To configure Box for the Next Generation API Data Protection, you need to authorize Netskope as a web application client to access your Box instance. Follow the instructions below.
Prerequisite
-
A Box account with Business, Business Plus, Enterprise, Enterprise Plus, or Enterprise Advanced license.
-
A Box admin or co-admin user account.
Assign a Co-admin User for Netskope
This section describes the steps to assign a co-admin user for Netskope. If you do not plan to use the Box admin account, you can grant co-admin access instead. If you are granting access to Netskope as an admin, skip this section and proceed to the next one.
Here are the steps to create and assign a co-admin user to Netskope.
-
Log in to your Box account as an enterprise admin user.
-
Click Admin Console and navigate to Users and Groups > Managed Users. Click a co-admin user from the list.
-
In the Role and Access Permissions section click Edit. Under Reports and Settings, enable the following permissions:
-
Click Save.
You can continue to be logged in as an admin user or re-login as a co-admin user and proceed to the next steps.
Authorize Netskope App on Box Admin Console
As an admin/co-admin, you should authorize the Netskope app on Box so that Netskope can make API calls to Box. You can either use a Box admin or a co-admin account to grant access to API Data Protection.
-
Log in to your Box account using the admin or co-admin user.
-
Click Admin Console and navigate to Integrations > Platform Apps Manager and click + Add Platform App. Under Client ID, enter the following API keys:
-
6id7lc5mv8j4eultjlo9d45z88qmv5xk– This is the Netskope JWT app. -
cjm7eo3a8w6ukc7c22m9lyj4r8ppx7r6– This is Netskope Event Stream app.– If you are connecting a US FedRAMP account, entervhfjvk8v1o40qxb3xlv1z3so24kdse9qas the Event Stream API key.
– If you are connecting a Canada Federal PBMM account, enterxguwcwhdzobxlkifmuqw8ubbqrakksq8as the Event Stream API key.
The Netskope JWT API key remains same for both the accounts.Click Next and Authorize.
If you encounter an error message like Disabled by Administrator, proceed to step 3.
-
-
Navigate to Integrations > Platform Apps Manager and click Platform App Settings. Check the status of the Disable unpublished platform apps by default setting.

If enabled, go back to Integrations > Platform Apps Manager and click + Add Platform App. Under Client ID, enter the following client ID:
and enable it. This is the Netskope OAuth app.3f1v9ccezmyxytgxq8lce6zy9ut3o3dv
Disable Shied Detection Rules in Box
Shield Detection Rules are used to monitor events and activities in your Box account for advanced security. Learn more. If you have enabled the Malicious Content shield detection rule, ensure that the Restrict download of malicious content option is disabled. This option is available under Admin Console > Shield > Detection Rules > Malicious Content. If enabled, Box will block Netskope from scanning files.

Configure Netskope to Access your Box Account
To authorize Netskope to access your Box account, follow the steps below:
-
Log in to the Netskope tenant UI and go to Settings > Configure App Access > Next Gen > CASB API.
-
Under Apps, select Box and click Setup CASB API Instance.
The Setup Instance window opens.
-
Under Administrator Email, enter the email address of the user who will receive an email notification when a policy violation or event triggers. This step is optional.
-
(optional) You can select this Centralized Model checkbox.
Box offers an optional centralized ownership model, where one or more administrators can create individual folders within their centralized home folder for each user, and then share those folders with the respective users. In this model, the administrator retains ownership of all files and folders within the organization, while users are assigned as co-owners. However, this setup can impose limitations on Netskope operations due to API rate limits, as Box enforces these limits on a per-user basis. As a result, Netskope operations may experience slowdowns when rate limits are reached. To mitigate this, Netskope provides an opt-in feature that ensures seamless and scalable API Data Protection in Box environments utilizing the centralized ownership model.
To enable this feature, follow the steps below:
-
On your Box account, navigate to the user’s root folder and share the relevant top-level folders with the internal user(s), assigning them the role of co-owner.
Box enforces API rate limits on a per-user basis. To work around this limitation, Netskope recommends assigning multiple internal users as co-owners across different top-level folders. Netskope recommends sharing each top-level folder with no more than 10 co-owners.For example, in the folder structure shown below, you should share top-level folders—such as
top_level_folder_aandtop_level_folder_b—with internal users (e.g.,user1,user2) as co-owners. This allows Netskope to retrieve files from these folders through the access granted to each co-owner.Go back to the Netskope tenant UI.
-
Select the Centralized Model checkbox on the instance creation page.
-
-
Under Instance Name, enter a name of the SaaS app instance. This step is optional and if left blank, Netskope will determine the name of the app instance post grant.
-
Click Grant Access.
You will be redirected to the Box sign-in page.
-
Log in with the Box admin or co-admin account and click Authorize.
You will be prompted with a set of permissions. Click Grant access to Box.

When the configuration results page opens, click Close.
Refresh your browser and you will see a green check icon next to the instance name.
Next, you can view the Next Generation API Data Protection Inventory page to get deep insights on various entities on your Box account. For more information on the Inventory page, see Next Generation API Data Protection Inventory.
You can receive audit events and standard user behavior analytic alerts in Skope IT. To know more: Next Generation API Data Protection Skope IT Events.
Next, you should configure a Next Generation API Data Protection policy. To do so, see Next Generation API Data Protection Policy Wizard.


