Quick tipHow toSmart CRM

Lock down who can log in to HubSpot: login methods, 2FA, IP rules and session timeout

Login security is set once for the whole account. Paid accounts already require 2FA, and the rest is worth five minutes.

Subscription
2FA required on Starter, Professional and Enterprise; some restrictions vary by tier
Permissions
Super Admin or Edit account defaults
Time
4 min · Beginner
Last verified

Short answer

Settings, Security, Login tab is where you set allowed login methods, IP restrictions, session timeout and allowed 2FA methods for every user. HubSpot's KB says 2FA is required for all Starter, Professional and Enterprise accounts and cannot be turned off or waived per user. When the requirement is switched on it takes effect after 24 hours, so users have time to set up a method. Text message 2FA is labeled least secure and is not available on free accounts.

1. Where

Go to Settings > Security. The Login tab starts with a setup wizard; Permissions is the second tab.

Security settings Login tab with a Setup Portal Login Settings button
Login and Permissions tabs (1) and the setup button (2).

2. 2FA

  • Required for Starter, Professional and Enterprise accounts. It applies account-wide and individual users cannot be excluded.
  • Passkeys and authenticator apps are available on all tiers. Text message is marked least secure.
  • After switching the requirement on there is a 24 hour grace period. Users without a method set it up at their next login.

3. Other rules

The wizard covers which login methods are allowed, IP address restrictions and session timeout. Set these with your IT team, and keep one Super Admin who can still get in if single sign-on breaks.

Sources

New field notes by email

One email when a new article publishes.

Still stuck?

If this did not fix it, the problem is probably specific to your setup. Book a call and we will look at it together.

Book a call with Sam