Configure SAML group push for Box

Use SAML group push when you want to add users to existing Box groups, create groups in Box, or manage group membership in Box.

If a user is a member of only one group in Okta or Active Directory (AD) and they're removed from the group, the group membership removal doesn't occur in Box.

If a user isn't assigned to any Okta or AD groups, the <groups> element is omitted from the Okta SAML assertion. Without a <groups> element to inspect, Box does nothing to its groups and the user's last group membership remains until you manually remove it.

  1. If you have an existing Box instance you want to configure, go to step 2. To configure SAML group push for a new Box instance:
    1. In the Admin Console, go to ApplicationsApplications.

    2. Click Browse App Catalog.
    3. Search for and select Box, and then click Add Integration.
    4. Complete the fields on the General Settings page and click Next.
    5. In the Sign On Methods section of the Sign-On Options page, select SAML 2.0.
    6. Click View SAML setup instructions and follow the instructions.
    7. Click Done.
  2. To configure SAML group push for an existing Box instance:
    1. In the Admin Console, go to ApplicationsApplications.

    2. Select your Box instance from the list of apps.
    3. Click the Sign On tab and click Edit.
    4. In the Sign on methods section, select SAML 2.0.
    5. Click View SAML setup instructions and follow the instructions.
    6. Click Done.
  3. Optional. To remove group memberships from Box:
    1. Open your Box instance and go to Admin ConsoleEnterprise Settings.
    2. Click the Users Settings tab.
    3. Clear the Remove user from groups upon SSO user login checkbox.
    4. Click Save.