Overview

Product video
OneLogin by One Identity is a modern, cloud-based access management solution that seamlessly manages all digital identities for your workforce, customers and partners. OneLogin provides secure single sign-on (SSO), multi-factor authentication (MFA) with support for a wide array of passwordless authentication factors, adaptive authentication, desktop-level MFA, directory integration with AD, LDAP, G Suite and other external directories, identity lifecycle management and much more.
OneLogin uses powerful authentication and role-based user provisioning engine enabling you to implement least-privileged access controls and eliminate manual user management workflows. Moreover, OneLogin delivers multi-layer, context aware and risk-based protection, minimizing the most common attacks and resulting in increased security, frictionless user experiences, and compliance with regulatory requirements.
OneLogin has pre-built authentication connectors with thousands of third-party web applications with extensibility across your entire portfolio. With OneLogin, you can:
-Implement single sign-on (SSO) for users across mobile, web and desktop
-Enforce contextual multi-factor authentication (MFA) and access security policies, and automate user account provisioning
-Provision users with granular access permissions into the AWS Console/CLI or directly to AWS services
-Extend security controls across your cloud infrastructure by leveraging pre-built integrations with Amazon Control Tower, AWS IAM, AWS SSO, Amazon Cognito, and Amazon EventBridge
If interested in private offers, email us at partnercircle@oneidentity.com .
Highlights
- SSO: Automatically sync users across multiple directories in minutes to enable one-click access to all corporate applications, whether on-prem or in the cloud, and enforce strong security policies, plus self-service password reset.
- MULTI-FACTOR AUTHENTICATION (MFA): Supports many authentication methods, including passwordless, passkeys, one-time passcodes, push notifications, biometric data, security keys and more. With real-time reporting and monitoring capabilities, gain insights into authentication events, enabling proactive detection and response to potential security incidents.
- ADVANCED DIRECTORY: Acts as your secure directory in the cloud with an intuitive web-based interface that allows you to manage users, their manager relationship, authentication policies and access controls.
Details
Introducing multi-product solutions
You can now purchase comprehensive solutions tailored to use cases and industries.
Features and programs
Buyer guide

Financing for AWS Marketplace purchases
Pricing
Free trial
Dimension | Description | Cost/12 months |
|---|---|---|
OneLogin 1-App Plan | Standard User License, OneLogin 1-App Plan for AWS | $12.00 |
OneLogin Advanced Plan | Standard User License, OneLogin Advanced Plan | $48.00 |
OneLogin Professional Plan | Standard User License, OneLogin Professional Plan | $96.00 |
Custom | Private offers available - email partners@onelogin.com | $96.00 |
Vendor refund policy
Please refer to OneLogin terms of service https://www.onelogin.com/terms
How can we make this page better?
Legal
Vendor terms and conditions
Content disclaimer
Delivery details
Software as a Service (SaaS)
SaaS delivers cloud-based software applications directly to customers over the internet. You can access these applications through a subscription model. You will pay recurring monthly usage fees through your AWS bill, while AWS handles deployment and infrastructure management, ensuring scalability, reliability, and seamless integration with other AWS services.
Support
Vendor support
To learn more about OneLogin Customer Support, visit
AWS infrastructure support
AWS Support is a one-on-one, fast-response support channel that is staffed 24x7x365 with experienced and technical support engineers. The service helps customers of all sizes and technical abilities to successfully utilize the products and features provided by Amazon Web Services.

Standard contract
Customer reviews
Centralized access has streamlined onboarding and strengthened authentication for all users
What is our primary use case?
OneLogin by One Identity is primarily used for identity and access management, with a focus on SSO and MFA. This allows users to access necessary applications through a centralized login rather than maintaining separate credentials for each application. Whether an employee needs access to Microsoft 365, Salesforce, or internal business applications, those apps are integrated with OneLogin by One Identity. Users log in once through the platform, complete MFA if necessary, and access applications they are authorized to use.
OneLogin by One Identity is also leveraged during onboarding and offboarding processes. New hires gain access based on their roles, and when someone leaves, their access is disabled centrally rather than relying on individual application teams to remove accounts.
What is most valuable?
OneLogin by One Identity's standout features are SSO and MFA, making the login process simpler for users and more secure. Centralized user and access management allows the IT team to manage multiple application access from one place. The reporting and user activity visibility is beneficial for troubleshooting access issues or reviewing security. Automation for onboarding and offboarding is crucial in large organizations as manual access management across applications is difficult. Integration with existing environments adds value, yet challenges still arise with legacy applications and varied authentication requirements.
What needs improvement?
Improving the integration of legacy applications would reduce manual work during implementation. Enhanced automation around access reviews and role changes could aid management as user applications grow. Additionally, simplifying the authentication process, particularly when using multiple devices, would improve user experience. Better automation could enhance access review and role change processes. OneLogin by One Identity is strong for modern applications, but making legacy integration easier would enhance its utility in enterprise environments.
For how long have I used the solution?
I have been using OneLogin by One Identity for around two years.
What do I think about the stability of the solution?
OneLogin by One Identity has been stable overall. I have not experienced major downtime that significantly affected users. Occasionally, there are authentication issues or short service interruptions, but they have not impacted significantly. However, since authentication is centralized, maintaining availability is crucial as service disruptions can affect access to multiple applications.
What do I think about the scalability of the solution?
OneLogin by One Identity scales well due to its cloud-based nature, allowing the organization to onboard new users and integrate additional applications without expanding IAM infrastructure. The challenge is not the number of users, but the environment's complexity. Adding applications can complicate integration and access policies, particularly with legacy or custom applications.
How are customer service and support?
My experience with OneLogin by One Identity's customer support has been positive, rating it eight out of ten. During the implementation, the support was highly effective and deserving of a ten out of ten from my perspective.
How was the initial setup?
The setup for OneLogin by One Identity was straightforward, but understanding the license's scope was crucial for assessing total implementation. Integrating with existing applications and directories was essential, as was considering the total cost beyond just licensing. Professional services, customization, and legacy application integration come with extra effort.
What was our ROI?
OneLogin by One Identity brings ROI by reducing manual work involved in user access management, rather than direct cost savings. Streamlined onboarding and centralized provisioning based on user roles save time. Central access disabling during offboarding minimizes the chance of leaving access active in applications. I have not formally measured a specific percentage, but I have observed less repetitive admin work, fewer manual steps, and easier troubleshooting of authentication issues.
What's my experience with pricing, setup cost, and licensing?
The pricing and licensing for OneLogin by One Identity were straightforward. The cost depends on the number of users, features required, and level of functionality. While the initial setup cost was not a major concern, I ensured I understood the licensing scope and potential extra requirements. Integration with existing applications and directories was crucial to consider for total costs.
Which other solutions did I evaluate?
I considered alternatives such as Microsoft Entra ID, Okta, and Ping Identity, evaluating factors including SSO and MFA capability, application integration, user provisioning, security controls, ease of admin, and licensing. My focus was not on feature count, but on which product best fits within the existing environment.
What other advice do I have?
Before implementing, assess organizational requirements instead of choosing OneLogin by One Identity based solely on features. Conduct a thorough review of applications, directories, and authentication processes. Test with crucial applications first to refine the user experience, then expand gradually.
Understand the licensing scope and integration effort needed, including with legacy systems, to have a complete view of the total cost of ownership.
When relying on AI capabilities, ensure they are governed carefully due to the sensitive nature of identity data, emphasizing human review in security decisions. Utilize AI as a support tool to identify risky behaviors but maintain human oversight.
Risk-based and adaptive authentication approaches enhance security without overwhelming users with unnecessary prompts. Strike the right balance in risk settings and review false positives for a smooth user experience.
I give OneLogin by One Identity an overall rating of eight out of ten.
Single sign-on has simplified access to cloud apps and reduced password reset workload
What is our primary use case?
The main use case for OneLogin by One Identity when I was using it at IQ was having one single user ID and one single password that gave me access to applications that were assigned to my profile.
Any cloud application is a use case for OneLogin by One Identity. Let me take the example of Salesforce. Salesforce uses your email as your user ID to log in, and sometimes your email has been used for another Salesforce instance, another Salesforce application, or another one you've used at a different company. Using OneLogin by One Identity, it had the SAML page that connected with Salesforce. OneLogin by One Identity had my user ID and password that was synced with Active Directory. If Salesforce was an assigned application, it would appear in my OneLogin by One Identity screen once I logged in, and I could just launch the application.
What is most valuable?
Based on my experience, some of the best features OneLogin by One Identity offers include built-in SAML pages that can be utilized by most cloud application providers. It also allows for a second login option directly to the SaaS application if you're using external contractors. OneLogin by One Identity didn't restrict that privilege, especially for support organizations, where you had an offshore support organization that needed one-time access to the application. You don't need to give them OneLogin by One Identity licenses or Active Directory accounts. You could have them use user ID and password to connect while your employees used OneLogin by One Identity. OneLogin by One Identity provided that additional security, which an application user ID and password could not provide. OneLogin by One Identity enforced multi-factor authentication, which wasn't enforced in many cloud applications.
OneLogin by One Identity has positively impacted my organization in that one big benefit was onboarding and offboarding. From an onboarding perspective, it was easier to train the user to have just one application to log into, which was OneLogin by One Identity. Offboarding was amazing. When a person left, I didn't have to search which applications they had access to. Once their Active Directory account was disabled and OneLogin by One Identity was disabled, they had access to none of the company's confidential applications and data.
What needs improvement?
The multi-factor authentication did improve security. In terms of productivity, initially it was a challenge. People were not used to getting SMS messages on their phones, especially if it's not a company provided phone. Some people even complained that they didn't want to use their phone to get work-related SMS messages even if it's multi-factor authentication. It didn't provide smoothness or ease in operations to begin with. Eventually, it helped because users did not have to remember so many user IDs and passwords. It was only one user ID and password for OneLogin by One Identity. So we had fewer trouble tickets and service requests and challenges with password resets and other issues. Eventually, user satisfaction was improved.
The only thing I find confusing, regardless of OneLogin by One Identity or other applications, is the reliance on Microsoft Authenticator and there are too many MFA applications. If OneLogin by One Identity could centralize and have one application such as Microsoft Authenticator or any other application, even if it was a biometric that supported OneLogin by One Identity multi-factor authentication, that would help because it's sometimes difficult having so many MFA authenticator applications to manage.
For how long have I used the solution?
I have been working in my current field for probably thirty years.
What do I think about the stability of the solution?
OneLogin by One Identity is stable.
What do I think about the scalability of the solution?
We scaled OneLogin by One Identity globally, so it is very scalable.
How are customer service and support?
There is room for improvement regarding customer support for OneLogin by One Identity.
Which solution did I use previously and why did I switch?
We didn't have an IAM solution before using OneLogin by One Identity.
How was the initial setup?
OneLogin by One Identity was initially deployed on-premises and then we moved it to a private cloud.
What about the implementation team?
We used AWS for our private cloud deployment of OneLogin by One Identity.
What was our ROI?
I can definitely mention that I don't have the metrics, but I can share that from a service desk perspective, the number of password reset calls reduced. As the calls reduced for password resets, which was the highest number of calls before OneLogin by One Identity, we could optimize our service desk employees and repurpose the ones that were needed for project work.
What's my experience with pricing, setup cost, and licensing?
I did not purchase OneLogin by One Identity through the AWS Marketplace. It was directly through a OneLogin by One Identity reseller or through the direct company, but not through the marketplace.
Which other solutions did I evaluate?
Before choosing OneLogin by One Identity, Okta was the only option we looked at.
What other advice do I have?
I would ask anyone looking into using OneLogin by One Identity to take a phased approach, either going by region in a multi-company organization or by company because sometimes you have small integration issues to resolve, especially with cloud applications and rules. Make sure that you resolve that with a smaller impacted population rather than implementing something globally in a large scale and then having bigger problems to deal with.
I rate OneLogin by One Identity a nine on a scale of one to ten. I choose nine for my rating of OneLogin by One Identity because I believe even the best of us have an opportunity to improve. We can never be a ten, or we should not be a ten. We should always aspire to improve.
Regarding OneLogin by One Identity's AI capabilities, my impression of its governance and security is excellent. My impression of its accuracy and reliability of output is also excellent.
We reviewed SmartFactor Authentication for OneLogin by One Identity, but had not implemented it while I was at IQ.
My impression of the User Identity Synchronization across directories functionality in OneLogin by One Identity is that it is very strong, actually in most single sign-on providers.
The integration of phishing-resistant device trust on my authentication processes is that I don't want to mix the two together. OneLogin by One Identity is, to me, a case where phishing should be managed through other services rather than OneLogin by One Identity. OneLogin by One Identity is, in my mind, an identity and access management solution. It's not an email security management solution.
From a user perspective, with the right amount of training and documentation, OneLogin by One Identity provides a very seamless end-user experience for signing in and authenticating to needed applications. They're simply logging into an application like Citrix in the good old days, and once you get into the MetaFrame, you launch your app. OneLogin by One Identity is the same. Once you log into OneLogin by One Identity, you have all your apps in a single form or single page.
I wasn't involved in the decision-making for pricing, setup cost, and licensing for OneLogin by One Identity.
Which deployment model are you using for this solution?
If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?
Centralized access has transformed onboarding, cut manual work, and improves everyday security
What is our primary use case?
OneLogin by One Identity is used for centralized identity and access management for employees, allowing secure access to multiple work applications through a single identity instead of managing separate credentials. It utilizes automated provisioning and de-provisioning, enabling prompt access assignment based on roles when new employees join, and the removal of access when they leave. This goes beyond SSO and MFA, as access policies are enforced based on role and user context, with updates occurring automatically when someone changes departments. OneLogin by One Identity supports role and attribute-based provisioning for entitlement management, and integrates features like smart factor authentication for high-risk login attempts.
How has it helped my organization?
One of the biggest positive impacts of OneLogin by One Identity has been the reduction of administrative workload while improving security through automated provisioning for new employees and removing access during offboarding. It minimizes the manual work involved in accessing individual applications with automated lifecycle management, which handles central login itself. The onboarding and offboarding processes have transitioned from hours to minutes. We have seen a thirty to forty percent reduction in onboarding and provisioning times as application access is assigned automatically based on roles instead of being configured manually.
Additionally, there has been a fifty percent reduction in password and access-related help desk tickets thanks to SSO and self-service password reset features. Positive results come mainly from automation in user provisioning and de-provisioning, paired with improved MFA and risk-based authentication collectively lowering the risk of unauthorized access.
What is most valuable?
OneLogin by One Identity offers valuable features such as single sign-on, multi-factor authentication, identity lifecycle management, and smart factor authentication, centralizing access to both cloud and on-premise applications. It supports role and attribute-based provisioning for entitlement management, offers real-time directory synchronization, and adaptive login flows with Vigilance AI. Additionally, its Smart Factor Authentication feature effectively balances security and usability, enhancing the authentication process by requiring stronger verification in case of unusual login behavior. The integration of phishing-resistant device trust significantly impacts authentication processes, adding another layer of security beyond verifying users' credentials.
A specific area in the valuable features is the automated provisioning and de-provisioning processes that reduce the risk of someone retaining access they no longer need. The lifecycle management feature automates these processes, making day-to-day access much easier to manage. OneLogin by One Identity helps in maintaining the directory infrastructure while centralizing SSO, MFA, and identity lifecycle management for both on-premise and cloud infrastructures. Additionally, it provides a seamless end-user experience by granting access through a single login, thereby reducing password-related support requests.
What needs improvement?
Reporting and analytics in OneLogin by One Identity can be improved, as filtering and customization options for more complex requests are limited. It does not support document exportation or sufficiently modify standard reports to relate to specific applications and administration data. There is also a need for further expansion of native integrations and automation operations. Greater coverage in the API for programmatically managing configuration and broader flexibility in dashboards would significantly enhance administrative experiences.
Enhancements in provisioning diagnostics, reporting flexibility, and simpler troubleshooting for complex integrations would greatly improve the administrative experience.
For how long have I used the solution?
I have been using OneLogin by One Identity for about two years.
What do I think about the stability of the solution?
OneLogin by One Identity is quite stable from my point of view, as I have been using it for a while and have found it to be very reliable in our overall day-to-day operations. The MFA and directory synchronization features remain dependable, and we have not experienced any major outages impacting significant user activity. I rate its stability at ten out of ten.
What do I think about the scalability of the solution?
OneLogin by One Identity demonstrates excellent scalability. We have been able to add more users, applications, and access policies without needing to revise our identity architecture significantly. My experience with scalability has been favorable; I rate it as really good, at nine out of ten, given its effectiveness in managing resources, authentication, and related processes like MFA, SSO, onboarding, and offboarding.
How are customer service and support?
Customer support for OneLogin by One Identity has been exceptional. We reached out to OneLogin by One Identity support several times, primarily for directory synchronization, provisioning, and application integration issues, and our overall experience has been very positive. The engineers we interacted with demonstrated technical expertise and aimed to identify root causes rather than merely providing generic troubleshooting steps. Their support portals and knowledge base are valuable resources, allowing many common configuration issues to be addressed without opening a ticket. One Identity provides multiple support tiers, including critical twenty-four seven coverage for issues, depending on the chosen support plan.
I rate customer support at a solid nine out of ten, as they have been responsive and highly knowledgeable, especially when I needed help with specific synchronization, provisioning, and application integration concerns. Their availability for twenty-four seven support is also something I appreciate, contributing to my high rating.
Which solution did I use previously and why did I switch?
We previously used Microsoft Entra ID, formerly Azure Active Directory, for many of our identity and authentication needs, alongside various manual processes for application access. We evaluated OneLogin by One Identity because we wanted a more flexible, natural identity platform featuring straightforward SSO, MFA, directory integration, and automated provisioning for onboarding.
How was the initial setup?
The initial deployment was relatively straightforward, particularly for basic SSO and MFA functionalities, though integrating and configuring more advanced provisioning policies required some additional planning.
What was our ROI?
We have seen a return on investment. The onboarding and offboarding processes have reduced costs by around ten to twenty percent. Time savings are notable as onboarding and offboarding durations have decreased by up to forty percent. Positive results come mainly from automation in user provisioning and de-provisioning, paired with a roughly fifty percent reduction in password-related help desk requests.
Additionally, while security ROI is harder to quantify, faster onboarding processes, effective MFA, and risk-based authentication collectively lower the risk of unauthorized access. In summary, the combining time savings, reduced support loads, and enhanced security truly validate the licensing cost.
What's my experience with pricing, setup cost, and licensing?
Our experience regarding pricing, setup cost, and licensing for OneLogin by One Identity has been generally positive, though it is not the cheapest identity management solution, especially as the number of users increases. However, the cost is justified by the significant reduction in manual administrative tasks, fewer password-related support requests, faster onboarding and offboarding times, and improved access security.
Which other solutions did I evaluate?
Before choosing OneLogin by One Identity, we also evaluated Okta, Microsoft Entra ID, and Ping Identity. These were our primary alternatives as they offer comparably robust capabilities surrounding SSO, MFA, and identity management. Ultimately, we chose OneLogin by One Identity because it provided the right balance of functionality, ease of administration, integration with hybrid directories, and cost aligned with our requirements without adding unnecessary complexities.
What other advice do I have?
My advice for others considering OneLogin by One Identity is to plan the implementation carefully before rolling it out company-wide. Identify critical applications and define roles and access policies, and determine how your directories will serve as the source of truth. It is also wise to execute the rollout in phases, starting with a small group of users. Investing time in the initial configuration will allow OneLogin by One Identity to significantly simplify identity management while providing a smoother and more secure authentication experience for users.
Regarding user identity synchronization functionality, my impression is very positive. It has been extremely beneficial in our hybrid environment. OneLogin by One Identity directly synchronizes identity information, providing a consistent way to manage it between our on-premise Active Directory and cloud applications. The main advantage is that when users are added, updated, disabled, or moved to different groups in the directory, those changes can automatically flow through OneLogin by One Identity to connected applications without requiring IT teams to update each system manually. It has made onboarding and offboarding processes more straightforward and effective, ensuring user access remains aligned across both on-premise and cloud environments.
I give this review an overall rating of ten out of ten.
Modern identity access has streamlined onboarding and strengthened secure workforce authentication
What is our primary use case?
My main use case for OneLogin by One Identity involves single sign-on and multi-factor authentication.
A specific example of how I use single sign-on and multi-factor authentication with OneLogin by One Identity includes during user onboarding, user offboarding, role-based access control, and identity lifecycle management.
What is most valuable?
The best features OneLogin by One Identity offers include advanced directory integration, single sign-on integration, integration with LDAP and Active Directory, as well as Workday.
Out of those features, the LDAP integration and Active Directory stand out the most for me because they really made a difference.
OneLogin by One Identity has positively impacted my organization by cutting implementation time by fifty to eighty percent and decreasing the workforce required to implement it by fifty percent.
What needs improvement?
OneLogin by One Identity can be improved by addressing the responsiveness time for requests, which is a bit slow, as well as the limited API limitation.
For how long have I used the solution?
I have been working in my current field for over five years.
What do I think about the stability of the solution?
OneLogin by One Identity is stable, and I find it to be a pretty stable solution.
What do I think about the scalability of the solution?
OneLogin by One Identity has very good scalability and is a very scalable solution.
How are customer service and support?
The customer support is very quick and overall pretty good.
I would rate the customer support on a scale of one to ten as a nine.
Which solution did I use previously and why did I switch?
I have not previously used a different solution.
Before choosing OneLogin by One Identity, I evaluated other options such as Okta.
What was our ROI?
I have seen a return on investment, with a fifty percent cost save and fifty to eighty percent fewer people required in terms of implementation.
What's my experience with pricing, setup cost, and licensing?
I find that in terms of pricing, setup cost, and licensing, it is very suitable for medium to large organizations, making it very cost-effective.
What other advice do I have?
Regarding OneLogin by One Identity's AI capabilities, I think its governance and security make it a pretty secure solution with a lot of integration, so it is a very good solution overall.
Regarding OneLogin by One Identity's AI capabilities, I find it to be pretty accurate in terms of the features available.
I do not use the solution's Smart Factor Authentication to adjust authentication flows in real-time depending on the risk score associated with the login attempt.
My impression of the user identity synchronization across directories functionality is that it is secure, has secure access to resources such as data and applications, as well as fast access with easy authentication.
The integration of phishing-resistant device trust has positively impacted my authentication processes by reducing risk and helping users effectively in terms of awareness about who has access to the system and how it is maintained.
I have not used the adaptive login flows with Vigilance AI.
My advice to others looking into using OneLogin by One Identity is to consider this solution because it is quite scalable and has a lot of integration, as well as good monitoring capabilities and session recording, making it well-designed and a good product overall.
I would rate this review an eight out of ten.
Which deployment model are you using for this solution?
If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?
Privileged access has been centralized and automation reduces audit and onboarding effort
What is our primary use case?
OneLogin by One Identity is being used as a PAM solution managing approximately 20,000 machines, with 60% being VMs and 40% being cloud-based access management. OneLogin by One Identity is also used for monitoring purposes with two devices deployed: one for session management and another for security management. Both devices provide strong privileged access management capability, including password vaulting, session monitoring, session recording, and session access for all users accessing the system. Reports can be generated whenever required.
An extra server takes backups from the sessions, and sessions that are not stored in OneLogin by One Identity are stored locally as history when long-term retention is needed. The integration of phishing-resistant device trust through OneLogin by One Identity has positively impacted authentication processes by helping identify phishing users effectively since awareness of who will access the system is maintained.
What is most valuable?
The standout features of OneLogin by One Identity include session monitoring, which provides access for the last year to see who accessed the system, what happened, and what commands they ran. If something happens with a Linux machine, potential attacks or issues can be investigated. For network-wide issues, monitoring and session recording can be reviewed and compared. A comprehensive audit trail can be generated and the kind of compliance desired on security investigations can be applied. Automated password rotation and role-based access are supported. For cloud monitoring, SCIM provisioning is used, and the system is authenticated through Azure, now Entra, by role-based access.
What needs improvement?
For large enterprise organizations that are also vendors for clients with differing requirements, all built-in features are considered, but sometimes new features based on client requirements need to be inbuilt. Customizing OneLogin by One Identity could be improved with processes to implement new features quickly without having to wait for months. For example, token-based access was needed, and implementing token-based or SCIM provisioning features took time. Reducing the time window for implementing custom solutions would enhance the product.
Documentation-wise, OneLogin by One Identity is one of the best found for any product, so there are no concerns there. Support-wise, OneLogin by One Identity is doing a great job. Support and management, including contacting OneLogin by One Identity for issues, are always straightforward.
For how long have I used the solution?
OneLogin by One Identity has been in use for the last four years with no concerns.
What do I think about the stability of the solution?
OneLogin by One Identity is very stable. Whenever problems are encountered, quick responses are received from OneLogin by One Identity's support team.
What do I think about the scalability of the solution?
Regarding scalability, if more resources are needed to manage clients and machines, resources can be easily scaled. The black box machine can be attached as required; currently, five are used for session management and five for password rotation. As many as needed can be added depending on the resources required to support the cluster. Scaling is very easy and can be done at any time.
How are customer service and support?
OneLogin by One Identity's support team is doing a great job, which is why the product has been used for the last four and a half years. Support and management, including contacting OneLogin by One Identity for issues, are always straightforward. Whenever problems are encountered, quick responses are received from OneLogin by One Identity's support team.
Which solution did I use previously and why did I switch?
CyberArk was previously used before switching to OneLogin by One Identity. After conversations with both sales teams, the sales pitch of OneLogin by One Identity stood out compared to CyberArk. OneLogin by One Identity was found to be a better solution in cost and resource management, which is why the switch was made.
How was the initial setup?
OneLogin by One Identity was deployed four years ago and is continuously being used with no issues. Currently, over 20,000 VMs and cloud environments are managed by OneLogin by One Identity. A cluster-based deployment is used, geo-redundant across three sites. It took one and a half months to build the lab environment. Once all problems and requirements for the environment setup were identified, the production deployment took around one month.
Since OneLogin by One Identity was implemented, a transition occurred from the old version, which was the TPAM solution. OneLogin by One Identity acquired that particular solution, and the transition was made to OneLogin by One Identity access management. This transition gave the capability to monitor, conduct comprehensive audits, and manage all resources easily whenever needed. Access control for admin personnel is very easy, and access can be managed. Whenever a system is required to be removed from the sync or out of the cluster, it is straightforward to remove from OneLogin by One Identity's Safeguard. The earlier PAM solution was quite difficult to set up, and this one has API Swagger development, making it easy to communicate. Whenever audits are needed, the REST API can be called, which is the biggest advantage.
What about the implementation team?
Once all problems and requirements for the environment setup were identified, the production deployment took around one month. In terms of return on investment, significant savings are being made. After implementation, fewer engineers in the team were needed to manage OneLogin by One Identity. Onboarding is automated, so there is no need to worry about the onboarding process, and using REST API calls for access management simplifies automation.
What was our ROI?
Significant savings are being made in terms of return on investment. After implementation, fewer engineers in the team were needed to manage OneLogin by One Identity. Onboarding is automated, so there is no need to worry about the onboarding process, and using REST API calls for access management simplifies automation. OneLogin by One Identity's Safeguard detailed Swagger build is quite helpful. Implementation time has been cut by 60 to 70%, and the number of people required for management has decreased by at least 60 to 70%. Once architecture is defined and deployed in the cluster, scaling becomes easy, and integration is straightforward for adding new systems.
What's my experience with pricing, setup cost, and licensing?
Regarding pricing, setup costs, and licensing, the virtual licensing option is suitable for small or midsize organizations. The black box developed by OneLogin by One Identity is not costly concerning the security features being provided.
Which other solutions did I evaluate?
Multiple options were evaluated before choosing OneLogin by One Identity, with CyberArk being one of them.
What other advice do I have?
My advice for others considering OneLogin by One Identity is that if a solution is needed that can scale easily in the future and currently does not manage many users and machines, OneLogin by One Identity can be chosen. If monitoring capabilities and session recording are needed, OneLogin by One Identity is one of the best solutions to recommend based on experience.
OneLogin by One Identity is a well-designed and impressive product. Even with the new AI features, it will change how security is implemented with policies, offering admins options to implement changes. If new features are needed, OneLogin by One Identity's Safeguard is always ready to help with implementation and provide those solutions. As a user, the user identity synchronization across directories functionality is really valuable to have.
The AI features in OneLogin by One Identity are new, so many components have not been implemented yet. Just started looking into the agent and its available AI functionality, so it cannot be fully assessed at this time. However, given the way the product is built and its architecture, it should be 100% useful for users.
The overall review rating for OneLogin by One Identity is ten out of ten.