We are running into an issue with two factor authentication for our Hubspot Outlook add-in and I wondered if anyone else has seen similar, or has some suggested workarounds.
Our corporate setup is to use Okta 2FA and I have been able to set this up for Hubspot with no problem. When users do not log on to Hubspot for 3 days they are prompted for their Okta credentials and are then able to access it. We use LastPass for password management and this works fine.
However, when the Outlook add-in has a similar timeout the add-in pops up a modal dialog for the user to enter credentials. Because it is a modal dialog it will not access the Lastpass add-in. Therefore users have to manually enter their Okta credentials which are deliberately rotated every few weeks for security (hence LastPass).
As a temporary workaround we are using Hubspot 2FA (the Hubspot mobile app) but this is breaching our internal security policy so I would like to find a permanent fix. Having a 30 day timeout on tokens would help (https://community.hubspot.com/t5/HubSpot-Ideas/Extend-options-for-hubspot-user-session-timeout-length/idc-p/1045999#M194277) but the fix that’s needed here is to allow modal dialogs to access the Lastpass add-in from Outlook
Hey @DarrenSimons, thank you for posting in our Community!
The HubSpot Outlook add-in’s modal dialog currently doesn’t support LastPass with Okta 2FA, creating that extra step. Using HubSpot 2FA is a good temporary workaround
To our top experts, @TomM2 and @danmoyle do you have any recommendations for @DarrenSimons matter?
Thank you,
Pam
Thanks @PamCotton. I have found another workaround which partly works, which is to to force Microsoft logon on signing in. This seems to work for us because our Microsoft 365 setup uses Okta, and Hubspot seems happy to authorise against that (the Microsoft logon and Hubspot logons use identical email addresses).
However, on the Hubspot addin each time I start Outlook I have to log in again, stating I’m using Microsoft login. Once I then choose my Microsoft ID it accepts this and lets me log in. It seems odd though that it doesn’t have any caching at all of my Microsoft credentials. Would that be the same issue or something different? If I could extend the token from Outlook session to 30 days this would work great for me.
Thanks,
Darren
Nothing to add here, @PamCotton. @DarrenSimons it looks like you sort of have a workaround, which is the best I’d be able to offer as an idea. The 2FA and security world is definitely wreaking havoc with users, especially when there are multiple layers. Have you added this use case to the ideas forum? That might be one way to encourage HubSpot to make some changes.