Skip to main content
Question

change SSO Idp and domain email address

  • August 28, 2026
  • 1 reply
  • 64 views

Hi team, 

 

we are currently have the below domain as verified domain and Idp is azure. 

complispace.com.au

Now we need to change everyone’s login to different domain name of “ideagenplc.com” and same time, I need to change from current azure IDP to ideagen’s azure. 

 

please guide me how to do this step by step.  

currently Box URL is: https://complispace.account.box.com/

1 reply

Jey Bueno Box
Forum|alt.badge.img
  • Community Manager
  • August 28, 2026

👋 Hi ​@Yu HE, welcome to the Box Community! I’d be glad to assist.
 

Here is a step-by-step guide to updating your SSO IDP (Azure/Microsoft Entra ID), migrating your user login email addresses to the new domain (ideagenplc.com), and updating your custom Box subdomain:
 

Pre-Requisites & Domain Setup

  1. Register and Verify the New Domain:

    • In the Box Admin Console, navigate to Enterprise Settings > Custom Setup (or Domain Verification).
    • Add ideagenplc.com as a verified domain. Complete the DNS/TXT record verification process to confirm ownership of the new domain in Box.
    • Note: Critical admin actions like adding or removing domains require Multi-Factor Authentication (MFA).
       
  2. Prepare the New Azure/Entra ID Tenant:

    • In your new Azure/Entra ID environment (ideagenplc.com), create and configure the Box Enterprise application.
    • Ensure SAML user attributes are mapped properly (at minimum, the user’s email / User Principal Name mapped to SAML Subject/email attribute, along with firstName and lastName).
    • Export/download the SAML Federation Metadata XML file from the new Azure IdP.
       

Configure and Test the New SSO Connection

  1. Set Up the New IdP Connection:

    • In the Box Admin Console, navigate to Enterprise Settings > User Settings.
    • If switching to a new IdP instance, upload the new Azure metadata XML file under Configure Single Sign-On (SSO) for All Users, or submit an SSO Setup Support Request to Box Product Support if assistance is needed.
    • Set SSO to SSO Test Mode (or work with Box Support to receive a Service Provider-initiated test link). SSO Test Mode allows users to log in with either SSO or standard Box passwords so users are not locked out during the transition.
       
  2. Test Authentication:

    • Have a test user assigned in the new Azure IdP log in using the test link or login flow to confirm SAML assertions and claims are correctly received by Box.
       

Update User Email Addresses in Box


Important: Because Box matches the SAML assertion’s email claim against existing user accounts, email addresses in Box must match the new domain in Azure before forcing the switch.

  1. Disable Email Change Restrictions (if necessary):
    • Under Enterprise Settings > Security, ensure “Prevent users from changing their primary email address” is temporarily toggled off if users or admins need manual editing capabilities.
       
  2. Update Primary Email Addresses:
    • Option A (Bulk Update via Admin Console / CSV or API): As an Admin, go to Admin Console > Users and Groups, select user accounts, and update their primary email address from @complispace.com.au to @ideagenplc.com (or use a bulk user CSV update / Box CLI / API).
    • Option B (Secondary Email / Alias Mapping): If users already have @ideagenplc.com linked as secondary email addresses, you can promote them to Primary once restrictions are temporarily lifted.
    • Caution: If Auto-Provisioning (On-the-Fly Registration) is enabled, ensure existing accounts are updated before users sign in with the new domain, otherwise new duplicate accounts will be created.
       

Update the Custom Subdomain / Box URL

  1. Request Subdomain Update:
    • Changing the enterprise subdomain (from complispace.account.box.com to e.g. ideagen.account.box.com) requires updating your custom subdomain settings under Enterprise Settings > Custom Setup or contacting your Box Account Team / Box Product Support.
    • Ensure that any updated redirect/ACS URLs are reflected in your new Azure Box Enterprise App configuration.
       

Cutover & Enforce SSO

  1. Switch SSO to Required:
    • Once all user email addresses are updated and test logins succeed, navigate to Admin Console > Enterprise Settings > User Settings.
    • Disable SSO Test Mode and enable SSO Required (requires admin MFA verification).
       
  2. Post-Migration Clean Up & Communication:
    • Notify users of the updated login URL and new login credentials.
    • Re-enable “Prevent users from changing their primary email address” in Enterprise Settings > Security to maintain IdP alignment as the single source of truth.


If you require further assistance changing SSO IDP and domain, please submit a ticket to our Product Support team. Thank you!