Listing Thumbnail

    OneLogin Workforce Identity

     Info
    Free Trial
    AWS Free Tier
    Elevate organizational security with strong and adaptive authentication, preventing unauthorized access to your most critical systems, applications and sensitive data.
    4.2

    Overview

    Play video

    OneLogin by One Identity is a modern, cloud-based access management solution that seamlessly manages all digital identities for your workforce, customers and partners. OneLogin provides secure single sign-on (SSO), multi-factor authentication (MFA) with support for a wide array of passwordless authentication factors, adaptive authentication, desktop-level MFA, directory integration with AD, LDAP, G Suite and other external directories, identity lifecycle management and much more.

    OneLogin uses powerful authentication and role-based user provisioning engine enabling you to implement least-privileged access controls and eliminate manual user management workflows. Moreover, OneLogin delivers multi-layer, context aware and risk-based protection, minimizing the most common attacks and resulting in increased security, frictionless user experiences, and compliance with regulatory requirements.

    OneLogin has pre-built authentication connectors with thousands of third-party web applications with extensibility across your entire portfolio. With OneLogin, you can:

    -Implement single sign-on (SSO) for users across mobile, web and desktop

    -Enforce contextual multi-factor authentication (MFA) and access security policies, and automate user account provisioning

    -Provision users with granular access permissions into the AWS Console/CLI or directly to AWS services

    -Extend security controls across your cloud infrastructure by leveraging pre-built integrations with Amazon Control Tower, AWS IAM, AWS SSO, Amazon Cognito, and Amazon EventBridge

    If interested in private offers, email us at partnercircle@oneidentity.com .

    Highlights

    • SSO: Automatically sync users across multiple directories in minutes to enable one-click access to all corporate applications, whether on-prem or in the cloud, and enforce strong security policies, plus self-service password reset.
    • MULTI-FACTOR AUTHENTICATION (MFA): Supports many authentication methods, including passwordless, passkeys, one-time passcodes, push notifications, biometric data, security keys and more. With real-time reporting and monitoring capabilities, gain insights into authentication events, enabling proactive detection and response to potential security incidents.
    • ADVANCED DIRECTORY: Acts as your secure directory in the cloud with an intuitive web-based interface that allows you to manage users, their manager relationship, authentication policies and access controls.

    Details

    Delivery method

    Deployed on AWS
    New

    Introducing multi-product solutions

    You can now purchase comprehensive solutions tailored to use cases and industries.

    Multi-product solutions

    Features and programs

    Buyer guide

    Gain valuable insights from real users who purchased this product, powered by PeerSpot.
    Buyer guide

    Financing for AWS Marketplace purchases

    AWS Marketplace now accepts line of credit payments through the PNC Vendor Finance program. This program is available to select AWS customers in the US, excluding NV, NC, ND, TN, & VT.
    Financing for AWS Marketplace purchases

    Pricing

    Free trial

    Try this product free according to the free trial terms set by the vendor.

    OneLogin Workforce Identity

     Info
    Pricing is based on the duration and terms of your contract with the vendor. This entitles you to a specified quantity of use for the contract duration. If you choose not to renew or replace your contract before it ends, access to these entitlements will expire.
    Additional AWS infrastructure costs may apply. Use the AWS Pricing Calculator  to estimate your infrastructure costs.

    12-month contract (4)

     Info
    Dimension
    Description
    Cost/12 months
    OneLogin 1-App Plan
    Standard User License, OneLogin 1-App Plan for AWS
    $12.00
    OneLogin Advanced Plan
    Standard User License, OneLogin Advanced Plan
    $48.00
    OneLogin Professional Plan
    Standard User License, OneLogin Professional Plan
    $96.00
    Custom
    Private offers available - email partners@onelogin.com
    $96.00

    Vendor refund policy

    Please refer to OneLogin terms of service https://www.onelogin.com/terms 

    How can we make this page better?

    Tell us how we can improve this page, or report an issue with this product.
    Tell us how we can improve this page, or report an issue with this product.

    Legal

    Vendor terms and conditions

    Upon subscribing to this product, you must acknowledge and agree to the terms and conditions outlined in the vendor's End User License Agreement (EULA) .

    Content disclaimer

    Vendors are responsible for their product descriptions and other product content. AWS does not warrant that vendors' product descriptions or other product content are accurate, complete, reliable, current, or error-free.

    Usage information

     Info

    Delivery details

    Software as a Service (SaaS)

    SaaS delivers cloud-based software applications directly to customers over the internet. You can access these applications through a subscription model. You will pay recurring monthly usage fees through your AWS bill, while AWS handles deployment and infrastructure management, ensuring scalability, reliability, and seamless integration with other AWS services.

    Support

    Vendor support

    To learn more about OneLogin Customer Support, visit

    AWS infrastructure support

    AWS Support is a one-on-one, fast-response support channel that is staffed 24x7x365 with experienced and technical support engineers. The service helps customers of all sizes and technical abilities to successfully utilize the products and features provided by Amazon Web Services.

    Product comparison

     Info
    Updated weekly
    By JumpCloud, Inc.

    Accolades

     Info
    Top
    100
    In Applications
    Top
    10
    In Application Servers
    Top
    100
    In Security

    Customer reviews

     Info
    Sentiment is AI generated from actual customer reviews on AWS and G2
    Reviews
    Functionality
    Ease of use
    Customer service
    Cost effectiveness
    Positive reviews
    Mixed reviews
    Negative reviews

    Overview

     Info
    AI generated from product descriptions
    Single Sign-On (SSO)
    Automatically synchronizes users across multiple directories to enable one-click access to corporate applications on-premises and in the cloud with enforced security policies and self-service password reset capabilities.
    Multi-Factor Authentication (MFA)
    Supports multiple authentication methods including passwordless authentication, passkeys, one-time passcodes, push notifications, biometric data, and security keys with real-time reporting and monitoring of authentication events.
    Adaptive Authentication
    Delivers multi-layer, context-aware and risk-based protection to minimize common attacks and enforce contextual access security policies based on user behavior and risk assessment.
    Identity Lifecycle Management
    Provides role-based user provisioning engine with granular access permissions, least-privileged access controls, and automated user account provisioning across applications and AWS services.
    Directory Integration
    Acts as a secure cloud-based directory with integration capabilities for Active Directory, LDAP, G Suite and other external directories, plus pre-built connectors with thousands of third-party web applications and AWS services including AWS IAM, AWS SSO, Amazon Cognito, and Amazon EventBridge.
    Cloud Directory Identity Management
    Centralize access across all identities with integrations to AWS Identity Center, Google Workspace, Microsoft 365, Active Directory, HRIS platforms, and network infrastructure resources
    Single Sign-On and Multi-Factor Authentication
    Frictionless, secure access to AWS resources and over 900 pre-built applications with automated user provisioning to Amazon IAM Identity Center and group-based permissions
    Cross-Operating System Server and Device Management
    Deploy, manage, and remotely assist AWS servers and corporate devices across Windows, macOS, iOS, Linux, AWS Linux AMIs, and Android from a single cloud platform
    Passwordless and Conditional Access
    Enable phishing-resistant access with passwordless SSO, password management, and conditional access controls to ensure only specific users on trusted devices and networks can access AWS resources
    Unified Platform with Zero Trust Capabilities
    Combine cloud directory identity management, access management, and cross-OS server and device management with enhanced IAM and device management controls to support Zero Trust security goals
    Single Sign-On Capability
    Enables one-click secure access to applications and resources including AWS IAM and AWS SSO
    Adaptive Multi-Factor Authentication
    Supports context and risk-aware authentication methods with passwordless user experience options
    Web Session Security and Monitoring
    Protects identities beyond login and provides visibility into user actions within web applications
    Identity Lifecycle Management and Automation
    Automates identity lifecycle events, orchestrates identity workflows, and streamlines access reviews and compliance requirements
    Cloud Directory and User Management
    Leverages scalable cloud directory to unify user management across enterprise and reduce identity silos

    Contract

     Info
    Standard contract
    No
    No
    No

    Customer reviews

    Ratings and reviews

     Info
    4.2
    89 ratings
    5 star
    4 star
    3 star
    2 star
    1 star
    51%
    48%
    0%
    1%
    0%
    39 AWS reviews
    |
    50 external reviews
    External reviews are from G2  and PeerSpot .
    Satyam Gupta

    Centralized identity has reduced manual access work and now automates secure user lifecycle management

    Reviewed on May 30, 2026
    Review provided by PeerSpot

    What is our primary use case?

    My main use case for OneLogin  is that we use this solution as our centralized identity provider to maintain and manage authentication, authorization, and secure access to both cloud and on-premises applications.

    What is most valuable?

    OneLogin  offers several best features such as federated single sign-on, risk-based authentication, automated user provisioning, and the most important, centralized access governance.

    I mostly rely on automated user lifecycle management within OneLogin, as it automatically provisions and de-provisions users' accounts, helping our nation improve security and reduce the manual work of the administrator.

    OneLogin has positively impacted my organization in several ways, as it has really improved both security and user productivity, allowing employees to securely access multiple applications with the help of single sign-on, which has significantly reduced password-related issues.

    The outcomes since adopting OneLogin are very positive, saving our time with a reduced workload by 30 to 40 percent, and user provisioning, including onboarding or off-boarding, has become very fast by 60 to 80 percent.

    What needs improvement?

    Based on my experience, the only improvement needed for OneLogin is customization of the dashboard; apart from this, all the features are very useful and scalable.

    For how long have I used the solution?

    I have been working in my current field for almost two years.

    What do I think about the stability of the solution?

    OneLogin is a very stable solution.

    What do I think about the scalability of the solution?

    I believe OneLogin is a scalable solution.

    How are customer service and support?

    The customer support for OneLogin has been very good and responsive; they are knowledgeable and able to troubleshoot effectively.

    Which solution did I use previously and why did I switch?

    We have not switched from a different solution; we have been using OneLogin since the beginning.

    How was the initial setup?

    My advice for organizations considering OneLogin is to start with a clear identity and access management strategy before deployment. They should take time to understand their applications, user groups, and access policies, enabling all necessary features including MFA or single sign-on and leveraging automated provisioning and de-provisioning to reduce administrative workload.

    What about the implementation team?

    We have a partnership with the vendor, and it goes beyond being just a customer.

    What was our ROI?

    I must say we have seen a great return on investment, with saved time and money, as the automation features have significantly improved our user provisioning and de-provisioning processes.

    What's my experience with pricing, setup cost, and licensing?

    The pricing, setup cost, and licensing for OneLogin are managed by our management team, not by us.

    Which other solutions did I evaluate?

    We have not evaluated other options apart from OneLogin.

    What other advice do I have?

    Regarding OneLogin's AI capabilities, I think its governance and security are supported by strong AI-driven and adaptive security capabilities, centralized identity management, role-based access control, and MFA with detailed auto audit logging. OneLogin provides accurate and reliable AI output, particularly when assessing login risk based on user behavior and device information, effectively identifying potential suspicious authentication attempts.

    We do use OneLogin's SmartFactor Authentication for balancing security and usability, and when a user logs in from a trusted device and known location, they are granted seamless access; however, if the login is from an unfamiliar device or location, it is flagged as a potential threat and requires additional authentication.

    My impression of the user identity synchronization across directories functionality in OneLogin is very smooth, as users are synchronized from the directory and group across our directory services and connected applications seamlessly.

    The impact of integrating phishing-resistant device trust on our authentication processes is that it has strengthened our applications and authentication by ensuring only trusted devices can access them, significantly reducing the risk of credential theft.

    My impression of OneLogin's ability to provide a seamless end-user experience for signing in and authenticating to needed applications is very positive, as it offers a smooth, user-friendly authentication experience.

    We do use adaptive login flows with Vigilance AI, which have proven very effective in improving our ability to detect and respond to risky authentication attempts. I would rate this review a 9 out of 10.

    Kapil Janbade

    Centralized access has strengthened authentication security and simplifies daily user logins

    Reviewed on May 30, 2026
    Review provided by PeerSpot

    What is our primary use case?

    My main use case for OneLogin  is to help us manage user authentication and provide secure single sign-on across applications. We use OneLogin  daily for single sign-on and user authentication. It helps a user securely access multiple applications with one set of credentials, improving both convenience and security.

    What is most valuable?

    The best features of OneLogin are single sign-on, multi-factor authentication (MFA), centralized user management, and secure access control. These features help improve security and simplify user access across applications.

    Multi-factor authentication (MFA) has had the biggest impact for our team. It adds an extra layer of security to user logins and helps protect our applications and accounts from unauthorized access.

    Another feature I appreciate is the ease of managing user access from a single platform. It makes administration simpler and helps maintain consistency across applications.

    OneLogin has improved security, simplified user access, and reduced the time spent managing login-related issues, making day-to-day operations more efficient.

    What needs improvement?

    An improvement would be enhanced reporting and analytics capabilities. More detailed and customizable reports would make it even easier to monitor user activity and access trends.

    For how long have I used the solution?

    I have been using OneLogin for around five years.

    What do I think about the stability of the solution?

    OneLogin has been very stable in our experience. It provides reliable authentication and access management with minimal downtime or issues.

    What do I think about the scalability of the solution?

    OneLogin is highly scalable. It can easily support a growing number of users, applications, and authentication requests, making it suitable for organizations of different sizes.

    How are customer service and support?

    Customer support has been good. The team is responsive, knowledgeable, and helpful. They assist in a timely manner to resolve issues.

    Which solution did I use previously and why did I switch?

    We previously used other authentication and access management tools. We switched to OneLogin to gain centralized identity management.

    How was the initial setup?

    The pricing and licensing were reasonable for our requirement, and the setup was straightforward. The overall value has been good, considering the security and productivity benefits it provides.

    What about the implementation team?

    We evaluated a few alternatives including Microsoft Entra ID , Azure AD , and Okta. We chose OneLogin because of its ease of use, strong SSO  capabilities, and straightforward user management.

    What was our ROI?

    We have seen a positive ROI. OneLogin reduced password-related support requests and simplified user access management, saving time for both end users and the IT team, while improving productivity.

    What's my experience with pricing, setup cost, and licensing?

    We saw fewer password-related support tickets and saved time on user access management. The centralized authentication and SSO  features help reduce administrative efforts and improve user productivity.

    Which other solutions did I evaluate?

    OneLogin is highly reliable in enforcing authentication and access policies. It consistently performs as expected, helping ensure accurate user authentication and secure access management across applications.

    What other advice do I have?

    My advice would be to plan for your application integration and access policies early. Take full advantage of the SSO and MFA features, as they can significantly improve security, simplify user access, and reduce administrative overhead. I would rate this product nine out of ten.

    Mohammed Asim Khan

    Centralized identity has automated onboarding and improves secure access to all business apps

    Reviewed on May 29, 2026
    Review provided by PeerSpot

    What is our primary use case?

    Our main use case for OneLogin  is to centralize user authentication and provide secure access to the business application through a single identity platform. For example, whenever a new employee joins our company, OneLogin  automatically creates access to approved applications based on their employee roles and responsibilities, allowing them to start working without waiting for manual account setup from the IT team. This process is totally automated.

    How has it helped my organization?

    OneLogin has impacted our organization positively in many ways because it has simplified application access, improved identity security, and increased operational efficiency. We haven't encountered any login-related issues since we started using this solution.

    There are measurable outcomes that I can share from my experience. We are getting fewer password reset requests and experiencing faster onboarding of users. We also see reduced administrative work overhead. These have been really measurable outcomes since we started using this solution.

    What is most valuable?

    The best features I can identify while handling and implementing this solution are its centralized authentication, single sign-on capabilities, and access policy management.

    In our day-to-day operation, the centralized authentication provides us deep visibility into whatever users are accessing. The single sign-on provides an extra layer of security for the authentication. The access management policy management is very useful for granular control, and the centralized access management really allows users to securely access multiple applications through one platform while simplifying administration.

    OneLogin is very useful in terms of governance and security with excellent AI capabilities. Most of the time it provides accurate output and is a very reliable solution.

    We use SmartFactor Authentication, which applies risk-based authentication policies by evaluating factors such as user locations, device, IP address, and behavior to determine the level of authentication required. This feature is very useful.

    The synchronization across the directory has been really impressive because it syncs in real time, occurring every five minutes. Whenever any new user is created in the Active Directory, it directly syncs to OneLogin. My impression has been really excellent with the synchronization.

    The integration of phishing-resistant devices has strengthened our authentication process by ensuring that access is granted not only based on the user but also on the security posture of the device being used. Trusted and compliant devices can access resources while unknown or non-compliant devices are subject to additional verification or access restrictions.

    The impression has been really positive and the end users are very happy, providing positive feedback with the smooth authentication experience.

    We use adaptive login flows with Vigilance AI, which provides an extra layer of security in our organization. This feature helps us identify unusual login activities and analyze factors that include location, device, IP address, and user behavior patterns. When a login appears low-risk, the user can authenticate, but if the system detects suspicious behavior from an unfamiliar location or device, it automatically requests additional verification through MFA, providing that extra layer of security.

    HR-driven identity management plays a critical role in automating the employee lifecycle. When employee information is updated in the HR tool, identity-related actions such as account creation, the assignment of access and role, or the account activation or deactivation can be triggered automatically. This helps us streamline onboarding, transferring role changes, and off-boarding, which reduces manual administrative work, improves accuracy, and reduces the risk of errors.

    What needs improvement?

    The only thing that needs to be improved with this solution is its initial implementation or fine-tuning, which requires an expert-level engineer to deploy. This could make the process easier to handle and deploy.

    From my experience, the solution really delivers strong authentication and access management capabilities. The only area where improvement is needed is the initial setup or implementation. Apart from this, everything really works well and very smoothly.

    For how long have I used the solution?

    I have been using OneLogin for two years.

    What do I think about the stability of the solution?

    OneLogin is a very stable solution.

    What do I think about the scalability of the solution?

    OneLogin is a very scalable solution, handling user count growth over the years.

    How are customer service and support?

    Customer support is excellent. They are able to resolve complex technical issues. Whenever we encounter any kind of issue, we raise a ticket with the customer support team.

    Which solution did I use previously and why did I switch?

    We have not switched from any previous solution. We started using this kind of solution with OneLogin only.

    How was the initial setup?

    My advice would be to start with the POC and check all the feature sets and AI capabilities. Once you are ready with the POC, you can proceed with the procurement of the solution and start with proper planning and use cases to begin the implementation, gradually onboarding or integrating the Active Directory.

    What was our ROI?

    We have seen an ROI and are able to save our time and money.

    Which other solutions did I evaluate?

    We have not evaluated other options because we started evaluating OneLogin initially, completed the POC, and were very impressed with this solution. We started using this solution several years ago.

    What other advice do I have?

    I have already covered everything I wanted to share. My overall rating for OneLogin is 9 out of 10.

    reviewer2809026

    Centralized access has strengthened authentication with seamless sign-on and smart risk-based MFA

    Reviewed on May 27, 2026
    Review provided by PeerSpot

    What is our primary use case?

    I have been testing OneLogin  for about six months. Single sign-on, multi-factor authentication, and user lifecycle management are my main use cases for OneLogin , and these are the things I have been testing with it. I have an application which I wanted to integrate with OneLogin for user lifecycle management. I want to provision my users to it and provide single sign-on to that application. When signing into that application, I also want it to integrate multi-factor authentication with it. These are the basic examples that I tried with OneLogin.

    What is most valuable?

    Single sign-on works reliably with OneLogin, and SCIM provisioning is also strong in OneLogin. Additionally, directory integrations are solid with OneLogin. OneLogin has more apps to integrate with, providing a great catalog. Smart Factor Authentication is a really worth mentioning feature that I appreciate.

    OneLogin's app catalog already has pre-existing connectors, which reduces the normal effort to create a custom one. Regarding Smart Factor Authentication, it reduces multi-factor authentication friction. Multi-factor authentication is only prompted when the risk score is calculated as high, and Smart Factor Authentication decides this. These features are what I appreciate.

    Smart Factor Authentication is something and the best feature I have implemented with this. It allows organizations, if implemented on a large scale, to provide better authentication when the risk is high by prompting the user for multi-factor authentication, which reduces entity risk. This is something that has an impact.

    When integrating Smart Factor Authentication, in a normal scenario, if a user is not a desk risk, then the usual authentication process will be followed. More multi-factor authentication fatigue will not be asked for that user, which reduces the friction for that user to log in and access the applications. Multi-factor authentication is enabled only when the risk factor of that user is high, then I ask the user about multi-factor authentication so that I can confirm that the user is genuine. With that, I can improve the security layer in any organization that uses OneLogin.

    OneLogin's ability to provide a seamless end-user experience for signing in and authenticating to needed applications is pretty good. The experience is very seamless in authenticating with the application using OneLogin.

    What needs improvement?

    OneLogin's online documentation could be improved with more information and clearer step-by-step instructions, which would help beginners understand these things better. OneLogin's APIs are limited regarding what can be done with the exposed APIs, and any SAML integration or custom SAML integration in any of the identity and access management platforms takes manual effort, which is something OneLogin could improve.

    In custom SAML integration, I cannot improve anything. OneLogin could improve some user interface elements which would make users feel more comfortable integrating a custom solution.

    Regarding artificial intelligence capabilities in OneLogin, that area still needs to be improved because the artificial intelligence developments in the security industry are not fully developed within OneLogin's capabilities.

    More improvements are needed, specifically regarding APIs and user interface, but the remaining features are already good.

    For how long have I used the solution?

    I have been working in my current field for almost two and a half to three years.

    What do I think about the stability of the solution?

    OneLogin is stable.

    What do I think about the scalability of the solution?

    OneLogin's scalability is pretty good. It can work with large-scale users and applications, and in consideration of scalability, I would rate it an eight.

    How are customer service and support?

    Customer support is also good, but it is slow. If I have an issue, the resolution will be taken and support will be given, but it is not really quick.

    Which solution did I use previously and why did I switch?

    I did not switch to OneLogin. I have used many solutions previously. Comparatively, OneLogin is also one of the good ones.

    How was the initial setup?

    I did not actually implement OneLogin. I tested it on my local machine. OneLogin was tested on my local machine, and for the test one, it is on the cloud.

    What about the implementation team?

    I am using some setup that is given and generated by OneLogin tenant, though I did not go through the deployment setup myself.

    What's my experience with pricing, setup cost, and licensing?

    I did not go through that phase yet because I did not actually take the license. As far as I know about the license, I have seen them, and it is pretty much acceptable for the solutions and features that OneLogin is providing.

    Which other solutions did I evaluate?

    I have evaluated other options like Okta, Microsoft Entra ID , and Ping Identity as alternatives.

    What other advice do I have?

    This is a great feature, and how I balance this is something which is significant. When the integration of phishing-resistant device trust is not secure, I stop the authentication at that point and do not continue or give the session.

    OneLogin does not have any human resources-driven identity management. As far as I configured it, I did not use any human resources system to get the users from. I used Active Directory integration. With Active Directory, the directory integrations are smooth. My organization may have human resources applications, but I have not tested them with OneLogin.

    Time-saving reduces the payments along with the licensing cost for the applications that I use. I have less knowledge in this area regarding pricing and return on investment, because I would have to implement it to truly understand. Plan my policies and users, groups, and other things accordingly so that I get the best out of it.

    OneLogin is a cool product for organizations to use for security. I would rate this review an eight overall.

    Rajkumar Raut

    Single sign-on has simplified identity workflows but customization and advanced features need work

    Reviewed on May 26, 2026
    Review from a verified AWS customer

    What is our primary use case?

    My use cases for OneLogin  mainly include SSO  integration and user onboarding, user lifecycle management from the source directory, which is Active Directory, and the different sources supported by OneLogin . I use this product for Single Sign-On , user onboarding, and user lifecycle management.

    The integration of phishing-resistant device trust with OneLogin impacts my authentication processes positively because OneLogin has its own MFA provider, OneLogin Protect, which provides good service and push notifications to avoid phishing and other issues.

    What is most valuable?

    OneLogin is user-friendly, and any administrator can handle it easily. It has plenty of applications to integrate for Single Sign-On and supports multiple protocols. It is easier and faster, and it has good service.

    The user identity synchronization across directories functionality in OneLogin enables real-time user synchronization operations. It supports real-time synchronization, and as soon as a user is created on the directory side, it reflects within a second. The speed of onboarding is efficient, and it supports load balancing. If one directory connection fails, it supports multiple directory connections.

    Integrating with third-party authentication providers through OneLogin is manageable because it has built-in authenticators that are supportive, including hardware token-based authentication. I have also used the built-in MFA configurations for OneLogin.

    I have used the adaptive login flows with Vigilance AI, which automatically triggers MFA based on the severity and risk score, making it a good feature provided by OneLogin security policies.

    The ability of Vigilance AI to detect risky behavior and adjust authentication factors affects my processes significantly because it tracks multiple factors such as location and IPs in real-time. When a user suddenly relocates to a different location or logs in from a different IP address, it detects it as high risk and triggers the adaptive MFA factor for more security.

    HR-driven identity management plays a crucial role in streamlining employee identity handling in my organization since OneLogin has an HRMS system to integrate for user onboarding, such as Workday . It also supports OneLogin developer APIs for customization, allowing for real-time onboarding for any other HRMS systems.

    Enforcing MFA at the desktop level, regardless of online or offline status, impacts our security protocols because OneLogin Protect requires an internet connection, while other supported MFA factors, such as Google Authenticator , are TOTP-based and can be handled offline. Thus, both scenarios are usable.

    The benefits of customer identity and access management for external clients in OneLogin are evident as it supports user registration flows and user authentication using OIDC flows. This product is customizable for CIAM  use cases and supports MFA enrollment through the APIs, allowing for scalability to onboard multiple users efficiently.

    OneLogin's SmartFactor Authentication adjusts authentication flows in real time depending on the risk score associated with login attempts, which is completely dependent on Vigilance AI detecting behaviors, device locations, and IP repetition to assess risk scores.

    OneLogin's ability to provide a seamless end user experience for signing in and authenticating to needed applications is positive because it features a seamless authentication flow with multiple SSO protocols, such as OIDC and SAML. For different supported protocol applications, it seamlessly redirects to OneLogin for authentication and completes the MFA and authentication processes efficiently, redirecting to the respective application afterward.

    What needs improvement?

    More customization should be available in OneLogin, such as customizable branding and better API support, including multiple APIs for policy management and more user-friendly APIs.

    I would appreciate seeing missing features such as an authorization server included in the future, and functionalities such as IdP redirection routing rules should be added.

    For how long have I used the solution?

    I have been using OneLogin for more than four years for OneLogin implementation such as SSO and integration, and IIM implementation for the organization.

    What do I think about the stability of the solution?

    OneLogin is stable.

    I have not had any performance issues, crashes, or downtimes with OneLogin. If there is maintenance mode, they notify the administrator by email, and they have the status.onelogin.com portal to check the availability of different services.

    What do I think about the scalability of the solution?

    I can onboard multiple users to manage user lifecycle management effectively with OneLogin.

    I generally use OneLogin for about 50,000 to 60,000 users, but there are some limitations for more than that. The API gets failed sometimes, not responding, and background jobs take too much time to process CSV onboarding, leading to some issues.

    How are customer service and support?

    OneLogin provides support, and I can raise tickets for any difficulty. They offer efficient support.

    Which solution did I use previously and why did I switch?

    In my previous experience, I have worked with multiple products such as Okta and Entra ID before switching to OneLogin.

    How was the initial setup?

    The initial setup process of OneLogin is straightforward. The account sign-up is easier than others, making it good.

    What about the implementation team?

    I am responsible for deploying OneLogin for different organizations.

    My organization is a partner of OneLogin, not just a system integrator or implementer of the product.

    What was our ROI?

    OneLogin provides measurable benefits and good ROI for beginners and small organizations that want a user-friendly UI, making it a preferable option for that audience.

    What's my experience with pricing, setup cost, and licensing?

    I am not much aware of the pricing, setup costs, and licensing part of OneLogin, but I know that it tends to be on the lesser side compared to competitors, making it cheaper than others.

    Which other solutions did I evaluate?

    The key differences between OneLogin and its competitors include functionality balance, where OneLogin offers limited functionalities suitable for day-to-day use, while competitors such as Okta have major features including automation with Okta workflow.

    What other advice do I have?

    I have not tried integrating with any third-party authenticators, but I have used the built-in authenticators only.

    Based on my experience, I would recommend OneLogin for its simplicity and easier administration for small organizations, but I would not recommend it for organizations seeking more feature-oriented and deeper IAM  capabilities.

    I have over six years of experience in the IAM  domain. I overall rate OneLogin as a product at seven out of ten.

    Which deployment model are you using for this solution?

    Public Cloud

    If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?

    View all reviews