Skip to content
  • There are no suggestions because the search field is empty.

HubSpot account security: essential settings and best practices

Understand the HubSpot settings and organisational controls that help protect account access, user permissions, backups and exported CRM data.

HubSpot account security helps protect your organisation from unauthorised access, data loss and other security incidents.

HubSpot provides tools for controlling how users sign in, strengthening authentication, reviewing account risks and protecting CRM data. These technical controls should form part of a wider organisational approach covering access management, data protection, retention and incident response.

The features available may depend on your HubSpot subscription and permissions.

Single sign-on

Single sign-on (SSO) allows users to access HubSpot through an organisation’s identity provider rather than relying solely on separate HubSpot credentials.

HubSpot supports SAML-based SSO with identity providers such as Microsoft Entra ID, Google Workspace, Okta and OneLogin.

SSO can help organisations:

  • Centralise user authentication
  • Apply consistent access policies across applications
  • Simplify access removal when somebody leaves or changes role
  • Reduce reliance on separate passwords
  • Manage access across multiple identity providers where required

Super Admin permissions are required to configure or edit SSO. HubSpot currently makes SSO available with Professional and Enterprise subscriptions.

HubSpot recommends exempting at least one trusted Super Admin from an enforced SSO requirement. This provides an alternative way to access the account if the identity provider becomes unavailable. Your organisation should control and monitor any exempt accounts carefully.

For current availability and configuration instructions, see Set up single sign-on.

Control allowed login methods

Super Admins can control which login methods users are permitted to use.

Available methods can include:

  • HubSpot email and password
  • Google
  • Microsoft
  • Apple
  • Passkeys
  • SSO, with an eligible subscription

Organisations can allow more than one method, choose when restrictions will be enforced and exempt specific users where there is a justified operational need.

HubSpot’s login settings can also be used to configure inactivity timeouts and, where appropriate, restrict access by IP address.

Before restricting login methods, confirm that users are enrolled in an approved method and that an appropriately controlled recovery route is available. Otherwise, users could be locked out of the account.

For current instructions, see Restrict which login methods users can use to access your account.

Require two-factor authentication

Two-factor authentication (2FA) adds a second verification step when a user signs in with a password.

HubSpot requires 2FA for Starter, Professional and Enterprise accounts. Organisations using HubSpot’s free tools can configure an account-wide 2FA requirement.

Depending on the options available, authentication methods can include:

  • The HubSpot mobile app
  • An authenticator application
  • Passkeys
  • Text messages
  • Other methods currently supported by HubSpot

Users should configure appropriate primary and recovery methods and store recovery information securely. Recovery codes should not be shared or kept somewhere accessible to unauthorised people.

When SSO and HubSpot 2FA are both configured, the authentication experience depends on whether a user is required to use SSO or is exempt from it. Administrators should review HubSpot’s current guidance before deciding how these controls should work together.

For current instructions, see Set up two-factor authentication for your HubSpot login.

Review Security Health

HubSpot’s Security Health area helps administrators assess important security measures across the account.

Its checks can include:

  • Inactive users
  • 2FA enrolment
  • Critical permissions
  • Super Admin access
  • Partner users with Super Admin access

HubSpot considers a user inactive when they have not logged in during the previous 90 days. Depending on the account and settings available, inactive users may be scheduled for automatic deactivation.

Security Health can be managed by Super Admins and users with appropriate Security Center access.

Security reviews should be completed regularly rather than treated as a one-off exercise. Administrators should investigate each recommendation before making a change, particularly where a user may require occasional or emergency access.

For current guidance, see Manage your account security using HubSpot Security Health.

Apply least-privilege access

Users should receive only the permissions they need to perform their role.

Review access regularly, particularly for:

  • Super Admin permissions
  • Billing access
  • User and permission management
  • Data import and export
  • Record deletion
  • App installation
  • Workflow and automation changes
  • Partner access
  • Access to sensitive information

Remove or reduce access when somebody changes role, leaves the organisation or no longer requires a particular capability.

Access decisions remain the responsibility of your organisation. HubSpot provides the technical controls, but your organisation must decide who should receive access and how that access should be approved and reviewed.

For permission-management guidance, see Add and edit user permissions.

Back up CRM data

HubSpot provides tools for backing up CRM records, including contacts, companies, deals, tickets and other supported objects.

The backup frequency, available options and restoration capabilities depend on your HubSpot subscription.

Backups can provide an additional safeguard, but they should form part of a documented recovery process. Your organisation should understand:

  • What data is included
  • How frequently backups are created
  • How long backup files are retained
  • Who can create, download and access them
  • Whether and how data can be restored
  • How recovery procedures will be tested

For current availability and instructions, see Back up CRM data.

Protect CRM backup and export files

A CRM backup or data export may contain personal, confidential or commercially sensitive information.

Once a file has been downloaded from HubSpot, it is stored outside HubSpot’s platform controls. Your organisation must protect that copy through its own security, access, retention and deletion processes.

Appropriate controls may include:

  • Restricting access to authorised users
  • Using approved, encrypted storage
  • Preventing storage on unmanaged devices
  • Recording who created and accessed the export
  • Applying documented retention and secure-deletion periods
  • Including exported files within incident-response procedures
  • Considering applicable UK GDPR and other legal obligations

Your organisation should obtain advice from its data protection, information security or legal specialists where necessary. HubSpot configuration alone does not determine whether an export or its subsequent use is lawful or appropriate.

For information about the data that can be exported, see Export your content and data.

Control who can export CRM data

Export permissions should be granted only where there is a legitimate operational need.

As part of your access-management process:

  • Identify which roles genuinely require export access
  • Apply the least-privilege principle
  • Review export permissions regularly
  • Remove access when it is no longer required
  • Document how exported information should be stored, shared and deleted
  • Investigate unexpected or inappropriate export activity

Only users with the appropriate permissions should be able to export CRM data.

Understand the boundaries of responsibility

HubSpot controls the technical security of data held within its platform according to its services and contractual commitments.

Your organisation decides:

  • Who is permitted to access the account
  • Which authentication methods should be allowed
  • Who receives elevated or export permissions
  • Whether and why data should be exported
  • Where exported files are stored
  • How long exported information is retained
  • Which legal, regulatory and internal requirements apply

Forbidden can advise on HubSpot configuration and permission design. Unless separately agreed, Forbidden does not store, process, monitor or audit CRM backup and export files downloaded by your organisation.

What to remember

HubSpot account security is an ongoing responsibility.

Super Admins and account owners should regularly review:

  • Login and authentication methods
  • SSO exemptions and recovery access
  • 2FA adoption
  • Inactive users
  • Super Admin and critical permissions
  • Partner access
  • Export permissions
  • Backup arrangements
  • The storage and retention of downloaded data

Particular care is required when information leaves HubSpot through a backup or export because your organisation’s own controls then determine how that copy is protected.

What can Forbidden help with?

Forbidden can help you review and configure HubSpot authentication settings, user roles, permissions, Super Admin access, partner access, export permissions and account-security recommendations.

We can also help you document HubSpot-specific access and backup processes. Decisions concerning organisational risk, legal compliance, data protection, identity-provider policy and the handling of downloaded files remain your organisation’s responsibility and should involve the appropriate internal specialists.

Further information