Issue
Login and access to Box from a specific application are blocked.
Affected users receive a warning e-mail stating, “Access restricted,” and a suspicious location alert is displayed on the Shield dashboard in the Admin Console.
Warning e-mail message
Access restricted.
Your access has been temporarily revoked because account activity from a restricted location has been detected. Access will be restored immediately once you log in from an approved location.
If you are not sure why you are receiving this message, please contact your system administrator.Root Cause
This issue occurs when access restrictions are enabled in the "Suspicious Location Detection Rule" in Box Shield. In this configuration, access from specific applications may be identified as activity from a potentially restricted location and subsequently blocked.
Resolution
Step 1: Diagnostics and alert verification
First, confirm whether the access block is caused by Box Shield.
- From the Admin Console, navigate to Shield > Dashboard and check whether any alerts associated with the affected user are displayed.
- Verify whether the user has received an e-mail stating, “account activity from a restricted location has been detected.”
Step 2: Excluding the application
If the issue is confirmed, exclude the affected application from the rule by following the steps below.
- Open "Filter Criteria" in the Suspicious Location Detection Rule.
- Enable Exclude integrations.
- Enter the integration name, select the relevant application from the list, and update the rule.
Step 3: Advanced solution when the application is not listed
If the application you want to exclude does not appear in the list, add it manually by following the steps below.
- In the Admin Console, go to Reports > Platform Activity, generate a report, and identify the client ID of the affected application.
- Navigate to Admin Console > Integrations > Platform App Manager tab.
- Click the + button on the right side of the screen.
- On the Add Platform App screen, enter the client ID identified earlier.
- On the Enable App screen, click Enable.
- Return to the Box Shield Detection Rule settings. The application should now be available for selection.