I’m trying to figure out the ins and outs of device pinning. We currently allow unlimited pinned devices. This has led to a number of phantom devices still pinned to Box accounts.
- If we limit the number of allowed devices, does an admin need to remove an old pinned device in order for a user to connect a new one?
- Can we expire pinned devices after a specific time period or does that token remain active until the account is marked inactive or the device is removed?
- Will disabling device pinning enterprise-wide force all devices to reauthenticate?
- If we do not allow device pinning how often will users have to reauthenticate? Is this controlled by “Security » Session Duration for All Users”?
Side-quest: Is there a way to block Box Sync since it’s no longer supported?
