Concepts and product choices
- What is Enterprise Mobility Management?
- What is the difference between MDM and MAM?
- Which approach is better for company-owned devices?
- Which approach is better for personally owned devices?
- Can Box use MDM and MAM at the same time?
- Is Box for EMM an MDM provider?
- Can Box's native mobile security settings replace EMM?
Applications and platforms
- What is Box for EMM on iOS?
- Is there a separate Box for EMM app on Android?
- Which Box app should be used for MDM on iOS?
- Which Box app should be used for MAM without device enrollment?
- Can the standard Box app and Box for EMM coexist on iOS?
- Can a user sign in to Box for EMM with a personal or unmanaged Box account?
Provider and account requirements
- Which MAM providers does Box support?
- Does a Box administrator need help from Box Product Support?
- What is the Public ID?
- What is the Management ID?
- What is the iOS one-time token?
Deployment and managed configuration
- Should users install Box for EMM directly from the Apple App Store?
- Can a managed Box app be backed up and restored to another device?
- What is Box-verified MDM deployment?
Microsoft Intune MAM and Conditional Access
- How is Intune MAM enabled for Box?
- Does turning on Intune MAM in Box affect users who are not enrolled?
- Must the Box and Intune email addresses match?
- Can MAM be enabled for only some users?
- Does Box support Intune Conditional Access?
- Does Conditional Access require another Microsoft app?
- What is Box as a Managed Place?
- Does Box as a Managed Place require device enrollment?
- Why can a user open an Office file but not save it back to Box?
Box Admin Console and related controls
- Which mobile content controls are available in the Box Admin Console?
- What is Box device pinning?
- Is device pinning the same as MDM enrollment?
- What happens when an administrator removes a device pin?
- Can Box prevent saving content on an unencrypted Android device?
- How does the iOS Files app interact with Box mobile security?
- What is the iOS EMM protected/unprotected Files setting?
Migration, updates, and deprovisioning
- How should an enterprise migrate from the standard Box app to Box for EMM?
- How can an administrator prevent users from bypassing the managed app?
- How is Box for EMM updated?
- What does “Contact admin for update” mean?
- What does “OS is no longer supported” mean?
- What should happen when a device is unenrolled or retired?
Troubleshooting
- What does “App is Not Authorized” mean?
- What does “User Is Not Authorized” mean?
- What causes an
invalid_redirect_urierror? - What causes an
invalid_clienterror with Microsoft Entra ID? - What causes a generic “Login Unsuccessful” error?
- Why does Box return to the login screen without an error?
- Why is Intune MAM required when the user opens Box?
- Why can a user not access Box files from Office on iOS?
Concepts and product choices
What is Enterprise Mobility Management?
Enterprise Mobility Management (EMM) is the broader practice of controlling access to company data through mobile devices and applications. In Box's documentation, EMM capabilities are divided primarily into:
- Mobile Device Management (MDM): The organization enrolls and manages the device.
- Mobile Application Management (MAM): The organization manages enterprise applications and their data without necessarily enrolling or controlling the whole device.
MDM and MAM can be used separately or together.
What is the difference between MDM and MAM?
MDM controls the device. It can enforce device-level requirements such as enrollment, lock-screen settings, VPN configuration, application sources, compliance, and remote wipe.
MAM controls enterprise applications and the data moving between them. It can separate work data from personal applications and restrict where managed content may be opened, copied, or saved without requiring full device enrollment.
Which approach is better for company-owned devices?
MDM is commonly used for company-owned devices because it gives the organization device-level control, including enrollment, compliance, network configuration, application deployment, and remote wipe.
The correct choice still depends on the organization's ownership model, privacy requirements, risk assessment, and existing mobility platform.
Which approach is better for personally owned devices?
MAM is often preferred for bring-your-own-device programs because it controls work applications and data without managing the entire personal device. MDM can also be used with personally owned devices if the organization and users accept device enrollment.
Can Box use MDM and MAM at the same time?
Yes. Deploy the MDM configuration and configure MAM separately. The device remains managed by the MDM provider while Intune app-protection policy controls managed application data.
Is Box for EMM an MDM provider?
No. Box for EMM is the Box application and configuration framework used with an EMM provider. The provider enrolls devices, distributes applications and configurations, evaluates compliance, and performs management actions. Box validates the managed deployment before allowing access.
For provider-specific policy behavior, contact or consult the EMM provider.
Can Box's native mobile security settings replace EMM?
They can provide useful controls when an EMM deployment is not possible, but they are not equivalent to full device or application management. Native Box controls include passcode requirements, inactivity settings, download and offline restrictions, external-app controls, printing restrictions, and device pinning.
Applications and platforms
What is Box for EMM on iOS?
Box for EMM is a separate iOS application designed for MDM-managed deployment. It can:
- Restrict enterprise Box access to approved managed devices
- Receive managed application configuration
- Validate that the app was provisioned by the organization
- Optionally participate in a Managed Status Check with supported providers
Is there a separate Box for EMM app on Android?
Android uses the standard Box app distributed and configured through Android Enterprise. When installed in the managed Android environment, it provides functionality comparable to Box for EMM on iOS.
Which Box app should be used for MDM on iOS?
Use Box for EMM to obtain the full Box MDM deployment controls on iOS. The application must be assigned and provisioned through the organization's MDM workflow.
Which Box app should be used for MAM without device enrollment?
Use the standard Box mobile app with a Microsoft Intune app-protection policy. A separate Box for EMM app is not required for MAM-only deployment.
Can the standard Box app and Box for EMM coexist on iOS?
They can be installed side by side, with separate credentials and application data, but Box does not recommend this as a permanent enterprise configuration. It can be useful for a controlled migration test.
After migration, disable unmanaged mobile access if the security design requires all enterprise users to use the managed application.
Can a user sign in to Box for EMM with a personal or unmanaged Box account?
No. The user must belong to the Box enterprise associated with the managed deployment. A user from another enterprise or an unmanaged account will not match the deployment's Box configuration and cannot sign in.
Provider and account requirements
Which MAM providers does Box support?
Box currently documents Microsoft Intune as its only supported MAM provider.
Does a Box administrator need help from Box Product Support?
Yes, for initial Box for EMM registration and the Public ID. Open a Box support case to request registration for the selected provider. Configure provider-side policies with the EMM vendor's documentation or support team.
What is the Public ID?
The Public ID is a shared deployment identifier supplied by Box Product Support. It associates the managed application configuration with the correct Box enterprise and settings.
Treat it as sensitive configuration data. Do not invent, reuse, or copy a Public ID from another enterprise.
What is the Management ID?
The Management ID identifies the managed device during a Managed Status Check. Its source and variable syntax depend on the MDM provider. Box's general configuration table describes it as required only for MSC deployments.
What is the iOS one-time token?
com.box.mdm.oneTimeToken is an iOS managed-configuration value used to help verify that the application was genuinely provisioned through the management provider and not copied or restored outside that workflow.
Use the provider-specific dynamic value documented by Box rather than a hard-coded value when one is available.
Deployment and managed configuration
Should users install Box for EMM directly from the Apple App Store?
No. Although an administrator can acquire the public application into an MDM catalog, the user must receive the assigned and managed instance through the organization's MDM workflow. A self-installed or device-restored copy does not receive valid managed configuration and can produce an App is Not Authorized error.
Can a managed Box app be backed up and restored to another device?
No. Restoring or transferring the application to another device can preserve an app copy without the valid device-specific management configuration. Remove the transferred copy and reprovision the application through the MDM provider.
What is Box-verified MDM deployment?
Box-verified deployment is the recommended approach. During login, Box checks the managed application configuration to verify that the app was deployed through the organization's MDM solution.
Microsoft Intune MAM and Conditional Access
How is Intune MAM enabled for Box?
Create and assign an Intune app-protection policy that targets Box. In the Box Admin Console, go to Enterprise Settings > Mobile and enable Intune Mobile Application Management (Intune MAM) when MAM should be enforced for the enterprise.
For iOS, Intune identifies the application as Box - Cloud Content Management. On Android, select Box.
Does turning on Intune MAM in Box affect users who are not enrolled?
It can. Box states that enabling the Intune MAM option in the Admin Console enforces the Intune MAM service even when a Box user has not already enrolled in it. Plan assignments, user communications, and pilot testing before enabling it broadly.
Must the Box and Intune email addresses match?
For a simple enterprise-wide MAM deployment, Box documents that users must use the same primary email address for Box and Intune.
For Conditional Access, the Microsoft Entra ID User Principal Name must appear as either the primary or a secondary email address on the Box account. A flexible managed configuration can also supply the user's UPN when the identifiers differ.
Can MAM be enabled for only some users?
Yes. Use a flexible deployment through managed app configuration and provider assignments. Box documents the Intune Enterprise value of 1 to enable MAM and a User Principal Name value to identify the Intune user.
The exact Intune keys and variable syntax must match the current Box and Microsoft documentation.
Does Box support Intune Conditional Access?
Yes. Box documents Conditional Access support in Box mobile and Box for EMM beginning with:
- iOS and iPadOS 5.34
- Android 6.33
Use current supported versions rather than treating these minimum versions as recommended deployment versions.
Does Conditional Access require another Microsoft app?
It can. Depending on the policy, Microsoft Authenticator may be required on iOS, and Microsoft Company Portal may be required on Android as the authentication broker. Confirm current broker requirements in Microsoft's documentation.
What is Box as a Managed Place?
Box as a Managed Place allows Intune-protected Microsoft mobile applications, such as Word, Excel, PowerPoint, Office, and Outlook, to save managed organizational content to Box while restricting saves to unapproved locations.
It extends Intune app-protection policy to treat Box as an approved managed storage destination.
Does Box as a Managed Place require device enrollment?
No. It is part of Intune MAM app-protection policy and can work on enrolled or unenrolled devices. Box documents Microsoft Entra ID or Okta federation for Box login as a requirement.
Why can a user open an Office file but not save it back to Box?
The Intune app-protection policy may not allow Box as a save destination. In the policy setting that controls where users may save copies of organizational data, allow Box as a selected service.
Microsoft can rename or reorganize policy settings, so verify the current label in Microsoft documentation.
Box Admin Console and related controls
Which mobile content controls are available in the Box Admin Console?
Under Enterprise Settings > Mobile, administrators can control behaviors such as:
- Saving files to the device or for offline access
- Whether preview-only collaborators can save content offline
- Opening content in external applications
- Printing
- Requiring Android device encryption before saving
- Allowing iOS applications to save files back to Box
- Requiring a Box app passcode and selecting an inactivity timeout
- Enforcing Intune MAM
Some dependent settings are available only after the parent setting is enabled.
What is Box device pinning?
Device pinning associates a managed user's Box account with particular mobile devices or client types. Administrators can limit how many devices of each type a user may connect.
When a user reaches the configured limit, another device cannot sign in until an administrator removes an existing pin.
Is device pinning the same as MDM enrollment?
No. Device pinning is a Box account-control feature. It limits and records Box client connections but does not enroll, configure, assess, or wipe the full device as an MDM provider can.
What happens when an administrator removes a device pin?
Box logs the user out on that device. Removing a pin does not itself perform a provider-level device wipe or retire the device from MDM.
Can Box prevent saving content on an unencrypted Android device?
Yes. When saving files to devices is allowed, an administrator can enable the Android setting that permits saving only when full-device encryption is present. This depends on Android support and the device's security configuration.
How does the iOS Files app interact with Box mobile security?
The Files app can expose Box as a storage provider so compatible applications can open and save content. However:
- The integration does not work when the organization requires a Box app-specific passcode because the Files app cannot enforce that passcode.
- Disabling external-application access prevents use of the Files integration.
- Box documents additional limitations for Box-specific file types, folder size, tags, favorites, and Recents behavior.
What is the iOS EMM protected/unprotected Files setting?
Box provides an Admin Console setting that disables iOS Files access for Box for EMM on iOS 12.0 or older because those operating-system versions could allow managed content to move to unmanaged locations.
Current Box mobile releases no longer support those old iOS versions, but the setting remains documented for legacy environments.
Migration, updates, and deprovisioning
How should an enterprise migrate from the standard Box app to Box for EMM?
- Register the enterprise and obtain the Public ID.
- Configure the MDM application, managed configuration, compliance policy, and assignments.
- Pilot with a small test group.
- Validate sign-in, file access, external-application behavior, offline access, updates, and deprovisioning.
- Communicate the cutover and provision Box for EMM to the remaining users.
- After the migration is complete, disable unmanaged Box mobile applications if the security design requires managed-only access.
Avoid disabling standard applications before the managed path has been validated.
How can an administrator prevent users from bypassing the managed app?
After migration, use Enterprise Settings > Apps to disable the applicable standard Box mobile applications for the enterprise. Box warns that this can also prevent enterprise users from accessing unmanaged Box mobile paths, so notify users and test the impact first.
How is Box for EMM updated?
The application can normally be updated through the app store after it has been provisioned, unless the administrator has disabled manual updates or controls versions through the provider. In that case, users must wait for the administrator to publish the required update.
What does “Contact admin for update” mean?
The installed app version has reached Box's required-update threshold, but the managed deployment has not made the newer version available. The EMM administrator must publish or permit the supported update.
Box begins update notifications when a mobile app version reaches 18 months of age and can require an update after a minimum of 20 months.
What does “OS is no longer supported” mean?
The device operating system cannot run a currently supported Box mobile version. Update the operating system or replace the device with one that meets Box's current support policy.
What should happen when a device is unenrolled or retired?
Use provider policy to remove managed Box access and organizational application data. Box recommends provider options such as removing the managed account or application on unenrollment where supported.
Test this lifecycle before deployment. MDM retirement, Box application removal, Box session termination, device-pin removal, and enterprise user deactivation are distinct controls.
Troubleshooting
What does “App is Not Authorized” mean?
The application was not correctly provisioned by the MDM provider. Common causes include:
- The user installed the app independently.
- The app was copied, backed up, or restored onto another device.
- The managed configuration or one-time token is missing or invalid.
Remove the app and reprovision it through the organization's MDM workflow.
What does “User Is Not Authorized” mean?
The user does not match the Box enterprise associated with the managed deployment, or the enterprise has not completed Box for EMM registration.
Confirm that the person is a managed user in the correct Box enterprise and that Box Product Support registered the enterprise's EMM instance.
What causes an invalid_redirect_uri error?
This error points to managed-configuration formatting. Check every key and value against the current provider guide, especially User Email Address. Remove leading or trailing spaces and tabs.
If the optional email parameter remains suspect, remove it and retest.
What causes an invalid_client error with Microsoft Entra ID?
In a MAM and Conditional Access flow, the Microsoft Entra ID UPN may be absent from the Box user's primary and secondary email addresses. Add and verify the UPN as a Box secondary email address when it differs from the primary Box login.
Do not disable the Intune MAM control merely as a troubleshooting shortcut without assessing the resulting Conditional Access impact.
What causes a generic “Login Unsuccessful” error?
Possible causes include a connectivity failure between Box and the EMM provider or an incorrect configuration key. Box specifically documents that Management ID must be spelled with the expected space rather than as ManagementID.
Confirm provider service health, network reachability, key spelling, and policy assignment.
Why does Box return to the login screen without an error?
Common possibilities include:
- The device is out of compliance.
- The user or app is not assigned to the policy.
- The wrong managed configuration reached the device.
- Box for EMM was not fully registered or configured.
- The device cannot reach Box or the provider service.
Compare one affected user and device with a known-good assignment before changing enterprise-wide policy.
Why is Intune MAM required when the user opens Box?
The Box enterprise has enabled enforcement of Intune Mobile Application Management. The user must sign in with the expected Microsoft identity and accept the assigned app-protection policy.
Confirm that the user is licensed and targeted in Intune, that the policy includes the correct Box application, and that the Microsoft UPN maps to the Box account.
Why can a user not access Box files from Office on iOS?
Check both Box and Intune policy:
- Box must allow opening content in external applications and saving files back to Box.
- Intune must allow Box as a managed save location.
- A required Box app-specific passcode prevents the Apple Files integration because Files cannot enforce that passcode.