Follow the instructions below to set up Box for Netskope SaaS Security Posture Management.
Prerequisites
- A Box account with one of the following licenses: Business, Business Plus, Enterprise, or Enterprise Plus.
- A Box admin or co-admin user account.
Procedure
Step 1: Assign Co-Admin User Permissions
Follow the procedure to assign the required permissions to a co-admin user to grant access to Netskope configuration. Skip this step if you are using the Box admin user for onboarding Netskope.
Only an enterprise admin user has the right to enable permissions for a co-admin user.
-
Log in to your Box account as an enterprise admin user.
-
Navigate to Admin Console.
-
Navigate to Users and Groups > Managed Users.
-
Select a co-admin user from the list, or select the desired user and change the role to co-admin.
-
In Role and Access Permissions, click Edit.
-
Under Reports and Settings, enable the following permissions:
-
Click Save.
You may remain logged in as an admin or log in as a co-admin before proceeding.
Step 2: Authorize Netskope App on Box Admin Console
- Log in to your Box account as an admin or co-admin.
- Navigate to Admin Console.
- Navigate to Integrations and go to Platform Apps Manager tab.
- Click Add Platform App (+ symbol).
- In Client ID field, enter
3ffau6fkvclyerc87okszntquufizdg2Netskope SSPM JWT App key. - Click Next to review the app’s permission scopes.
- Click Authorize.
- Repeat steps 4 to 7 and use
Ipds86lv92ah6lssuvz0gt80c2xx356eNetskope SSPM User Grant App key in Step 5.
Step 3: Configure Netskope to Access your Box Account
- Log in to the Netskope tenant UI and go to Settings > Configure App Access > Next Gen > SECURITY POSTURE.
- Under Apps, select Box and click Setup Security Posture Instance. The Setup Instance window opens.
- Enter the admin user’s email under Administrator Email to authorize apps.
- Select the Security Scan Interval.
- (Optional) Enter an Instance Name.
- Click Grant Access.
- Click Grant Access to Box. When the configuration results page opens, click Close.
- Refresh your browser, and you will see the instance.


