ツール一覧 › HubSpot
HubSpot のアクセス管理機能(SSO・MFA・IP制限・監査ログ)
公式資料によると、HubSpot は MFA・SSO・2FA・IP制限・監査ログ に対応しています。(資料の取得日 2026-10-04)
判定(かんたん基準)
Step1:MFA(0.99) / SSO(1.00) + 監査ログ(1.00)|許可 最終|許可
かんたん基準:Step1 は「MFA か SSO」に対応し、かつ監査ログを取得できれば許可。Step2 は「2FA か IP制限」に対応し、かつ監査ログを取得できれば許可。どちらも満たさなければ、個人情報・取引情報・財務情報・機密情報を扱うかどうかで決まります。括弧内は「対応している」確率です。
項目ごとの読み取り
| 項目 | 公式資料の記載 | 確率 | 根拠 |
|---|---|---|---|
| MFA | 対応と記載 | 0.99 | Configure approved 2FA methods for users |
| SSO | 対応と記載 | 1.00 | Set up single sign |
| 2FA | 対応と記載 | 1.00 | Set up two |
| IP制限 | 対応と記載 | 1.00 | Manage login and account access settings |
| 監査ログ | 対応と記載 | 1.00 | View and export account activity history |
「公式資料に記載なし」は、その要素の公式ページを読んだが記載がなかったもの。「未収集」は、公式ページをまだ見つけられていないもの(機能がないという意味ではありません)。
根拠(公式資料の原文)
SSO:Set up single sign-on (SSO)
https://knowledge.hubspot.com/account-security/set-up-single-sign-on-sso
Set up single sign-on (SSO)
Marketing, sales, agency, and customer success blog content.
Examples of how real customers use HubSpot for their business.
続きを読む(ほか 60 段落)
Product Updates Blog
Updates on the latest releases from HubSpot’s Product team.
Account & Setup
Account Security
Available with any of the following subscriptions, except where noted:
Professional, Enterprise
Single sign-on (SSO) allows you to give your team members one account for all of the systems your business uses.
Security Assertion Markup Language, or SAML, is an open standard used for authentication. Based upon the Extensible Markup Language (XML) format, web applications use SAML to transfer authentication data between two parties - the identity provider (IdP) and the service provider (SP).
You can also set up SSO and restrict which login methods users can use to access your account through the login settings wizard. If you have an SAML-based SSO set up, you can require users to log in to HubSpot using their SSO credentials.
Permissions required
Super Admin permissions are required to set up or edit single sign-on.
The SSO setup process should be done by an IT administrator with experience creating applications in your identity provider account.
Log in to your identity provider account.
Navigate to your applications.
On the Login tab, if you haven’t configured your portal login settings, click Setup Portal Login Settings. Or, in the Single sign-on (SSO) section, click Configure.
In the right panel:
XML upload is available for all SSO set-ups. Drag and drop or click Choose a file to upload your federation metadata. Then, click Verify.
If you're using Microsoft AD FS, toggle the I'm using Microsoft AD FS (legacy on-premise) switch on. Then, click Copy next to the values as needed. Paste the values from your identity provider below. Click Verify.
The navigation instructions and field names above may differ across identity providers. You can find more specific instructions for setting up applications with commonly used identity providers below:
Microsoft Entra ID (formerly Azure AD)
you're using Active Directory Federation Services, learn more about
Require SSO for all users
After setting up SSO, you can require all users to use SSO to log in to HubSpot. This setting is turned on by default.
On the Login tab, in the Single sign-on (SSO) section, select the Require single sign-on checkbox.
Exclude specific users from SSO requirement
After setting up SSO, you can exclude specific users from the SSO requirement to allow them to also log in with their HubSpot user account.
In the left sidebar menu, select Security.
On the Login tab, in the Single sign-on (SSO) section, click Manage exempted users.
In the dialog box, click the Choose users dropdown menu and select the users that'll be able to log in with their HubSpot accounts. For example, you can select partners and contractors if they lack an SSO login.
Click Add application.
On the application's details page, click the Sign On tab.
Under the "SAML 2.0 is not configured until you complete the setup instructions" message, click View Setup Instructions. This will open a new tab. Keep it open, then return to the original tab in Okta.
In the same tab, scroll down to Advanced Sign-on Settings and add your Hub ID in the Portal Id field. Learn how to access your Hub ID.
Navigate to your user settings. Assign the new app to any users that are also in your HubSpot account, including yourself.
Return to the View Setup Instructions tab. Copy each of the URLs and the certificate, and paste them in HubSpot in the Identity Provider Identifier or Issuer URL field, the Identity Provider Single Sign-On URL field, and the X.509 Certificate field.
Click Verify. You’ll be prompted to log in with your Okta account to finish the configuration and save your settings.
Please note: you need administrative access in your OneLogin instance to create a new SAML 2.0 application in OneLogin, as required.
Log in to OneLogin.
Navigate to Apps.
Search for HubSpot.
Click the app that states "SAML2.0".
In the upper right, click Save.
Click the Configuration tab.
In the HubSpot Account ID field, add your Hub ID. Learn how to access your Hub ID.
Click the SSO tab.
Copy the following fields from OneLogin and paste them into the corresponding fields of the SSO setup panel in HubSpot:
Copy the value under Issuer URL and paste it into Identity Provider Identifier or Issuer URL.
Copy the value under SAML 2.0 Endpoint (HTTP) and paste it into Identity Provider Single Sign-on URL.
Once your SSO setup has been verified, navigate to https://app.hubspot.com/login/sso and enter your email address. HubSpot will look up your portal's single sign-on configuration and send you to your SSO provider to sign in. You’ll also see a Log in with SSO button when visiting a direct link to your account.
Once your SSO setup has been verified, navigate to https://app.hubspot.com/login/sso and enter your email address. HubSpot will look up your account's single sign-on configuration and send you to your SSO provider to sign in. You’ll also see a Log in with SSO button when visiting a direct link to your account.
Set up SSO using multiple identity providers
Use multiple single sign-on configurations to manage access across different identity providers within your HubSpot account. This can help your organization manage users across regions, subsidiaries, or systems that require separate identity providers. For example, if your company uses separate IdPs for North America and Europe, you can configure both in the same HubSpot account so users can select the proper IdP when they log in.
Enter the identity provider details and a configuration name.
If your account has no requirements but has turned on SSO, you can log in with any method including SSO.
Can I configure and use SSO during a HubSpot trial?
Yes. If your account has any
Professional or
Enterprise trial, a
Super Admin can set up SSO for your account.
Does SSO impact other HubSpot account types?
MFA:Configure approved 2FA methods for users
https://knowledge.hubspot.com/account-security/configure-allowed-2fa-methods-for-users
Configure approved 2FA methods for users
Skip to content
Setup, how-to, and troubleshooting guides
続きを読む(ほか 65 段落)
Developer Documentation
Reference for API & CMS development
Academy Content Library
A complete library of Academy’s free online video lessons and certification courses.
Academy Certification Courses
A collection of lessons and practical exercises leading to an industry-recognized certification in HubSpot’s tools or strategy.
Classroom Training
Schedule in-person training for a hands-on and personalized HubSpot training experience.
CRM & Sales Hub
Ask and answer questions about using HubSpot’s CRM and Sales Hub.
Discuss and learn HubSpot’s marketing tools and inbound strategy.
Learn about Service Hub and share your expertise.
Meet the Experts
Learn how to get the most out of HubSpot from those who know it best.
Search, vote for, and submit ideas to improve the HubSpot platform.
HubSpot Developers
Ask questions and connect with users building on HubSpot.
HubSpot User Groups
Meet regularly with your local community of HubSpot users.
Marketing, sales, agency, and customer success blog content.
Examples of how real customers use HubSpot for their business.
Product Updates Blog
Updates on the latest releases from HubSpot’s Product team.
Account & Setup
Account Security
Available with any of the following subscriptions, except where noted:
Starter, Professional, Enterprise
Professional, Enterprise
Configure which two-factor authentication (2FA) methods your team can use when logging in to your HubSpot account. Standardizing 2FA methods helps align login requirements with your organization's security policies. For example, you can require users to log in using an authenticator app (e.g., Google Authenticator) instead of SMS-based 2FA.
Learn more about improving your account security with login and password best practices.
Permissions required
Super Admin permissions are required to manage approved 2FA methods.
Before you get started
The setting is turned off by default, allowing all HubSpot-offered 2FA methods.
The HubSpot mobile app will always be turned on by default as a 2FA method and cannot be turned off.
This setting limits 2FA methods when logging in through a browser only. It does not limit 2FA methods when logging in through the HubSpot mobile app. For example, if your account has limited 2FA options, users logging in through the HubSpot mobile app can still use all HubSpot-offered 2FA methods.
Configure approved 2FA methods
Manage the two-factor authentication methods available to users when signing in to HubSpot.
In your HubSpot account, click the settings icon in the top navigation bar.
In the left sidebar menu, navigate to Security.
On the Login tab, in the Account 2FA preferences section, toggle the Approved 2FA methods switch on.
If you're configuring approved 2FA methods for the first time, click Setup Portal Login Settings and continue setting up the login methods.
Select the checkboxes for the 2FA methods you want to approve for your users:
Authenticator app (recommended): enter a one-time code from an app like Google Authenticator, Authy, or Duo.
Text message (least secure): enter a one-time code sent through text message.
HubSpot mobile app: receive a notification from the HubSpot mobile app. This method is turned on by default and can't be turned off.
Impact of changing approved 2FA methods
When you configure or change the allowed 2FA methods in your HubSpot account, the user experience will vary depending on whether they have already set up a 2FA method or not.
For users with an existing 2FA method that is no longer approved: the user will be able to log in with that 2FA method the next time they log in. After logging in, the user will be prompted to set up one of the allowed methods for future logins.
For users who do not have any 2FA method set up: after entering their username and password, the user will be prompted to enter a verification code sent to their email. Following this, they will be prompted to set up one of the approved 2FA methods.
Was this article helpful?
Thanks for letting us know. How would you describe this article?
Inaccurate: it doesn’t reflect what I see in the product
Unclear: it’s difficult to understand
Missing information: it’s not comprehensive enough
Irrelevant: it doesn’t match what I searched for
Great! Is there anything we could change to make it even more helpful?
Is there anything we could change to make this article helpful?
Allow HubSpot to contact me about my documentation feedback.
Only used if we need clarification on your feedback.
Thank you for your feedback, it means a lot to us.
This form is used for documentation feedback only. Learn how to get help with HubSpot.
Table of contents
Related content
knowledge.hubspot.com -->
2FA:Set up two-factor authentication for your HubSpot login
Set up two-factor authentication for your HubSpot login
Examples of how real customers use HubSpot for their business.
Product Updates Blog
続きを読む(ほか 51 段落)
Updates on the latest releases from HubSpot’s Product team.
Account & Setup
September 28, 2026
Please note: the available methods for setting up 2FA may vary depending on your HubSpot subscription level and country or region. 2FA using the Google Authenticator app is supported globally. The countries that support SMS 2FA are the same as the supported countries for calling.
Authenticator app (recommended)
When logging in with the Office 365 add-in integration, you cannot use the Sign in with Google 2FA method. You must use your HubSpot email and password.
If you have already set up 2FA with Google Authenticator but have switched to a new Android phone, you can transfer Authenticator codes to your new device.
Set up 2FA for your account
To set up 2FA in HubSpot:
In your HubSpot account, click the settings icon in the top navigation bar.
In the left sidebar menu, navigate to General > Security.
Select from the following authentication methods:
Passkey (most secure): log in using biometrics, Face ID, or a device pin. Learn how to set up passkeys.
Authenticator app (more secure): enter a one-time code using a third party authenticator app.
To set up 2FA using an authenticator app or SMS, follow the on-screen instructions to set up the third party app or phone number. In HubSpot, click Next.
Click Done or add a secondary 2FA method. 2FA will apply the next time you log in to your HubSpot account.
Click Remember me to avoid being asked for 2FA for 28 days.
Click Ask every time to always prompt for 2FA every time you log in.
Set up a secondary 2FA method
After you've set up your primary 2FA method, it's strongly recommended to set up a secondary method. A secondary method will allow you to log in to HubSpot if you can't access your primary method or backup codes.
To set up a secondary authentication method:
In the Two-factor authentication (2FA) section, you can view your primary 2FA method listed, along with an option to set up a secondary method of either 2FA SMS messages or a third party authenticator app. If you choose 2FA SMS messages, it is recommended you set up a trusted phone number:
To add a trusted phone number, in the Trusted Phone Number section, click Add a trusted phone number.
On the Trusted Phone Number screen, type your phone number in the text box.
A six-digit code will be sent to the phone number. Type the code in the text box, then click Next.
A verified screen will appear after you input the six-digit code. Click Done.
After setting up a trusted phone number, or if you're selecting a third party authenticator app, click Text message or Authenticator app. Follow the on-screen instructions to finish setting up your secondary method.
Reset your 2FA login
If you lose your 2FA device and don't have access to a passkey, secondary 2FA method, or backup codes, you'll need to reset your 2FA to regain access to your account. Learn how to reset your 2FA and passkeys.
Turn off 2FA for your login
For Starter, Professional, and Enterprise accounts, 2FA is required for all users logging in with a username and password. If you have a Professional or Enterprise account where single sign-on is required, or if you're using HubSpot's free tools, you can turn off 2FA for your login.
Please note: it is highly recommended that you keep 2FA turned on to protect your account. Because logging in with 2FA requires you to have access to a secondary device, the risk of an intruder gaining access to your account is much lower.
To turn off 2FA for your login:
In the Two-factor authentication section, click Remove [Primary method], and if turned on, Remove [Secondary method].
Please note: as of March 20, 2026, the HubSpot mobile app is temporarily unavailable when setting up 2FA methods. If you've previously set up 2FA with the HubSpot mobile app, you can continue to use this method when logging in. If you remove the HubSpot mobile app as a 2FA method, it can't be re-added. To set up 2FA, you'll need to use a passkey, an authenticator app, or SMS.
In the dialog box, input the 2FA code sent to your primary or secondary method. If you don't have access to either method, but have your backup codes, click Use a backup code. If you don't have access to any of these methods, click Lost your authentication device? to reset your 2FA to regain access to your account. Once you regain access to your account, you can then turn off 2FA.
In the next dialog box, click Turn off.
After you have turned off your primary and secondary methods for 2FA, you'll no longer need 2FA to access your account.
Require 2FA for all users
Permissions required
Super Admin or Edit account defaults permissions are required to enforce 2FA.
2FA is required for all HubSpot Starter, Professional, and Enterprise accounts and can't be turned off. Accounts using HubSpot’s free tools can choose whether to require 2FA. The requirement applies account-wide. Individual users can't be excluded.
In the left sidebar menu, navigate to Security.
On the Login tab, toggle the Enforce 2FA to log in switch on.
In the dialog box, click Yes.
Once turned on, every user in the account will receive an email and an in-app notification to turn on 2FA in their account.
Backup codes are used to log in to your account if you lose your 2FA device. Once you have configured 2FA, you may receive the Check your 2FA backup codes notification. This is an automated reminder to confirm that your backup codes are saved. Receiving this notification does not indicate a security issue. If you can't locate your saved backup codes, generate new codes and save them to your device.
How do I access or refresh my 2FA backup codes?
In the left sidebar menu, click General > Security.
In the Two-factor authentication (2FA) section, click View backup codes.
In the dialog box, click Print or Download (PDF) to save your backup codes.
IP制限:Manage login and account access settings
https://knowledge.hubspot.com/account-security/limit-logins-to-trusted-ip-addresses
Meet regularly with your local community of HubSpot users.
Marketing, sales, agency, and customer success blog content.
Examples of how real customers use HubSpot for their business.
続きを読む(ほか 37 段落)
Product Updates Blog
Updates on the latest releases from HubSpot’s Product team.
Account & Setup
Account Security
September 22, 2026
Available with any of the following subscriptions, except where noted:
All products and plans
Additional subscriptions required for certain features
To manage access to your HubSpot account, you can limit logins to specific IP addresses or locations, restrict users to a single account, and manage HubSpot employee access. These settings help you improve your account's security and keep control over who can log in and view your HubSpot data.
Limit logins to trusted IP addresses
Subscription required
A Starter, Professional, or Enterprise subscription is required to limit logins to trusted IP addresses.
Permissions required
Super Admin permissions are required to limit logins to trusted IP addresses.
Limit HubSpot account access to trusted IP addresses. You can block logins from VPNs or from IPs outside your network, and restrict unauthorized access from personal or public computers and unsecured WiFi networks. Any bad actors logging in from outside your allowed IP range will be blocked even if they have proper login credentials. Learn more about the ways HubSpot helps you secure your account.
If this is your first time configuring your login settings, learn how to use the login settings wizard to restrict which login methods users can use to access the account.
Please note: limiting logins to trusted IP addresses applies to logins on both computers and mobile devices. If users log in using their mobile device outside of an allowed IP address, they will be blocked from accessing the account.
To limit logins to trusted IP addresses:
In your HubSpot account, click the settings icon in the top navigation bar.
In the left sidebar menu, under Account management, click Security.
On the Login tab, under Account restrictions, toggle the Allowed login IPs switch on.
In the Allowed IP Addresses section, enter the IP addresses in the text box. Use commas to separate different IP addresses or dashes to represent an IP address range.
To exempt certain users from limited logins to allowed IPs, click the Exempt Users dropdown menu and select the checkboxes next to the users you wish to exempt.
On the bottom left, click Save.
Limit logins to allowed locations
A Starter, Professional, or Enterprise subscription is required to limit logins to approved locations.
Super Admin permissions are required to limit logins to approved locations.
Manage HubSpot account access by approving locations that users can log in from. This helps you secure your account by ensuring only users in allowed regions can access your data. For example, you can approve specific countries or regions for your team while blocking login attempts from unauthorized areas.
To configure allowed locations:
In the left sidebar menu, under Account Management, click Security.
On the Login tab, in the Allowed login locations section, click Configure.
In the Manage approved locations panel, view the suggested locations based on your account's login history.
To view which users are logging in from a specific location, click [number] users. This displays a list of users logging in from that location with the last date each user logged in.
To add a new location, click Add locations.
Click the Country dropdown menu and select the checkboxes next to each country you want to approve.
If you’re adding a location in the United States, click the State dropdown menu and select the checkboxes next to each state you want to approve.
If a user logs in from a location that has not been approved, they'll receive the following error message: There was a problem logging you in.
監査ログ:View and export account activity history
https://knowledge.hubspot.com/account-management/view-and-export-account-activity-history
Updates on the latest releases from HubSpot’s Product team.
Account & Setup
Account Management
続きを読む(ほか 79 段落)
September 23, 2026
Country, region, and IP address of the user that made the change.
Users in an account with an Enterprise subscription can:
Click the success checkmark to resolve a comment.
To filter comments, click the Comments dropdown menu, and select Open comments, All comments, or Resolved comments.
To export the entire audit log or an audit log based on the selected filters, click Export report. Then, click Export.
View the user analytics tab
an Enterprise account is required to eview the user analytics tab.
To view user analytics from your Audit Logs page:
In the left panel, under Data Management, click Audit Logs.
At the top, click the Analyze tab.
On the Analyze tab:
At the top, you can see an overview of total daily logins, total daily deletions, total daily exports, and total daily reports. Click View Details to be taken to a centralized audit log for that specific action.
Below the overview, you can view charts of user activity by category, action, login trend, and CRM record. You can also filter each section by clicking the dropdown menus next to each option. Click View Filtered Records to be taken to a centralized audit log for that specific action.
Set up notifications for audit log events
Super admins can set up audit log notifications for their account. Once turned on, you'll receive notifications via email when the corresponding event occurs. To set up notifications for audit log events:
In the left panel, under Your Preferences, click Notifications.
At the top, click the Notifications tab.
Scroll down and click Audit logs.
Set up your notifications:
Select the Multiple Exports checkbox to be notified when a high number of exports get logged in a day.
Select the Removed admin permission checkbox to be notified when a user’s admin permissions are removed.
HubSpot employee access history
By default, HubSpot employees have limited access to your HubSpot account. This allows employees such as your account manager and support specialists to help with your account.
Super Admins in an Enterprise account can view what actions were taken by HubSpot employees whilst they were logged into your account, using the Audit Log.
Super Admins in Starter, Professional, or Enterprise accounts can view when HubSpot employees logged into your account by exporting the last 90 days of logins. Each export has timestamps for each case of employee login, and the department that the employee works in at HubSpot.
Account Management: members of your account management team. Account managers might enter your account to assist during strategy calls or check on your progress and success with HubSpot.
Services: members of HubSpot's Services team, like technical consultants, onboarding specialists, and site migration managers. Services employees might enter your account to assist you or check on the status of services you’ve purchased.
Customer Support: members of HubSpot's technical support team. Customer support might enter your account to help troubleshoot bugs or help members of your team learn about the HubSpot product.
Sales: members of HubSpot's sales team. The sales team might enter your account during a product demo, or to determine how to help you get the most value from using HubSpot.
Product/User Experience: members of HubSpot's product and UX teams. Product and UX teams might enter your account to follow up on feedback or questions that you’ve raised about HubSpot functionality.
HubSpot employees in other departments might occasionally log in, and take actions in your account for reasons not listed above. If you have questions about the information you're seeing in your export, you can contact HubSpot support.
Learn how to remove HubSpot employee account access.
Export HubSpot employee access history
To export HubSpot employee access history:
In the left panel, under Account Management, click Security.
Under the Login tab, scroll down and click therightright arrow next to Allow Access to expand the section.
Click Download employee access history. If you're unable to see Download employee access history, click Setup Portal Login Settings. After setting up your login settings, the option will be available.
Starter accounts
CRM object association definition updated:
A new association configuration is created.
An existing association configuration is deleted.
An association label is changed.
An association limit is changed.
CRM object activation/deactivation and renaming
CRM record view
Customer Agent actions
Data privacy requests
Multi-account management
Pipeline changes
Property updates
Property value updates
Conditional property logic
Conditional property options
Record creation form
Salesforce activity (updates made in HubSpot by the Salesforce integration)
Sensitive property values
Auto association of companies to contacts is turned on or off.
AI Assistant settings for content prompts or customer analysis turned on or off.
Security activity history
Super Admins can export security activity history to see a list of security-related actions that users have taken in the account in the last year. The following user actions are included in each export:
Adding, removing, or requiring single sign-on (SSO) or two-factor authentication (2FA).
Importing acceptance tests.
Exporting contacts or users.
Adding, removing, or impersonating users and admin.
Adding or removing admin permissions.
Deactivating or reactivating users.
Turning email tracking and attachment logging settings on or off .
Adding or removing email recipients from the Never Log list.
Performing a permanent delete of a contact.
Sending manual registration emails or password reset emails.
Creating a payment account and updating information, account changes, or sending payment onboarding links.
Creating, syncing, or deleting sandboxes.
For each user action, the export will show:
The time of the action.
The type of action.
The user's email address.
The ID of the affected object.
The approximate location.