Blog· HubSpot technical SEO 9 min read

HubSpot SSO Setup Guide for Okta, Entra ID & Google

Learn how to implement Single Sign-On (SSO) in your HubSpot portal to enhance security and simplify user management. This guide provides step-by-step instructions for configuring SSO with Okta, Microsoft Entra ID, and Google Workspace.

HubSpot SSO Setup Guide for Okta, Entra ID & Google — HubStack HubSpot article cover
In this article
  • Prerequisites for HubSpot SSO Implementation
  • Step 1: Initial HubSpot SSO Configuration
  • Step 2: Configuring Okta for HubSpot SSO
  • Step 3: Configuring Microsoft Entra ID (Azure AD)
  • Step 4: Finalizing and Verifying the Connection
  • Managing Users and Enforcing SSO

Single Sign-On (SSO) is no longer a luxury for large organizations; it is a fundamental security requirement for managing access to critical business applications like HubSpot. SSO allows your team members to log in to HubSpot using the same credentials they use for other company systems, such as their corporate email or internal network. This centralized authentication process eliminates the need for separate HubSpot-specific passwords, significantly reducing the risk of security breaches from weak or reused credentials.

The primary benefits of implementing SSO are threefold: enhanced security, simplified user management, and improved user experience. By centralizing authentication through a trusted Identity Provider (IdP), you enforce your company's password policies and multi-factor authentication (MFA) requirements across HubSpot. For administrators, onboarding and offboarding users becomes seamless; access is granted or revoked from a single directory, eliminating the risk of lingering access for former employees. For users, the convenience of one less password to remember streamlines their workflow and reduces friction.

Before proceeding, it is critical to note that configuring Single Sign-On in HubSpot requires a subscription to any of the Enterprise-level Hubs (Marketing, Sales, Service, CMS, or Operations). If your organization is managing a large team or sensitive customer data within HubSpot, the security and administrative efficiencies gained from SSO are a compelling reason to consider an upgrade. For technical assistance with this process, our HubSpot support and maintenance team can manage the entire configuration for you.

Prerequisites for HubSpot SSO Implementation

Before you begin the technical configuration of SSO, you must ensure you have the necessary permissions and subscriptions in place. Attempting to start the process without these prerequisites will lead to roadblocks and delays. First and foremost, your HubSpot account must have an active Enterprise-level subscription. SSO functionality is not available on Free, Starter, or Professional tiers. You can verify your subscription level in your HubSpot portal under 'Account & Billing'.

Next, you will need Super Admin permissions within your HubSpot portal. Only Super Admins have the authority to access and modify security settings, including Single Sign-On configuration. Additionally, you must have administrative access to your organization's chosen Identity Provider (IdP). An IdP is the system that manages your users' digital identities and authenticates them, such as Okta, Microsoft Entra ID (formerly Azure AD), Google Workspace, or OneLogin. Without admin rights in the IdP, you cannot create the necessary application integration to connect with HubSpot.

Finally, gather the necessary information from your IT department. This includes knowing which IdP the company uses and having a clear understanding of your organization's user provisioning policies. Decide whether you will manually create users in HubSpot and then enforce SSO, or if you will use Just-in-Time (JIT) provisioning, which automatically creates a HubSpot user the first time they log in via SSO. Planning this ahead of time ensures a smooth rollout. If you need help structuring your user permissions and roles, a proper HubSpot CRM setup is essential.

Step 1: Initial HubSpot SSO Configuration

The SSO configuration process begins inside your HubSpot portal. As a Super Admin, navigate to the settings icon in the top-right corner. From the left sidebar menu, select 'Account Defaults', then click on the 'Security' tab. Here, you will find the 'Single Sign-On (SSO)' section. Click 'Set up' to begin the process. This is the central hub where you will both retrieve information for your IdP and later input information from your IdP.

HubSpot will present you with two crucial values: the 'Audience URI (Service Provider Entity ID)' and the 'Sign on URL, ACS, Recipient, or Redirect'. The Audience URI is a unique identifier for your HubSpot portal's SSO service. The Sign on URL, often called the Assertion Consumer Service (ACS) URL, is the endpoint where your IdP will send the authentication assertion (the 'proof' that the user is who they say they are).

Copy both of these values. You will need to paste them into the corresponding fields during the application setup in your Identity Provider. Keep this browser tab open, as you will return to it later to complete the setup. It is critical that these values are copied exactly, as any typos or extra spaces will cause the connection to fail. This initial step is universal, regardless of which IdP you use. The next steps will diverge based on your specific provider.

Step 2: Configuring Okta for HubSpot SSO

If your organization uses Okta as its IdP, the configuration is straightforward. Log in to your Okta admin dashboard and navigate to 'Applications' > 'Applications'. Click 'Create App Integration' and select 'SAML 2.0' as the sign-on method. On the General Settings page, give the app a name, such as 'HubSpot', and optionally upload a logo for easier identification by your users. Click 'Next' to proceed to the SAML settings.

This is where you will use the values you copied from HubSpot. In the 'Single sign on URL' field, paste the 'Sign on URL, ACS, Recipient, or Redirect' from HubSpot. Check the box for 'Use this for Recipient URL and Destination URL'. In the 'Audience URI (SP Entity ID)' field, paste the 'Audience URI' from HubSpot. Leave the 'Default RelayState' field blank. Below, in the 'Attribute Statements' section, you must map user attributes from Okta to HubSpot. At a minimum, you must map the user's email address. Add a statement where the 'Name' is 'email' and the 'Value' is 'user.email'. You can also map 'firstName' and 'lastName' for a better user experience.

After configuring the SAML settings and attribute statements, click 'Next' and then 'Finish'. Okta will take you to the Sign On tab for the newly created application. Here, you will find the values that HubSpot needs to complete the connection. Click 'View SAML setup instructions'. A new page will open containing the 'Identity Provider Single Sign-On URL', 'Identity Provider Issuer', and the X.509 Certificate. Copy these values; you will paste them back into HubSpot in the final step. For complex user role mapping, consider a consultation on our HubSpot technical SEO services to ensure proper setup.

Okta to HubSpot Attribute Mapping
Okta Attribute NameName formatHubSpot Value
emailUnspecifieduser.email
firstNameUnspecifieduser.firstName
lastNameUnspecifieduser.lastName

Step 3: Configuring Microsoft Entra ID (Azure AD)

For organizations using Microsoft's ecosystem, configuring SSO is done through the Entra ID (formerly Azure Active Directory) portal. Log in to the Microsoft Entra admin center, navigate to 'Identity' > 'Applications' > 'Enterprise applications'. Click on '+ New application', and then on the next screen, click '+ Create your own application'. Give your application a name, like 'HubSpot SSO', and ensure the option 'Integrate any other application you don't find in the gallery (Non-gallery)' is selected. Click 'Create'.

Once the application is created, go to the 'Single sign-on' section from the left-hand menu and select 'SAML'. Here, you will configure the connection using the values from HubSpot. Click the 'Edit' icon in the 'Basic SAML Configuration' section. In the 'Identifier (Entity ID)' field, paste the 'Audience URI' from HubSpot. In the 'Reply URL (Assertion Consumer Service URL)' field, paste the 'Sign on URL, ACS...' from HubSpot. Leave the other fields blank and click 'Save'.

Next, you need to gather the information to provide back to HubSpot. In the 'SAML Signing Certificate' section, find the 'Certificate (Base64)' and click 'Download' to get the certificate file. You will upload this file to HubSpot. Alternatively, you can download the 'Federation Metadata XML' which contains all the required information in one file. HubSpot supports both methods. Also, copy the 'Login URL' and 'Microsoft Entra ID Identifier' from the 'Set up HubSpot SSO' section. You now have everything needed from Entra ID to finalize the setup in HubSpot. Be sure to also assign users or groups to this application within Entra ID to grant them access.

Step 4: Finalizing and Verifying the Connection

With the configuration completed in your IdP, return to the HubSpot SSO setup page you left open. You will now populate the fields under the heading 'Identity Provider'. In the 'Identity Provider Identifier or Issuer URL' field, paste the 'Identity Provider Issuer' from Okta or the 'Microsoft Entra ID Identifier' from Entra ID. In the 'Identity Provider Single Sign-On URL' field, paste the 'Identity Provider Single Sign-On URL' (Okta) or 'Login URL' (Entra ID).

Next, you need to provide the X.509 certificate. You have two options: 'Upload Certificate' or 'Paste Certificate'. If you downloaded the certificate file from your IdP, use the upload option. If you copied the certificate text, paste it into the provided text box, including the '-----BEGIN CERTIFICATE-----' and '-----END CERTIFICATE-----' lines. After filling in these three fields, the 'Verify' button at the bottom of the page will become active.

Click 'Verify'. HubSpot will attempt to initiate an SSO handshake with your IdP. You will be redirected to your IdP's login page in a new window. Log in with your corporate credentials. If the configuration is correct on both ends, the handshake will succeed, and you will see a success message in HubSpot. If it fails, double-check that all URLs and URIs have been copied and pasted correctly, without any extra spaces or typos, and ensure the user you are testing with is assigned to the application in your IdP. For persistent issues, it may be time to contact HubStack for expert help.

Managing Users and Enforcing SSO

Once verification is successful, you have enabled SSO, but you have not yet enforced it. By default, users can still log in with their HubSpot username and password. You can control how SSO is enforced from the HubSpot SSO settings page. The 'Login preferences' section gives you granular control. You can require SSO for all users, all users except Super Admins, or specific users and teams.

It is a strongly recommended best practice to keep at least one Super Admin account exempt from SSO. This provides a 'break-glass' account that can log in with a password if there is ever an issue with your IdP or the SSO configuration itself. This prevents you from being locked out of your own portal. To set this up, select the 'CONTROL SSO PREFERENCE FOR SPECIFIC USERS' option and ensure your emergency admin account is set to 'Password login only'.

Finally, consider Just-in-Time (JIT) provisioning. You can enable this by checking the 'Automatically create users' box in the SSO settings. When a new user in your organization logs into HubSpot via SSO for the first time, JIT will automatically create a user account for them. This automates the onboarding process. However, you must configure their default permissions carefully. In the 'New user defaults' section, you can set the default Hubs, roles, and teams for these auto-created users. A well-planned user permission strategy, often part of our initial HubSpot onboarding and setup services, is crucial for maintaining a secure and organized portal.

FAQ

Questions people actually ask AI about this.

What HubSpot subscription do I need for SSO?

Single Sign-On (SSO) is an enterprise-grade feature. You must have an active subscription to any of HubSpot's Enterprise-level products, such as Marketing Hub Enterprise, Sales Hub Enterprise, or Service Hub Enterprise.

Can I use Google Workspace for HubSpot SSO?

Yes, you can use Google Workspace as your Identity Provider (IdP) for HubSpot SSO. The process involves creating a custom SAML application within your Google Admin console and using the provided URLs and certificate to configure the connection in HubSpot.

What is Just-in-Time (JIT) provisioning?

JIT provisioning automatically creates a user account in HubSpot the first time a person successfully logs in through SSO. This automates user onboarding, but requires careful configuration of default permissions for new users to maintain security.

Will enforcing SSO log out all my current users?

Enforcing SSO does not immediately log out users who are already active. However, the next time they need to log in, they will be required to use SSO. Users who do not have credentials in your IdP will be unable to access HubSpot.

Should I require SSO for all users?

It is a security best practice to require SSO for most users. However, you should always keep at least one Super Admin account configured for password-only login. This acts as a backup account in case your IdP has an outage.

What happens if my Identity Provider has an outage?

If your IdP goes down, users who are required to use SSO will be unable to log in to HubSpot. This is why having a 'break-glass' Super Admin account that uses a password to log in is critically important for portal access during emergencies.

Can I assign different permissions to users logging in via SSO?

Yes. User permissions are managed within HubSpot, not by the SSO connection itself. You can assign specific roles and team memberships to users regardless of how they authenticate. JIT provisioning allows you to set default permissions for auto-created users.

My SSO verification failed. What should I check first?

The most common causes for verification failure are copy-paste errors. Double-check that the Audience URI and Sign on URL in your IdP exactly match what HubSpot provided. Also, ensure the Identity Provider Issuer URL and certificate in HubSpot exactly match what your IdP provided.

Does HubSpot SSO support Multi-Factor Authentication (MFA)?

HubSpot's SSO integration inherits the security policies of your Identity Provider. If you enforce MFA in Okta, Entra ID, or another IdP, users will be required to complete that MFA challenge before being granted access to HubSpot.

Can HubStack set up SSO for my company?

Yes, absolutely. HubStack provides expert technical services, including full SSO configuration and user permission strategy. We can work directly with your IT team to ensure a secure and seamless implementation.

Proof

What this looks like when it's done right.

Secure and Streamline Your HubSpot Access

Related

Technical SEO services

Redirect mapping, metadata baselines, canonical configuration, schema and indexing controls — handled as an ongoing programme rather than a launch-week scramble.

HubSpot technical SEO
Keep reading

How to Set Up HubSpot CRM for a 30-Person Team (Without Overbuilding It)

Most failed CRM rollouts are overbuilt, not underbuilt. Here is the order we configure HubSpot for a 30-person company — and everything we deliberately leave out of version one.

Read article