HubSpot Ideas

Christian

Force 2-factor authentication (2FA) for all users to comply with GDPR

In relation to GDPR we need to ensure that our data is protected the best possible way, and the Hubspot setup right now is that each individual user needs to turn it on. 

I'm suggesting an option for the Admin to turn it on for all users, so that they're forced to have it, just like we have in Salesforce. 

HubSpot Updates
Delivered
July 15, 2019 08:20 AM

Hey everyone! Big news: we've launched the ability to require two-factor authentication to all of our customers. If you're interested in enabling this feature, you can find it in your Account Defaults settings. Please let me know if you have feedback on the feature! We're thrilled we could get this important security functionality into HubSpot for everyone to use to keep themselves safe.

In Beta
March 18, 2019 02:55 PM

Hey all, we certainly do have a limited beta going for this feature at the moment. If you'd like to be added to the beta, please send me a private message here with your Hub ID, & we'll get you sorted! Thanks.

July 11, 2018 01:07 PM

Hey everyone, I wanted to drop into this thread & let you know that this is definitely something we hear you on, & something that we want to do our best to solve. Privacy requirements & account security are things that we & our customers take very seriously, as well we should.

 

I did want to let you know that, while we don't have a solution in place for this precise request, we've just added a visual icon that will show you which users in your portal have currently enabled 2FA, & can also let you know whether or not that user has generated any backup codes (something we strongly recommend that they do!) You can see the new icon in the Users & Teams section of your portal settings. If a user has the filled version of the icon, shown below, they've enabled both 2FA & backup codes. If they have an unfilled version of it, they have 2FA but haven't completed backup generation yet. The filled icon is shown below:

 

Settings.png

 

22 Replies
JazNE
Member

Why is this being forced on companies that don't have EU contacts in their DB / don't do business there? The Admin should be able to turn this off. Also, if you have SSO on, this is just another madness to deal with!! Unless you work in regulated industries, this really doesn't make any business sense. I have to hang on to my phone every time I get logged out!?

staceys15
Member

How do i turn this off? I need someone to access my account and it will not allow them to.