To use a Co-Admin account to enable API access for Skyhigh CASB, policy remediation actions such as quarantine, delete, or modify sharing does not have sufficient permissions to act on the primary Admin or other Co-Admin accounts. This is a scoping limitation of the Box APIs.
For a Co-Admin to manage Skyhigh CASB for Box DLP policy, enable the following permissions:
- Users and Groups:
- Manage users
- Manage groups
- Reports and Settings:
- View settings for your company
- Edit settings for your company
- Run new reports and access existing reports
IMPORTANT: Even with these permissions enabled, a Co-Admin cannot monitor the files of another Co-Admin in Box.