SaaS ITGC チェック

ツール一覧 › Slack

Slack のアクセス管理機能(SSO・MFA・IP制限・監査ログ)

公式資料によると、Slack は MFA・SSO・2FA・IP制限・監査ログ に対応しています。(資料の取得日 2026-10-03)

判定(かんたん基準)

Step1:MFA(1.00) / SSO(1.00) + 監査ログ(0.95)|許可
最終|許可

かんたん基準:Step1 は「MFA か SSO」に対応し、かつ監査ログを取得できれば許可。Step2 は「2FA か IP制限」に対応し、かつ監査ログを取得できれば許可。どちらも満たさなければ、個人情報・取引情報・財務情報・機密情報を扱うかどうかで決まります。括弧内は「対応している」確率です。

項目ごとの読み取り

項目公式資料の記載対応している確率
MFA対応と記載1.00
SSO対応と記載1.00
2FA対応と記載1.00
IP制限対応と記載0.97
監査ログ対応と記載0.95

根拠(公式資料の原文)

Set up SAML single sign-on for Slack

https://slack.com/intl/en-gb/help/articles/203772216-Set-up-SAML-single-sign-on-for-Slack

Who can use this feature? Workspace owners and org owners

Available on the Business+ and Enterprise subscriptions

Available on the Free and Pro subscriptions if you’ve connected a Salesforce org to Slack

Choose whether SSO is required for all members, required for all members excluding guests or optional.

If you chose to require SSO, your members will see a sign-in page before they can access Slack.

Mandatory workspace two-factor authentication

https://slack.com/intl/en-gb/help/articles/212221668-Mandatory-workspace-two-factor-authentication-

Who can use this feature? Org owners, org admins, and workspace owners

Available on all subscriptions

For an added layer of security, you can require your members and guests to use two-factor authentication (2FA) when they sign in to Slack.

By default, people can choose between SMS text message and authentication app 2FA methods. On paid subscriptions, owners and admins can restrict this to prevent members from using SMS for 2FA.

Tick the box next to Require members to have 2FA set up. If you like, select Authenticator apps only to prevent people from using SMS for 2FA.

People who don’t set up 2FA within 24 hours will be signed out of Slack and prompted to set up 2FA before they can sign in again.

Note: If you’re using SSO, 2FA should be set up through your identity provider.

Slack updates and changes

https://slack.com/intl/en-gb/help/articles/115004846068-Slack-updates-and-changes

Org owners and org admins can control access to their Enterprise orgs with IP allowlists.

Audit logs in Enterprise Grid

https://slack.com/intl/en-gb/help/articles/360000394286-Audit-logs-in-Enterprise-Grid

Who can use this feature? Org owners and members with the audit logs admin system role

Available on Enterprise subscriptions

Audit logs provide a record of changes and usage that help to keep your Slack Enterprise organisation secure and protect against misuse. You can view audit logs directly in Slack, export them as a CSV and use the Audit Logs API to create custom monitoring tools.

To export audit logs, click Export in the top right-hand corner of the page and select Export CSV or Export JSON.

この結果について

確認状況
未確認(自動判定)
資料の取得日
2026-10-03
判定日
2026-10-03
判定モデル
TypeSafe Jev(jev-1.13.0)。公式資料の原文から各項目の記載を読み取り、判定の木はプログラムで計算しています。