Skip to content

Configure approved 2FA methods for users

Last updated: June 25, 2026

Available with any of the following subscriptions, except where noted:

Configure which two-factor authentication (2FA) methods your team can use when logging in to your HubSpot account. Standardizing 2FA methods helps align login requirements with your organization's security policies. For example, you can require users to log in using an authenticator app (e.g., Google Authenticator) instead of SMS-based 2FA.

Learn more about improving your account security with login and password best practices

Permissions required Super Admin permissions are required to manage approved 2FA methods.

Before you get started

  • The setting is turned off by default, allowing all HubSpot-offered 2FA methods. 
  • The HubSpot mobile app will always be turned on by default as a 2FA method and cannot be turned off. 
  • This setting limits 2FA methods when logging in through a browser only. It does not limit 2FA methods when logging in through the HubSpot mobile app. For example, if your account has limited 2FA options, users logging in through the HubSpot mobile app can still use all HubSpot-offered 2FA methods.

Configure approved 2FA methods

Manage the two-factor authentication methods available to users when signing in to HubSpot.

  1. In your HubSpot account, click the settings icon in the top navigation bar.
  2. In the left sidebar menu, navigate to Security.
  3. On the Login tab, in the Account 2FA preferences section, toggle the Approved 2FA methods switch on.
    • If you're configuring approved 2FA methods for the first time, click Setup Portal Login Settings and continue setting up the login methods
  4. Select the checkboxes for the 2FA methods you want to approve for your users:
    • Authenticator app (recommended): enter a one-time code from an app like Google Authenticator, Authy, or Duo. 
    • Text message (least secure): enter a one-time code sent through text message.
    • HubSpot mobile app: receive a notification from the HubSpot mobile app. This method is turned on by default and can't be turned off. 

  1. Click Save.

Impact of changing approved 2FA methods 

When you configure or change the allowed 2FA methods in your HubSpot account, the user experience will vary depending on whether they have already set up a 2FA method or not. 

  • For users with an existing 2FA method that is no longer approved: the user will be able to log in with that 2FA method the next time they log in. After ‌logging in, the user will be prompted to set up one of the allowed methods for future logins. 
  • For users who do not have any 2FA method set up: after entering their username and password, the user will be prompted to enter a verification code sent to their email. Following this, they will be prompted to set up one of the approved 2FA methods. 
Was this article helpful?
This form is used for documentation feedback only. Learn how to get help with HubSpot.