On Box for EMM for iOS with Microsoft Intune, opening an Office file through iOS Open In… / Share Sheet (Word, Excel, or PowerPoint) may open the file as read-only. As a result, the user may be unable to edit the file or save changes back to Box through this workflow.
Other workflows, such as opening the same file from the Files app or accessing Box as a storage location from the Office app, may still allow the user to edit the file.
Symptoms
- The user opens an Office file (
.docx,.xlsx,.pptx, etc.) in Box for EMM on iOS. - The user selects Open In… / Share Sheet and then selects Word, Excel, or PowerPoint.
- Office opens the file in read-only mode; The user cannot edit the file or save changes back to Box through this workflow.
- Other workflows may continue to work, including:
- Files → Box for EMM → Office
- Office app → Box Places / storage account
- Open in Microsoft Word/Excel/PowerPoint (WOPI)
- The environment uses Intune app protection policies (MAM), with Box for EMM deployed through MDM. The behavior may affect multiple users or devices.
Note: Do not confuse this issue with Feature disabled for Open in Microsoft Excel/Word/PowerPoint. These are different workflows and are covered by different troubleshooting guidance.
Root cause
Microsoft Intune app protection policies can control how organizational data is transferred between iOS applications.
When data-transfer restrictions apply to the Open In… workflow, the file may be transferred to Office as a protected or encrypted copy rather than as the original Box File Provider item. Depending on the applicable Intune policy and the receiving app, Office may therefore open the file as read-only and may not be able to save changes back to Box.
For MDM-managed iOS devices, Microsoft documents Policy managed apps with OS sharing as the configuration used to allow data transfer between policy-managed apps and other MDM-managed iOS apps. Microsoft also documents the use of IntuneMAMUPN and IntuneMAMOID to associate the managed app with the enrolled user when transferring data to an iOS managed app.
See Microsoft's documentation:
- Microsoft Learn: How to Manage Data Transfer Between iOS Apps in Microsoft Intune
- Microsoft Learn: iOS/iPadOS App Protection Policy Settings
For additional technical background, see the following publicly available discussion in the Microsoft Intune App SDK for iOS repository:
Resolution
1. Review the Intune configuration for Open In… data transfer
Review the Microsoft Intune app protection and app configuration settings used for Box for EMM and Microsoft Office.
- Confirm that Box for EMM is deployed as an MDM-managed app.
In the Intune App protection policy, review Send org data to other apps.
For MDM-enrolled devices where data needs to be transferred between policy-managed apps and other MDM-managed iOS apps, Microsoft documents Policy managed apps with OS sharing for this scenario.-
Review the App configuration for Box for EMM. For Microsoft Intune, configure the following configuration values:
-
IntuneMAMUPN={{userprincipalname}} -
IntuneMAMOID={{userid}}
For details on configuring Box for EMM with Microsoft Intune, see the Box for EMM configuration guide for Microsoft Intune.
For details on configuring the user UPN setting for Microsoft Intune or third-party EMM, see Microsoft's Configure user UPN setting for Microsoft Intune or third-party EMM. -
- Confirm that Box for EMM and Word/Excel/PowerPoint are assigned compatible app protection policies.
- Confirm that the applicable Receive data from other apps setting allows the expected data-transfer scenario.
Note: The exact configuration should follow your organization's data-protection requirements. Changing an Intune app protection policy can affect how organizational data is shared between applications.
2. Apply the configuration and retest
After reviewing or updating the configuration:
- Sync the device with Company Portal / Intune.
- Fully quit Box for EMM and the affected Office application.
Reopen Box for EMM and retry:
Box for EMM → Open In… → Word/Excel/PowerPoint- If the policy does not appear to have been applied, allow sufficient time for the updated configuration to reach the device before performing additional troubleshooting.
If the issue continues after the Intune configuration has been reviewed and the Open In… workflow still opens the file as read-only, contact Box Support and provide:
- Exact reproduction steps and the Office application used
- Screenshots of the relevant Box for EMM app configuration
- The Send org data to other apps and Receive data from other apps settings
- Box for EMM version
- iOS version
- Microsoft Office application and version
- Box mobile logs
- A short screen recording showing the behavior
Alternative workflows
If your organization needs to keep Policy managed apps instead of Policy managed apps with OS sharing, the Open In… flow may remain restricted by the organization's data-transfer policy.
In that situation, consider the following alternative workflows, depending on the organization's configuration:
- Office app → Box through Places / storage account
- Files → Box File Provider → Office
- Open in Microsoft Word/Excel/PowerPoint (WOPI)
These workflows use different integration paths and may not be affected by the same Open In… data-transfer behavior.