IT Rules for Box Deprovisioning

IT Rules for Box Deprovisioning

Summary

Box accounts may be deprovisioned for two main reasons: the account is a low-storage,

low-risk account that has barely been accessed, or the user is an alumni account past

the grace period. Current students, employees, faculty, affiliates, and resource accounts

are protected from deprovisioning under the current rules.

Deprovisioning Rules

  1. Low-Storage / Low-Risk Account Rule

This rule is meant to clean up accounts that appear unused, have almost no data, and

do not belong to someone with an active university role.

A Box account may be deprovisioned if it meets the low-risk cleanup criteria:

  • The account has less than 2 MB of data.

  • The account has had no Box activity for more than 1 year.

  • The account is not in the Resource Accounts group.

  • The user is not active in Banner as a student, employee, faculty member, or

affiliate.

  1. Alumni Rule

This rule is meant to remove alumni-only Box accounts after the grace period has

passed. A Box account may be deprovisioned under the alumni rule if:

The user is classified as alumni in Banner.

The user is not currently a student, employee, faculty member, or affiliate.

The user was not previously staff or faculty.

The user is past the configured alumni grace period of 182 days (~ 6 months).

Storage size and recent Box activity do not matter for the alumni rule.


Who Is Protected?

The following accounts are not deprovisioned by the current rules:

  • Current students

  • Current employees

  • Current faculty

  • Current affiliates

  • Resource accounts

  • Alumni-only users who are still within the grace period

  • Box accounts that cannot be matched to Banner

  • Former staff/faculty who do not meet the low-storage / low-risk account rule


Important Notes

  1. This job is run manually as needed. It does not run every day.

  2. When the job runs, it checks the current Box and Banner information at that time. If someone became alumni two years ago and the job runs today, the graceperiod does not start today. The job sees that they are already past the grace period.

  3. Alumni may lose SSO access when they become alumni. That happens outside of this deprovisioning job. The grace period only controls when the Boxaccount becomes eligible to be archived and deleted.

  4. When a Box account is deprovisioned, the account’s contents are moved to a central archive account, and then the Box account is deleted.

  5. If the person logs into Box again later, a new Box account may be created. This does not necessarily restore access to their old data.

 


FAQ

If I am currently a student, employee, faculty member, or affiliate, can my Box

account be deprovisioned?

No. Current active university roles are protected.

If I become alumni, do I still have Box access during the grace period?

Not necessarily. Alumni may lose SSO access when they become alumni. The grace

period only controls when the Box account becomes eligible for archive and deletion.

If I became alumni two years ago and the job runs now, does my grace period

start today?

No. The job checks whether you are already past the grace period when it runs.

If I am alumni-only but have a lot of Box data, does that protect my account?

No. Under the alumni rule, storage size does not matter.

If I left the university as staff or faculty, when could my Box account be

deprovisioned?

Only if you no longer have an active role, the account has less than 2 MB of data, and

there has been no Box activity for more than 1 year.

If my inactive low-storage account is deleted and I log back into Box later, will I

get my old files back?

Not necessarily. Logging in may create a new Box account, but the old files may remain

in the central archive and may not automatically be restored.