Skip to content

Integrate Box

You can integrate Box with Sophos XDR so that it sends data to Sophos for analysis.

Sophos XDR uses a Box custom app to collect enterprise audit and security events from your Box environment.

Key steps

The key steps in a Box integration are as follows:

  • Create a Box custom app.
  • Configure application access and permissions.
  • Authorize the application.
  • Gather the Enterprise ID, Client ID, and Client Secret.
  • Configure the integration in Sophos XDR.

Requirements

The following is required for Box configuration:

Add a Box integration

To integrate Box, you must first create and authorize a custom app in Box, then provide the application details in Sophos XDR.

Create a custom app

To create a Box custom app, do as follows:

  1. Follow the steps in Box's own guide: Setup with Client Credentials Grant.
  2. Configure the following settings:

    • App Name: Enter a descriptive name.
    • Purpose: Select the appropriate value.
    • Authentication Method: Select Server Authentication (with Client Credentials Grant).
  3. Click Create App.

  4. Once the app is created, open it in the Box Developer Console.
  5. Open the Authorization tab.
  6. Click Review and Submit.

    An approval request is sent to your Box enterprise administrator.

  7. Follow the instructions in the approval email to complete the authorization.

Configure application access

To configure application access, do as follows:

  1. Open the custom app you created.
  2. In App access level, select App + Enterprise Access.
  3. In Application Scopes, select Manage Enterprise Properties.

    For more information, see Manage enterprise properties.

  4. Open the General Settings tab.

  5. Copy the Enterprise ID. You'll need to provide this in Sophos XDR.
  6. Open the Configuration tab.
  7. In OAuth 2.0 credentials, copy the Client ID. You'll need to provide this in Sophos XDR.
  8. Click Fetch Client Secret to show the Client Secret. Copy it, as you'll need to provide this in Sophos XDR.

Configure the integration in Sophos XDR

To integrate Box with Sophos XDR, do as follows:

  1. In Sophos Fusion, go to Security Operations > Integrations > Marketplace.
  2. Click Box.

    The Box page opens. You can configure integrations here and see a list of any you've already configured.

  3. In Configured integrations, click Add new.

  4. In Add an integration, do as follows:

    1. Enter a name for the integration.
    2. Enter the Box Enterprise ID, Box Client ID, and Box Client Secret that you got from Box.
  5. Click Done.

The new integration appears under Configured integrations. If its status icon is a green tick, your data should appear in the Sophos Data Lake after validation.

Configuration notes

Keep the following in mind during Box configuration:

  • The custom app must be approved by a Box enterprise administrator before it can be used.

Additional resources

For more information on configuring Box, see the following documents: