Configure Box Co-Admin
When using a Co-Admin account to enable API access for Skyhigh CASB, policy remediation actions such as quarantine, delete, or modify sharing do not have sufficient permissions to act on the primary admin or other Co-Admin accounts. This is a scoping limitation of the Box APIs.
For a Co-Admin to manage Skyhigh CASB for the Box DLP policy, enable the following permissions:
- Users and Groups:
- Manage users
- Manage groups
- Reports and Settings:
- View settings for your company
- Edit settings for your company
- Run new reports and access existing reports
IMPORTANT:
- Even with the above permissions enabled, a Co-Admin cannot monitor another Co-Admin's files in Box.
- An admin account is required if the Co-Admin does not own the files and folders.

