Update: In the coming weeks, Box will be rolling out the ability for admins to enforce the Exposed Password Restriction, requiring managed users with a detected exposed password to update to a new, secure password before accessing Box. This capability will initially be off by default, and it can be toggled on within the Admin Console.
As part of our ongoing commitment to maintaining a secure and trusted platform, we are rolling out new protections aimed at hardening managed users' accounts against compromise, protecting their organizations against attacks that exploit reused or exposed credentials.
Over the coming weeks, we are rolling out Exposed Password Detection to managed user accounts. Box will begin notifying managed users within the application if they are re-using a password from another site that has been exposed in a security incident. This helps protect against accounts that re-use previously compromised login credentials, which could put their accounts and corporate data at risk.
Are you a Box customer interested in joining the conversation on all things Box Security and Governance? Join our user group!