restricted to Admins, who must complete their own MFA to proceed. Co-admins are limited to read-only access for these settings.

Configuring Multi-Factor Authentication for your Managed Users

Go to Admin Console > Enterprise Settings > Security.

In the Multi-Factor Authentication section, enable Require multi-factor authentication for all managed users. If SSO Required is turned on, this setting will be hidden.

Configure the Authentication Method and Authentication Frequency. See the Multi-Factor Authentication section in Enterprise Settings: Security Tab for details.

Use MFA to authenticate this change:

If you are already enrolled in the MFA, you need to authenticate the change using your chosen MFA method

If you are not enrolled in any MFA, Box will send you a verification code by email. Use this code to authenticate

When you enter the correct code, your configuration or other changes are saved. If the code is incorrect, you receive an error message.

When you enable multi-factor authentication for logins, people must log in again through the Box web app to set up the association with their mobile phone. If they do not first log into their account through the Box web app, they can't use any mobile device to access Box.

After the initial successful login, Box will remember the browser and you will not be prompted for MFA within the defined authentication frequency if you need to log in again. Only clearing the browser's cache and cookies will re-prompt MFA.

If Single Sign On (SSO) is enabled for your account in Required Mode, you will not be able to enable multi-factor authentication here because it is configured by your SSO provider. Go to Admin Console > Enterprise Settings > User Settings tab to access single sign-on settings. MFA will still be available if SSO is configured in Test Mode. See Setting up Single Sign-On for more information.

When you enable and save this setting, Box sends email notifications to all of your existing managed users, alerting them to log in and complete the setup of multi-factor authentication for their account.

If someone loses their phone or for some other reason cannot access the confirmation codes sent to their mobile device, you can exempt this individual from the multi-factor authentication requirement. People who are exempt are able to log in successfully with only their Box password.

Configuring 2-step login verification for external collaborators

After you enforce 2FA, external collaborators must enroll in 2FA with Box to access your enterprise's shared content. External collaborators who are already enrolled in 2FA with Box, or who are using an SSO provider to access their Box account, can continue to access the shared content.

In the Multi-Factor Authentication section, under External Users, select Configure or Edit Configuration.

In the 2-Step Verification for External Collaborators dialog box, select whether to disable 2-step login, enable 2-step login for all external collaborators, or enable for - or except for - a defined set of external collaborators. If you enable 2-step login, select when it will be enforced. For more details, see the External Collaborators section in Enterprise Settings: Security Tab.

Use MFA to authenticate this change, using the method described in Multi-Factor Authentication Required for Admin Console Critical Actions.

At the top of the page, click Save.

The External Collaborator's experience with 2FA for External Collaborators

It is important to know how 2FA affects external collaborators. When you enforce 2FA, external collaborators can have different experiences, as summarized in this table:

External collaborator

To gain access to shared content

Is enrolled in 2FA with Box

Can access shared content if enrolled with required authentication method

Uses SSO to log into Box

Can access shared content

Is not enrolled in 2FA with Box and does not use SSO

Previously collaborated on shared folders

Cannot access your enterprise's shared content

Can access all folders from outside of your enterprise

In the Box account window, set up 2FA from the pending invitations panel under ACTION REQUIRED in the Files page, or from the Account Settings page.

Is invited to a new collaboration

Cannot access your enterprise's newly shared content

Does not have a Box account

Receives an invitation email to accept the collaboration invite by signing up for a new Box account

Register for a new Box account

When the setting is on, 2FA times out every 30 days for external collaborators. As a result, if an external collaborator does not authenticate with 2FA for 30 days or longer, they are challenged with 2FA next time they try to log in. If the external collaborator is a managed user of another enterprise that has a 2FA timeout of less than 30 days for managed users, they will need to complete 2FA verification sooner as a result.

Email Notifications when setting up 2FA for External Collaborators

Users’ EIDs have SSO in Test Mode and users do not already have 2FA enabled, or

Users are in an SSO-Required EID, and/or

The Managed User's experience with 2FA for External Collaborators

Enrolling in 2FA for External Collaboration

MFA backup codes are coming to Box

Configuring Multi-Factor Authentication

Multi-Factor Authentication Required for Admin Console Critical Actions

監査ログ:User Activity Report

https://support.box.com/hc/en-us/articles/4415012490387-User-Activity-Report

User Activity reports provide an overview of the actions your users are taking in Box. Use this report to view the actions made by your users within a given time period. You can filter the report by:

Specific folders or files

User actions may be delayed by up to one day before uploading an exported .csv reports.

続きを読む(ほか 121 段落)

check box at the top of the list to select all files

folder, only the files within the selected folders, not

within any subfolders, will be included in the report.

Enable Include Subfolders, and then

all subfolders will be included in the report.

Note: If you enable the Include Subfolders

more than one folder, the Enable Subfolders option will be disabled.

When the Includes Subfolders feature is enabled:

The View option is not supported and will

the message No matching results found. You

Last Week (default)

Last day/week/month/year(s) values mean the previous day/week/month/year(s)

from the date the report was run.

Any individual user activity

Note: Box AI reporting is available for Business accounts and above.

AI query: User queried Box AI and received a response.

Enable Auto Roll In For Domain: Admin enabled

Disable Auto Roll in For Domain: Admin disabled

at any time you may be able to restore files that have been moved

to the trash but not yet deleted. However, when a file is deleted

from the trash, you have only 14 days to recover it before it

Moved: User moved a file to a new location in

When a folder is moved, only one event is generated for the folder,

regardless of its contents. Files and subfolders in the folder

Set file auto-delete: User set a file to delete

Restored from trash: User restored a deleted

from the trash.

Unlocked: User unlocked a file, permitting access.

Uploaded: User uploaded a file or caused a file

to be uploaded (such as when an Admin runs a report). When this

is selected, the report also includes Created events.

Created event is generated when a folder was created.

File version restored: User restored a previous

version of a file.

File marked malicious: User marked a file as

Applied watermark: User added a watermark to

Watermark will display the current viewer's email address or

as well as time of access across the document's contents.

Removed watermark: User removed the watermark

a watermarked file.

Synced folder: User synced a folder to their

Un-synced folder: User un-synced a folder from

Extended expiration date: User extended a retention

period. When this is selected, additional details will display

in the Details column of the report:

Retention Policy ID (ID of the winning policy that was

Retention Policy Name (name of the winning policy that

Old Disposition Time

New Disposition Time

Content Access: This event occurs when:

An item is accessed by an authorized end user or programmatically

by a Box application.

A thumbnail is generated for a file when a folder (in

the mobile or web app) is accessed.

In some cases, you might see multiple Content Access events

for for a single activity, such as a Preview or Move. This

because, on a technical level, larger files are sometimes

to improve efficiency. This does not affect the user experience,

but when this happens, each chunk involved is a separate

Access event. For example, a Preview of a large PDF file

be one Previewed event for the file, it would be multiple

Content access events for thumbnail generation do not have

Created File Request: User created a new File

Edited File Request: User edited an existing

Edited group: User edited a group in any way,

adding another user to the group.

Created Group Admin: Admin or Co-Admin appointed

Updated Group Admin Permissions: Admin or Co-Admin

group admin permissions.

Deleted Group Admin: Admin or Co-Admin removed

Item removed from group: User removed a group's

access to a specific file or folder.

Granted folder access: User granted a group

to a specific folder.

Removed from group: User removed another user

an existing group.

Opened legal hold case: User created a legal

policy in the Policies tab of the Admin Console.

Edited legal hold case: User edited an existing

legal hold policy.

Closed legal hold case: User closed a legal

Created legal hold assignment: User assigned

user as a custodian in a legal hold policy. A custodian is a

who may have had access to the content affected by this legal

Admin Login: User with Admin privileges logged

the account of one of their managed users.

Added Device Association: Admin pinned the Box

pinned by opening your Admin Console and navigating to

Enterprise Settings >

Accepted Terms of Service: User agreed to the

Terms of Service upon initial login.

typed in an incorrect password.

Login: User successfully logged into Box via

endpoint (Web application, mobile apps, Box APIs, and so on).

Rejected Terms of Service: User rejected the

a browser from a new device or a new token is issued for an OAuth

Removed login activity application: User logged

out of a device that they logged into previously.

device association. You can view all devices that users have

by opening your Admin Console and navigating to

Note: This action type was available

up through November, 2021, when Box had only SMS as an

authentication factor. When additional authentication

were added, the Login multi factor verification enabled

action type replaced this one. For reports spanning this

date, you could see both action types.

Login verification disabled: User disabled two-step

were added, the Login multi factor verification disabled

Failed Device Trust Check: User failed a

OAuth2 access token created: An OAuth2 access

which allows secure authorized access to Box, was created for

which allows secure authorized access to Box, was revoked for

This typically occurs after a defined number of unsuccessful

for a user. This typically occurs after a period defined by admins

for their account in account settings.

Login verification enabled in November, 2021,

For reports spanning this date, you could see both action

Added template: User added a metadata template

Violated share policy: User violated a sharing

Note: Box stopped tracking this

Deleted Policy: User deleted an existing security

この結果について

確認状況
未確認(自動判定)
資料の取得日
2026-10-04
判定日
2026-10-04
判定モデル
TypeSafe Jev(jev-1.13.0)。公式資料の原文から各項目の記載を読み取り、判定の木はプログラムで計算しています。