SaaS ITGC チェック

ツール一覧 › Notion

Notion のアクセス管理機能(SSO・MFA・IP制限・監査ログ)

公式資料によると、Notion は MFA・SSO・2FA・IP制限・監査ログ に対応しています。(資料の取得日 2026-10-03)

判定(かんたん基準)

Step1:MFA(1.00) / SSO(0.99) + 監査ログ(0.97)|許可
最終|許可

かんたん基準:Step1 は「MFA か SSO」に対応し、かつ監査ログを取得できれば許可。Step2 は「2FA か IP制限」に対応し、かつ監査ログを取得できれば許可。どちらも満たさなければ、個人情報・取引情報・財務情報・機密情報を扱うかどうかで決まります。括弧内は「対応している」確率です。

項目ごとの読み取り

項目公式資料の記載対応している確率
MFA対応と記載1.00
SSO対応と記載0.99
2FA対応と記載1.00
IP制限対応と記載0.98
監査ログ対応と記載0.97

根拠(公式資料の原文)

SAML SSO configuration in Notion

https://www.notion.com/help/saml-sso-configuration

Notion provides Single Sign-On (SSO) functionality for Business and Enterprise customers to access the app through a single authentication source.

This feature is only available for users on the Business Plan or Enterprise Plan.

To use SSO with Notion: Your workspace must be on a Business Plan or Enterprise Plan.

Only workspace members can use SAML SSO to log in.

Two-step verification in Notion

https://www.notion.com/help/two-step-verification

By enabling two-step verification, you can help keep your Notion account and your organization more secure.

This feature is available to all plan types and can be set up easily in your account settings.

In order to use 2-step verification, you must: Have a password. Not be in an organization that requires login via identity provider (such as Okta, Microsoft Azure, Google Workspace, etc.).

IP address restrictions in Notion

https://www.notion.com/help/ip-address-restrictions

Enterprise organization owners can restrict login to specific IP addresses.

To set up allowed IP addresses, you must be an Enterprise organization owner.

Workspace audit log in Notion

https://www.notion.com/help/audit-log

Audit logs give Enterprise organization owners access to detailed information about security and safety-related activity.

The audit log feature is available to organization owners on the Enterprise Plan.

Audit logs give you information about events that happen across your organization's workspaces, as well as who took specific actions and when.

You can export your audit log as a CSV.

この結果について

確認状況
未確認(自動判定)
資料の取得日
2026-10-03
判定日
2026-10-03
判定モデル
TypeSafe Jev(jev-1.13.0)。公式資料の原文から各項目の記載を読み取り、判定の木はプログラムで計算しています。