Box 2FA: How to Set Up an Authenticator App
Your Box account holds the files and folders you store and share. Box calls the feature 2-Step Verification, a form of multi-factor authentication, and supports authenticator apps that follow the TOTP standard, so Authenticator App - Novaz can supply your codes. Box also offers SMS, email and security keys, but you can enable only one of these methods at a time.
A Box account may store backups of your most important data, so 2FA keeps that safe. Besides an authenticator app, Box also offers SMS text codes. An authenticator app (TOTP) is usually the best balance of security and convenience — and it's safer than SMS codes, which can be intercepted through SIM-swap attacks.
2FA methods Box supports
- SMS text message
- Authenticator app (TOTP)
Before you start
- Your Box email address and password
- An account where your organization doesn't require single sign-on (SSO) for authentication: if it does, the "2-Step Verification" section isn't shown in your account settings
- A phone number for verification, which Box requires when you register an authenticator app
- Authenticator App - Novaz installed on your iPhone or iPad. If your Box administrator requires a specific TOTP authenticator app, use that one instead
- A file only you can access, for the backup codes Box gives you at the end
Part 1: Turn on 2FA in Box
- 1
Open Account Settings
Log in to Box at app.box.com/login. Click your account icon in the top-right corner of the page and select "Account Settings".
- 2
Click Set Up under 2-Step Verification
On the "Account" tab, find the "2-Step Verification" section and click "Set Up".
- 3
Choose Authentication App
Select "Authentication App" and click "Next". Box shows a QR code with a secret key under it; keep the page open.
Part 2: Add Box to Authenticator App - Novaz
- 4
Add Box in Authenticator App - Novaz
Open Authenticator App - Novaz, tap the + button and scan the QR code. If it won't scan, choose to enter a setup key and type the secret key shown under the QR code. Use "Box" as the account name, then tap "Save".
Part 3: Confirm and finish
- 5
Enter the code and click Submit
Enter the code shown in Authenticator App - Novaz and click "Submit".
- 6
Add a phone number for verification
Box now asks for a phone number, which Box support would use to verify your identity if you can't authenticate in the app. Enter it and click "Submit".
- 7
Copy your backup codes
Copy the backup codes, paste them into a file only you have access to and save it somewhere secure. Click "Complete". 2-Step Verification is now on.
- 8
Know how Box login works now
After every email and password login, Box shows the two-step verification screen. Enter the code from Authenticator App - Novaz and click "Submit".
If something goes wrong
- There's no "2-Step Verification" section: your organization requires single sign-on (SSO). Contact your Box admin with any questions about SSO.
- Box shows "Oops! We can't seem to find the page you're looking for" after MFA, or "Unable to remove 2-step verification": try a private or incognito window, clear Box's cache and cookies, disable ad blockers and privacy extensions, or try another browser or device.
- Box rejects the code: make sure your iPhone sets its date and time automatically (Settings > General > Date & Time), then enter the newest code.
- You connect to Box by FTP: authenticator apps and security keys aren't supported for FTP for non-SSO customers, so FTP users with 2FA must use SMS.
Checked against Box's own help pages on September 25, 2026. Menu names can change, so these pages have the current path:
- Multi-Factor Authentication Set Up for Your Account – Box Support ↗
- Logging in to Box – Box Support ↗
- Backup Phone Number for TOTP – Box Support ↗
- MFA backup codes are coming to Box (Jan 2023) – Box Support ↗
- Troubleshooting MFA Errors: "We can't seem to find the page you're looking for" and "Unable to remove 2-step verification" – Box Support ↗
How to recover your Box account
Box gives you backup codes during setup. Each works exactly once: on the two-step verification screen, click "Use account backup code instead", enter an unused code and click "Submit". Box says you can generate new codes as needed. If you're locked out without them because you can't get your codes, contact your primary admin, who can disable 2FA on your account; Business Plus and Enterprise admins can do this through the instant login feature in the Admin Console. On a Personal, Starter or Business account, contact Box Product Support.
Frequently asked questions
- Can I use an authenticator app and SMS at the same time?
- No. Box lets you enable only one of authenticator app, security key, email or SMS for 2-factor authentication. Backup codes come on top of the app, SMS or security key method.
- Why does Box ask for my phone number when I'm using an app?
- Box requires a backup phone number when you register a TOTP authenticator app. Box support uses it to verify your identity if you can't authenticate in the app.
- How do I remove 2-Step Verification or change method?
- Click your account icon, select "Account Settings", scroll to the "Authentication" section on the "Account" tab and click "Remove" next to the method, then "Remove" again to confirm. If your admin requires MFA, you'll have to add a method before you next sign in.
- Can my Box admin make me use 2-Step Verification?
- Yes. An admin can require 2FA, including for external collaborators, and may require an authenticator app or security key, or a specific TOTP-compliant authenticator app.
Generate your Box codes in Authenticator App - Novaz
Free, offline, and encrypted. One tap for every 6-digit code.
Get the appMore Backup guides
Novaz is not affiliated with, endorsed by, or sponsored by Box. Box and its logo are trademarks of their respective owner and are used here for identification only.



