SaaS ITGC チェック

ツール一覧 › HubSpot

HubSpot のアクセス管理機能(SSO・MFA・IP制限・監査ログ)

公式資料によると、HubSpot は MFA・SSO・2FA・IP制限・監査ログ に対応しています。(資料の取得日 2026-10-04)

判定(かんたん基準)

Step1:MFA(0.99) / SSO(1.00) + 監査ログ(1.00)|許可
最終|許可

かんたん基準:Step1 は「MFA か SSO」に対応し、かつ監査ログを取得できれば許可。Step2 は「2FA か IP制限」に対応し、かつ監査ログを取得できれば許可。どちらも満たさなければ、個人情報・取引情報・財務情報・機密情報を扱うかどうかで決まります。括弧内は「対応している」確率です。

項目ごとの読み取り

項目公式資料の記載確率根拠
MFA対応と記載0.99Configure approved 2FA methods for users
SSO対応と記載1.00Set up single sign
2FA対応と記載1.00Set up two
IP制限対応と記載1.00Manage login and account access settings
監査ログ対応と記載1.00View and export account activity history

「公式資料に記載なし」は、その要素の公式ページを読んだが記載がなかったもの。「未収集」は、公式ページをまだ見つけられていないもの(機能がないという意味ではありません)。

根拠(公式資料の原文)

SSO:Set up single sign-on (SSO)

https://knowledge.hubspot.com/account-security/set-up-single-sign-on-sso

Set up single sign-on (SSO)

Marketing, sales, agency, and customer success blog content.

Examples of how real customers use HubSpot for their business.

続きを読む(ほか 60 段落)

Product Updates Blog

Updates on the latest releases from HubSpot’s Product team.

Account & Setup

Account Security

Available with any of the following subscriptions, except where noted:

Professional, Enterprise

Single sign-on (SSO) allows you to give your team members one account for all of the systems your business uses.

Security Assertion Markup Language, or SAML, is an open standard used for authentication. Based upon the Extensible Markup Language (XML) format, web applications use SAML to transfer authentication data between two parties - the identity provider (IdP) and the service provider (SP).

You can also set up SSO and restrict which login methods users can use to access your account through the login settings wizard. If you have an SAML-based SSO set up, you can require users to log in to HubSpot using their SSO credentials.

Permissions required

Super Admin permissions are required to set up or edit single sign-on.

The SSO setup process should be done by an IT administrator with experience creating applications in your identity provider account.

Log in to your identity provider account.

Navigate to your applications.

On the Login tab, if you haven’t configured your portal login settings, click Setup Portal Login Settings. Or, in the Single sign-on (SSO) section, click Configure.

In the right panel:

XML upload is available for all SSO set-ups. Drag and drop or click Choose a file to upload your federation metadata. Then, click Verify.

If you're using Microsoft AD FS, toggle the I'm using Microsoft AD FS (legacy on-premise) switch on. Then, click Copy next to the values as needed. Paste the values from your identity provider below. Click Verify.

The navigation instructions and field names above may differ across identity providers. You can find more specific instructions for setting up applications with commonly used identity providers below:

Microsoft Entra ID (formerly Azure AD)

you're using Active Directory Federation Services, learn more about

Require SSO for all users

After setting up SSO, you can require all users to use SSO to log in to HubSpot. This setting is turned on by default.

On the Login tab, in the Single sign-on (SSO) section, select the Require single sign-on checkbox.

Exclude specific users from SSO requirement

After setting up SSO, you can exclude specific users from the SSO requirement to allow them to also log in with their HubSpot user account.

In the left sidebar menu, select Security.

On the Login tab, in the Single sign-on (SSO) section, click Manage exempted users.

In the dialog box, click the Choose users dropdown menu and select the users that'll be able to log in with their HubSpot accounts. For example, you can select partners and contractors if they lack an SSO login.

Click Add application.

On the application's details page, click the Sign On tab.

Under the "SAML 2.0 is not configured until you complete the setup instructions" message, click View Setup Instructions. This will open a new tab. Keep it open, then return to the original tab in Okta.

In the same tab, scroll down to Advanced Sign-on Settings and add your Hub ID in the Portal Id field. Learn how to access your Hub ID.

Navigate to your user settings. Assign the new app to any users that are also in your HubSpot account, including yourself.

Return to the View Setup Instructions tab. Copy each of the URLs and the certificate, and paste them in HubSpot in the Identity Provider Identifier or Issuer URL field, the Identity Provider Single Sign-On URL field, and the X.509 Certificate field.

Click Verify. You’ll be prompted to log in with your Okta account to finish the configuration and save your settings.

Please note: you need administrative access in your OneLogin instance to create a new SAML 2.0 application in OneLogin, as required.

Log in to OneLogin.

Navigate to Apps.

Search for HubSpot.

Click the app that states "SAML2.0".

In the upper right, click Save.

Click the Configuration tab.

In the HubSpot Account ID field, add your Hub ID. Learn how to access your Hub ID.

Click the SSO tab.

Copy the following fields from OneLogin and paste them into the corresponding fields of the SSO setup panel in HubSpot:

Copy the value under Issuer URL and paste it into Identity Provider Identifier or Issuer URL.

Copy the value under SAML 2.0 Endpoint (HTTP) and paste it into Identity Provider Single Sign-on URL.

Once your SSO setup has been verified, navigate to https://app.hubspot.com/login/sso and enter your email address. HubSpot will look up your portal's single sign-on configuration and send you to your SSO provider to sign in. You’ll also see a Log in with SSO button when visiting a direct link to your account.

Once your SSO setup has been verified, navigate to https://app.hubspot.com/login/sso and enter your email address. HubSpot will look up your account's single sign-on configuration and send you to your SSO provider to sign in. You’ll also see a Log in with SSO button when visiting a direct link to your account.

Set up SSO using multiple identity providers

Use multiple single sign-on configurations to manage access across different identity providers within your HubSpot account. This can help your organization manage users across regions, subsidiaries, or systems that require separate identity providers. For example, if your company uses separate IdPs for North America and Europe, you can configure both in the same HubSpot account so users can select the proper IdP when they log in.

Enter the identity provider details and a configuration name.

If your account has no requirements but has turned on SSO, you can log in with any method including SSO.

Can I configure and use SSO during a HubSpot trial?

Yes. If your account has any

Professional or

Enterprise trial, a

Super Admin can set up SSO for your account.

Does SSO impact other HubSpot account types?

MFA:Configure approved 2FA methods for users

https://knowledge.hubspot.com/account-security/configure-allowed-2fa-methods-for-users

Configure approved 2FA methods for users

Skip to content

Setup, how-to, and troubleshooting guides

続きを読む(ほか 65 段落)

Developer Documentation

Reference for API & CMS development

Academy Content Library

A complete library of Academy’s free online video lessons and certification courses.

Academy Certification Courses

A collection of lessons and practical exercises leading to an industry-recognized certification in HubSpot’s tools or strategy.

Classroom Training

Schedule in-person training for a hands-on and personalized HubSpot training experience.

CRM & Sales Hub

Ask and answer questions about using HubSpot’s CRM and Sales Hub.

Discuss and learn HubSpot’s marketing tools and inbound strategy.

Learn about Service Hub and share your expertise.

Meet the Experts

Learn how to get the most out of HubSpot from those who know it best.

Search, vote for, and submit ideas to improve the HubSpot platform.

HubSpot Developers

Ask questions and connect with users building on HubSpot.

HubSpot User Groups

Meet regularly with your local community of HubSpot users.

Marketing, sales, agency, and customer success blog content.

Examples of how real customers use HubSpot for their business.

Product Updates Blog

Updates on the latest releases from HubSpot’s Product team.

Account & Setup

Account Security

Available with any of the following subscriptions, except where noted:

Starter, Professional, Enterprise

Professional, Enterprise

Configure which two-factor authentication (2FA) methods your team can use when logging in to your HubSpot account. Standardizing 2FA methods helps align login requirements with your organization's security policies. For example, you can require users to log in using an authenticator app (e.g., Google Authenticator) instead of SMS-based 2FA.

Learn more about improving your account security with login and password best practices.

Permissions required

Super Admin permissions are required to manage approved 2FA methods.

Before you get started

The setting is turned off by default, allowing all HubSpot-offered 2FA methods.

The HubSpot mobile app will always be turned on by default as a 2FA method and cannot be turned off.

This setting limits 2FA methods when logging in through a browser only. It does not limit 2FA methods when logging in through the HubSpot mobile app. For example, if your account has limited 2FA options, users logging in through the HubSpot mobile app can still use all HubSpot-offered 2FA methods.

Configure approved 2FA methods

Manage the two-factor authentication methods available to users when signing in to HubSpot.

In your HubSpot account, click the settings icon in the top navigation bar.

In the left sidebar menu, navigate to Security.

On the Login tab, in the Account 2FA preferences section, toggle the Approved 2FA methods switch on.

If you're configuring approved 2FA methods for the first time, click Setup Portal Login Settings and continue setting up the login methods.

Select the checkboxes for the 2FA methods you want to approve for your users:

Authenticator app (recommended): enter a one-time code from an app like Google Authenticator, Authy, or Duo.

Text message (least secure): enter a one-time code sent through text message.

HubSpot mobile app: receive a notification from the HubSpot mobile app. This method is turned on by default and can't be turned off.

Impact of changing approved 2FA methods

When you configure or change the allowed 2FA methods in your HubSpot account, the user experience will vary depending on whether they have already set up a 2FA method or not.

For users with an existing 2FA method that is no longer approved: the user will be able to log in with that 2FA method the next time they log in. After ‌logging in, the user will be prompted to set up one of the allowed methods for future logins.

For users who do not have any 2FA method set up: after entering their username and password, the user will be prompted to enter a verification code sent to their email. Following this, they will be prompted to set up one of the approved 2FA methods.

Was this article helpful?

Thanks for letting us know. How would you describe this article?

Inaccurate: it doesn’t reflect what I see in the product

Unclear: it’s difficult to understand

Missing information: it’s not comprehensive enough

Irrelevant: it doesn’t match what I searched for

Great! Is there anything we could change to make it even more helpful?

Is there anything we could change to make this article helpful?

Allow HubSpot to contact me about my documentation feedback.

Only used if we need clarification on your feedback.

Thank you for your feedback, it means a lot to us.

This form is used for documentation feedback only. Learn how to get help with HubSpot.

Table of contents

Related content

knowledge.hubspot.com -->

2FA:Set up two-factor authentication for your HubSpot login

https://knowledge.hubspot.com/account-security/set-up-two-factor-authentication-for-your-hubspot-login

Set up two-factor authentication for your HubSpot login

Examples of how real customers use HubSpot for their business.

Product Updates Blog

続きを読む(ほか 51 段落)

Updates on the latest releases from HubSpot’s Product team.

Account & Setup

September 28, 2026

Please note: the available methods for setting up 2FA may vary depending on your HubSpot subscription level and country or region. 2FA using the Google Authenticator app is supported globally. The countries that support SMS 2FA are the same as the supported countries for calling.

Authenticator app (recommended)

When logging in with the Office 365 add-in integration, you cannot use the Sign in with Google 2FA method. You must use your HubSpot email and password.

If you have already set up 2FA with Google Authenticator but have switched to a new Android phone, you can transfer Authenticator codes to your new device.

Set up 2FA for your account

To set up 2FA in HubSpot:

In your HubSpot account, click the settings icon in the top navigation bar.

In the left sidebar menu, navigate to General > Security.

Select from the following authentication methods:

Passkey (most secure): log in using biometrics, Face ID, or a device pin. Learn how to set up passkeys.

Authenticator app (more secure): enter a one-time code using a third party authenticator app.

To set up 2FA using an authenticator app or SMS, follow the on-screen instructions to set up the third party app or phone number. In HubSpot, click Next.

Click Done or add a secondary 2FA method. 2FA will apply the next time you log in to your HubSpot account.

Click Remember me to avoid being asked for 2FA for 28 days.

Click Ask every time to always prompt for 2FA every time you log in.

Set up a secondary 2FA method

After you've set up your primary 2FA method, it's strongly recommended to set up a secondary method. A secondary method will allow you to log in to HubSpot if you can't access your primary method or backup codes.

To set up a secondary authentication method:

In the Two-factor authentication (2FA) section, you can view your primary 2FA method listed, along with an option to set up a secondary method of either 2FA SMS messages or a third party authenticator app. If you choose 2FA SMS messages, it is recommended you set up a trusted phone number:

To add a trusted phone number, in the Trusted Phone Number section, click Add a trusted phone number.

On the Trusted Phone Number screen, type your phone number in the text box.

A six-digit code will be sent to the phone number. Type the code in the text box, then click Next.

A verified screen will appear after you input the six-digit code. Click Done.

After setting up a trusted phone number, or if you're selecting a third party authenticator app, click Text message or Authenticator app. Follow the on-screen instructions to finish setting up your secondary method.

Reset your 2FA login

If you lose your 2FA device and don't have access to a passkey, secondary 2FA method, or backup codes, you'll need to reset your 2FA to regain access to your account. Learn how to reset your 2FA and passkeys.

Turn off 2FA for your login

For Starter, Professional, and Enterprise accounts, 2FA is required for all users logging in with a username and password. If you have a Professional or Enterprise account where single sign-on is required, or if you're using HubSpot's free tools, you can turn off 2FA for your login.

Please note: it is highly recommended that you keep 2FA turned on to protect your account. Because logging in with 2FA requires you to have access to a secondary device, the risk of an intruder gaining access to your account is much lower.

To turn off 2FA for your login:

In the Two-factor authentication section, click Remove [Primary method], and if turned on, Remove [Secondary method].

Please note: as of March 20, 2026, the HubSpot mobile app is temporarily unavailable when setting up 2FA methods. If you've previously set up 2FA with the HubSpot mobile app, you can continue to use this method when logging in. If you remove the HubSpot mobile app as a 2FA method, it can't be re-added. To set up 2FA, you'll need to use a passkey, an authenticator app, or SMS.

In the dialog box, input the 2FA code sent to your primary or secondary method. If you don't have access to either method, but have your backup codes, click Use a backup code. If you don't have access to any of these methods, click Lost your authentication device? to reset your 2FA to regain access to your account. Once you regain access to your account, you can then turn off 2FA.

In the next dialog box, click Turn off.

After you have turned off your primary and secondary methods for 2FA, you'll no longer need 2FA to access your account.

Require 2FA for all users

Permissions required

Super Admin or Edit account defaults permissions are required to enforce 2FA.

2FA is required for all HubSpot Starter, Professional, and Enterprise accounts and can't be turned off. Accounts using HubSpot’s free tools can choose whether to require 2FA. The requirement applies account-wide. Individual users can't be excluded.

In the left sidebar menu, navigate to Security.

On the Login tab, toggle the Enforce 2FA to log in switch on.

In the dialog box, click Yes.

Once turned on, every user in the account will receive an email and an in-app notification to turn on 2FA in their account.

Backup codes are used to log in to your account if you lose your 2FA device. Once you have configured 2FA, you may receive the Check your 2FA backup codes notification. This is an automated reminder to confirm that your backup codes are saved. Receiving this notification does not indicate a security issue. If you can't locate your saved backup codes, generate new codes and save them to your device.

How do I access or refresh my 2FA backup codes?

In the left sidebar menu, click General > Security.

In the Two-factor authentication (2FA) section, click View backup codes.

In the dialog box, click Print or Download (PDF) to save your backup codes.

IP制限:Manage login and account access settings

https://knowledge.hubspot.com/account-security/limit-logins-to-trusted-ip-addresses

Meet regularly with your local community of HubSpot users.

Marketing, sales, agency, and customer success blog content.

Examples of how real customers use HubSpot for their business.

続きを読む(ほか 37 段落)

Product Updates Blog

Updates on the latest releases from HubSpot’s Product team.

Account & Setup

Account Security

September 22, 2026

Available with any of the following subscriptions, except where noted:

All products and plans

Additional subscriptions required for certain features

To manage access to your HubSpot account, you can limit logins to specific IP addresses or locations, restrict users to a single account, and manage HubSpot employee access. These settings help you improve your account's security and keep control over who can log in and view your HubSpot data.

Limit logins to trusted IP addresses

Subscription required

A Starter, Professional, or Enterprise subscription is required to limit logins to trusted IP addresses.

Permissions required

Super Admin permissions are required to limit logins to trusted IP addresses.

Limit HubSpot account access to trusted IP addresses. You can block logins from VPNs or from IPs outside your network, and restrict unauthorized access from personal or public computers and unsecured WiFi networks. Any bad actors logging in from outside your allowed IP range will be blocked even if they have proper login credentials. Learn more about the ways HubSpot helps you secure your account.

If this is your first time configuring your login settings, learn how to use the login settings wizard to restrict which login methods users can use to access the account.

Please note: limiting logins to trusted IP addresses applies to logins on both computers and mobile devices. If users log in using their mobile device outside of an allowed IP address, they will be blocked from accessing the account.

To limit logins to trusted IP addresses:

In your HubSpot account, click the settings icon in the top navigation bar.

In the left sidebar menu, under Account management, click Security.

On the Login tab, under Account restrictions, toggle the Allowed login IPs switch on.

In the Allowed IP Addresses section, enter the IP addresses in the text box. Use commas to separate different IP addresses or dashes to represent an IP address range.

To exempt certain users from limited logins to allowed IPs, click the Exempt Users dropdown menu and select the checkboxes next to the users you wish to exempt.

On the bottom left, click Save.

Limit logins to allowed locations

A Starter, Professional, or Enterprise subscription is required to limit logins to approved locations.

Super Admin permissions are required to limit logins to approved locations.

Manage HubSpot account access by approving locations that users can log in from. This helps you secure your account by ensuring only users in allowed regions can access your data. For example, you can approve specific countries or regions for your team while blocking login attempts from unauthorized areas.

To configure allowed locations:

In the left sidebar menu, under Account Management, click Security.

On the Login tab, in the Allowed login locations section, click Configure.

In the Manage approved locations panel, view the suggested locations based on your account's login history.

To view which users are logging in from a specific location, click [number] users. This displays a list of users logging in from that location with the last date each user logged in.

To add a new location, click Add locations.

Click the Country dropdown menu and select the checkboxes next to each country you want to approve.

If you’re adding a location in the United States, click the State dropdown menu and select the checkboxes next to each state you want to approve.

If a user logs in from a location that has not been approved, they'll receive the following error message: There was a problem logging you in.

監査ログ:View and export account activity history

https://knowledge.hubspot.com/account-management/view-and-export-account-activity-history

Updates on the latest releases from HubSpot’s Product team.

Account & Setup

Account Management

続きを読む(ほか 79 段落)

September 23, 2026

Country, region, and IP address of the user that made the change.

Users in an account with an Enterprise subscription can:

Click the success checkmark to resolve a comment.

To filter comments, click the Comments dropdown menu, and select Open comments, All comments, or Resolved comments.

To export the entire audit log or an audit log based on the selected filters, click Export report. Then, click Export.

View the user analytics tab

an Enterprise account is required to eview the user analytics tab.

To view user analytics from your Audit Logs page:

In the left panel, under Data Management, click Audit Logs.

At the top, click the Analyze tab.

On the Analyze tab:

At the top, you can see an overview of total daily logins, total daily deletions, total daily exports, and total daily reports. Click View Details to be taken to a centralized audit log for that specific action.

Below the overview, you can view charts of user activity by category, action, login trend, and CRM record. You can also filter each section by clicking the dropdown menus next to each option. Click View Filtered Records to be taken to a centralized audit log for that specific action.

Set up notifications for audit log events

Super admins can set up audit log notifications for their account. Once turned on, you'll receive notifications via email when the corresponding event occurs. To set up notifications for audit log events:

In the left panel, under Your Preferences, click Notifications.

At the top, click the Notifications tab.

Scroll down and click Audit logs.

Set up your notifications:

Select the Multiple Exports checkbox to be notified when a high number of exports get logged in a day.

Select the Removed admin permission checkbox to be notified when a user’s admin permissions are removed.

HubSpot employee access history

By default, HubSpot employees have limited access to your HubSpot account. This allows employees such as your account manager and support specialists to help with your account.

Super Admins in an Enterprise account can view what actions were taken by HubSpot employees whilst they were logged into your account, using the Audit Log.

Super Admins in Starter, Professional, or Enterprise accounts can view when HubSpot employees logged into your account by exporting the last 90 days of logins. Each export has timestamps for each case of employee login, and the department that the employee works in at HubSpot.

Account Management: members of your account management team. Account managers might enter your account to assist during strategy calls or check on your progress and success with HubSpot.

Services: members of HubSpot's Services team, like technical consultants, onboarding specialists, and site migration managers. Services employees might enter your account to assist you or check on the status of services you’ve purchased.

Customer Support: members of HubSpot's technical support team. Customer support might enter your account to help troubleshoot bugs or help members of your team learn about the HubSpot product.

Sales: members of HubSpot's sales team. The sales team might enter your account during a product demo, or to determine how to help you get the most value from using HubSpot.

Product/User Experience: members of HubSpot's product and UX teams. Product and UX teams might enter your account to follow up on feedback or questions that you’ve raised about HubSpot functionality.

HubSpot employees in other departments might occasionally log in, and take actions in your account for reasons not listed above. If you have questions about the information you're seeing in your export, you can contact HubSpot support.

Learn how to remove HubSpot employee account access.

Export HubSpot employee access history

To export HubSpot employee access history:

In the left panel, under Account Management, click Security.

Under the Login tab, scroll down and click therightright arrow next to Allow Access to expand the section.

Click Download employee access history. If you're unable to see Download employee access history, click Setup Portal Login Settings. After setting up your login settings, the option will be available.

Starter accounts

CRM object association definition updated:

A new association configuration is created.

An existing association configuration is deleted.

An association label is changed.

An association limit is changed.

CRM object activation/deactivation and renaming

CRM record view

Customer Agent actions

Data privacy requests

Multi-account management

Pipeline changes

Property updates

Property value updates

Conditional property logic

Conditional property options

Record creation form

Salesforce activity (updates made in HubSpot by the Salesforce integration)

Sensitive property values

Auto association of companies to contacts is turned on or off.

AI Assistant settings for content prompts or customer analysis turned on or off.

Security activity history

Super Admins can export security activity history to see a list of security-related actions that users have taken in the account in the last year. The following user actions are included in each export:

Adding, removing, or requiring single sign-on (SSO) or two-factor authentication (2FA).

Importing acceptance tests.

Exporting contacts or users.

Adding, removing, or impersonating users and admin.

Adding or removing admin permissions.

Deactivating or reactivating users.

Turning email tracking and attachment logging settings on or off .

Adding or removing email recipients from the Never Log list.

Performing a permanent delete of a contact.

Sending manual registration emails or password reset emails.

Creating a payment account and updating information, account changes, or sending payment onboarding links.

Creating, syncing, or deleting sandboxes.

For each user action, the export will show:

The time of the action.

The type of action.

The user's email address.

The ID of the affected object.

The approximate location.

この結果について

確認状況
未確認(自動判定)
資料の取得日
2026-10-04
判定日
2026-10-04
判定モデル
TypeSafe Jev(jev-1.13.0)。公式資料の原文から各項目の記載を読み取り、判定の木はプログラムで計算しています。