ZTCA Configuration: Restrict HubSpot sign-ins to trusted IPs using Entra Conditional Access
ID: 9cfa76d3-aab3-5506-ba05-74eb164c5f93
STIX ID: report--9cfa76d3-aab3-5506-ba05-74eb164c5f93
Feed Name: ThreatLocker Blog
This operational guide explains step-by-step how to configure Microsoft Entra ID Named Locations and a Conditional Access policy to restrict HubSpot sign-ins to approved static IP addresses, covering prerequisites (HubSpot Enterprise SAML SSO, Require SSO enabled), policy creation (targeting HubSpot, excluding trusted locations, blocking access), validation in Report-only mode using sign-in logs and the What If tool, and safe enablement guidance to avoid locking out users. It also highlights limitations of IP-based restrictions and recommends layering with additional controls like MFA and Zero Trust.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
