Overview

Product video
OneLogin by One Identity is a modern, cloud-based access management solution that seamlessly manages all digital identities for your workforce, customers and partners. OneLogin provides secure single sign-on (SSO), multi-factor authentication (MFA) with support for a wide array of passwordless authentication factors, adaptive authentication, desktop-level MFA, directory integration with AD, LDAP, G Suite and other external directories, identity lifecycle management and much more.
OneLogin uses powerful authentication and role-based user provisioning engine enabling you to implement least-privileged access controls and eliminate manual user management workflows. Moreover, OneLogin delivers multi-layer, context aware and risk-based protection, minimizing the most common attacks and resulting in increased security, frictionless user experiences, and compliance with regulatory requirements.
OneLogin has pre-built authentication connectors with thousands of third-party web applications with extensibility across your entire portfolio. With OneLogin, you can:
-Implement single sign-on (SSO) for users across mobile, web and desktop
-Enforce contextual multi-factor authentication (MFA) and access security policies, and automate user account provisioning
-Provision users with granular access permissions into the AWS Console/CLI or directly to AWS services
-Extend security controls across your cloud infrastructure by leveraging pre-built integrations with Amazon Control Tower, AWS IAM, AWS SSO, Amazon Cognito, and Amazon EventBridge
If interested in private offers, email us at partnercircle@oneidentity.com .
Highlights
- SSO: Automatically sync users across multiple directories in minutes to enable one-click access to all corporate applications, whether on-prem or in the cloud, and enforce strong security policies, plus self-service password reset.
- MULTI-FACTOR AUTHENTICATION (MFA): Supports many authentication methods, including passwordless, passkeys, one-time passcodes, push notifications, biometric data, security keys and more. With real-time reporting and monitoring capabilities, gain insights into authentication events, enabling proactive detection and response to potential security incidents.
- ADVANCED DIRECTORY: Acts as your secure directory in the cloud with an intuitive web-based interface that allows you to manage users, their manager relationship, authentication policies and access controls.
Details
Introducing multi-product solutions
You can now purchase comprehensive solutions tailored to use cases and industries.
Features and programs
Buyer guide

Financing for AWS Marketplace purchases
Pricing
Free trial
Dimension | Description | Cost/12 months |
|---|---|---|
OneLogin 1-App Plan | Standard User License, OneLogin 1-App Plan for AWS | $12.00 |
OneLogin Advanced Plan | Standard User License, OneLogin Advanced Plan | $48.00 |
OneLogin Professional Plan | Standard User License, OneLogin Professional Plan | $96.00 |
Custom | Private offers available - email partners@onelogin.com | $96.00 |
Vendor refund policy
Please refer to OneLogin terms of service https://www.onelogin.com/terms
How can we make this page better?
Legal
Vendor terms and conditions
Content disclaimer
Delivery details
Software as a Service (SaaS)
SaaS delivers cloud-based software applications directly to customers over the internet. You can access these applications through a subscription model. You will pay recurring monthly usage fees through your AWS bill, while AWS handles deployment and infrastructure management, ensuring scalability, reliability, and seamless integration with other AWS services.
Support
Vendor support
To learn more about OneLogin Customer Support, visit
AWS infrastructure support
AWS Support is a one-on-one, fast-response support channel that is staffed 24x7x365 with experienced and technical support engineers. The service helps customers of all sizes and technical abilities to successfully utilize the products and features provided by Amazon Web Services.

Standard contract
Customer reviews
Centralized identity has reduced manual access work and now automates secure user lifecycle management
What is our primary use case?
My main use case for OneLogin is that we use this solution as our centralized identity provider to maintain and manage authentication, authorization, and secure access to both cloud and on-premises applications.
What is most valuable?
OneLogin offers several best features such as federated single sign-on, risk-based authentication, automated user provisioning, and the most important, centralized access governance.
I mostly rely on automated user lifecycle management within OneLogin, as it automatically provisions and de-provisions users' accounts, helping our nation improve security and reduce the manual work of the administrator.
OneLogin has positively impacted my organization in several ways, as it has really improved both security and user productivity, allowing employees to securely access multiple applications with the help of single sign-on, which has significantly reduced password-related issues.
The outcomes since adopting OneLogin are very positive, saving our time with a reduced workload by 30 to 40 percent, and user provisioning, including onboarding or off-boarding, has become very fast by 60 to 80 percent.
What needs improvement?
Based on my experience, the only improvement needed for OneLogin is customization of the dashboard; apart from this, all the features are very useful and scalable.
For how long have I used the solution?
I have been working in my current field for almost two years.
What do I think about the stability of the solution?
OneLogin is a very stable solution.
What do I think about the scalability of the solution?
I believe OneLogin is a scalable solution.
How are customer service and support?
The customer support for OneLogin has been very good and responsive; they are knowledgeable and able to troubleshoot effectively.
Which solution did I use previously and why did I switch?
We have not switched from a different solution; we have been using OneLogin since the beginning.
How was the initial setup?
My advice for organizations considering OneLogin is to start with a clear identity and access management strategy before deployment. They should take time to understand their applications, user groups, and access policies, enabling all necessary features including MFA or single sign-on and leveraging automated provisioning and de-provisioning to reduce administrative workload.
What about the implementation team?
We have a partnership with the vendor, and it goes beyond being just a customer.
What was our ROI?
I must say we have seen a great return on investment, with saved time and money, as the automation features have significantly improved our user provisioning and de-provisioning processes.
What's my experience with pricing, setup cost, and licensing?
The pricing, setup cost, and licensing for OneLogin are managed by our management team, not by us.
Which other solutions did I evaluate?
We have not evaluated other options apart from OneLogin.
What other advice do I have?
Regarding OneLogin's AI capabilities, I think its governance and security are supported by strong AI-driven and adaptive security capabilities, centralized identity management, role-based access control, and MFA with detailed auto audit logging. OneLogin provides accurate and reliable AI output, particularly when assessing login risk based on user behavior and device information, effectively identifying potential suspicious authentication attempts.
We do use OneLogin's SmartFactor Authentication for balancing security and usability, and when a user logs in from a trusted device and known location, they are granted seamless access; however, if the login is from an unfamiliar device or location, it is flagged as a potential threat and requires additional authentication.
My impression of the user identity synchronization across directories functionality in OneLogin is very smooth, as users are synchronized from the directory and group across our directory services and connected applications seamlessly.
The impact of integrating phishing-resistant device trust on our authentication processes is that it has strengthened our applications and authentication by ensuring only trusted devices can access them, significantly reducing the risk of credential theft.
My impression of OneLogin's ability to provide a seamless end-user experience for signing in and authenticating to needed applications is very positive, as it offers a smooth, user-friendly authentication experience.
We do use adaptive login flows with Vigilance AI, which have proven very effective in improving our ability to detect and respond to risky authentication attempts. I would rate this review a 9 out of 10.
Centralized access has strengthened authentication security and simplifies daily user logins
What is our primary use case?
My main use case for OneLogin is to help us manage user authentication and provide secure single sign-on across applications. We use OneLogin daily for single sign-on and user authentication. It helps a user securely access multiple applications with one set of credentials, improving both convenience and security.
What is most valuable?
The best features of OneLogin are single sign-on, multi-factor authentication (MFA), centralized user management, and secure access control. These features help improve security and simplify user access across applications.
Multi-factor authentication (MFA) has had the biggest impact for our team. It adds an extra layer of security to user logins and helps protect our applications and accounts from unauthorized access.
Another feature I appreciate is the ease of managing user access from a single platform. It makes administration simpler and helps maintain consistency across applications.
OneLogin has improved security, simplified user access, and reduced the time spent managing login-related issues, making day-to-day operations more efficient.
What needs improvement?
An improvement would be enhanced reporting and analytics capabilities. More detailed and customizable reports would make it even easier to monitor user activity and access trends.
For how long have I used the solution?
I have been using OneLogin for around five years.
What do I think about the stability of the solution?
OneLogin has been very stable in our experience. It provides reliable authentication and access management with minimal downtime or issues.
What do I think about the scalability of the solution?
OneLogin is highly scalable. It can easily support a growing number of users, applications, and authentication requests, making it suitable for organizations of different sizes.
How are customer service and support?
Customer support has been good. The team is responsive, knowledgeable, and helpful. They assist in a timely manner to resolve issues.
Which solution did I use previously and why did I switch?
We previously used other authentication and access management tools. We switched to OneLogin to gain centralized identity management.
How was the initial setup?
The pricing and licensing were reasonable for our requirement, and the setup was straightforward. The overall value has been good, considering the security and productivity benefits it provides.
What about the implementation team?
We evaluated a few alternatives including Microsoft Entra ID , Azure AD , and Okta. We chose OneLogin because of its ease of use, strong SSO capabilities, and straightforward user management.
What was our ROI?
We have seen a positive ROI. OneLogin reduced password-related support requests and simplified user access management, saving time for both end users and the IT team, while improving productivity.
What's my experience with pricing, setup cost, and licensing?
We saw fewer password-related support tickets and saved time on user access management. The centralized authentication and SSO features help reduce administrative efforts and improve user productivity.
Which other solutions did I evaluate?
OneLogin is highly reliable in enforcing authentication and access policies. It consistently performs as expected, helping ensure accurate user authentication and secure access management across applications.
What other advice do I have?
My advice would be to plan for your application integration and access policies early. Take full advantage of the SSO and MFA features, as they can significantly improve security, simplify user access, and reduce administrative overhead. I would rate this product nine out of ten.
Centralized identity has automated onboarding and improves secure access to all business apps
What is our primary use case?
Our main use case for OneLogin is to centralize user authentication and provide secure access to the business application through a single identity platform. For example, whenever a new employee joins our company, OneLogin automatically creates access to approved applications based on their employee roles and responsibilities, allowing them to start working without waiting for manual account setup from the IT team. This process is totally automated.
How has it helped my organization?
OneLogin has impacted our organization positively in many ways because it has simplified application access, improved identity security, and increased operational efficiency. We haven't encountered any login-related issues since we started using this solution.
There are measurable outcomes that I can share from my experience. We are getting fewer password reset requests and experiencing faster onboarding of users. We also see reduced administrative work overhead. These have been really measurable outcomes since we started using this solution.
What is most valuable?
The best features I can identify while handling and implementing this solution are its centralized authentication, single sign-on capabilities, and access policy management.
In our day-to-day operation, the centralized authentication provides us deep visibility into whatever users are accessing. The single sign-on provides an extra layer of security for the authentication. The access management policy management is very useful for granular control, and the centralized access management really allows users to securely access multiple applications through one platform while simplifying administration.
OneLogin is very useful in terms of governance and security with excellent AI capabilities. Most of the time it provides accurate output and is a very reliable solution.
We use SmartFactor Authentication, which applies risk-based authentication policies by evaluating factors such as user locations, device, IP address, and behavior to determine the level of authentication required. This feature is very useful.
The synchronization across the directory has been really impressive because it syncs in real time, occurring every five minutes. Whenever any new user is created in the Active Directory, it directly syncs to OneLogin. My impression has been really excellent with the synchronization.
The integration of phishing-resistant devices has strengthened our authentication process by ensuring that access is granted not only based on the user but also on the security posture of the device being used. Trusted and compliant devices can access resources while unknown or non-compliant devices are subject to additional verification or access restrictions.
The impression has been really positive and the end users are very happy, providing positive feedback with the smooth authentication experience.
We use adaptive login flows with Vigilance AI, which provides an extra layer of security in our organization. This feature helps us identify unusual login activities and analyze factors that include location, device, IP address, and user behavior patterns. When a login appears low-risk, the user can authenticate, but if the system detects suspicious behavior from an unfamiliar location or device, it automatically requests additional verification through MFA, providing that extra layer of security.
HR-driven identity management plays a critical role in automating the employee lifecycle. When employee information is updated in the HR tool, identity-related actions such as account creation, the assignment of access and role, or the account activation or deactivation can be triggered automatically. This helps us streamline onboarding, transferring role changes, and off-boarding, which reduces manual administrative work, improves accuracy, and reduces the risk of errors.
What needs improvement?
The only thing that needs to be improved with this solution is its initial implementation or fine-tuning, which requires an expert-level engineer to deploy. This could make the process easier to handle and deploy.
From my experience, the solution really delivers strong authentication and access management capabilities. The only area where improvement is needed is the initial setup or implementation. Apart from this, everything really works well and very smoothly.
For how long have I used the solution?
I have been using OneLogin for two years.
What do I think about the stability of the solution?
OneLogin is a very stable solution.
What do I think about the scalability of the solution?
OneLogin is a very scalable solution, handling user count growth over the years.
How are customer service and support?
Customer support is excellent. They are able to resolve complex technical issues. Whenever we encounter any kind of issue, we raise a ticket with the customer support team.
Which solution did I use previously and why did I switch?
We have not switched from any previous solution. We started using this kind of solution with OneLogin only.
How was the initial setup?
My advice would be to start with the POC and check all the feature sets and AI capabilities. Once you are ready with the POC, you can proceed with the procurement of the solution and start with proper planning and use cases to begin the implementation, gradually onboarding or integrating the Active Directory.
What was our ROI?
We have seen an ROI and are able to save our time and money.
Which other solutions did I evaluate?
We have not evaluated other options because we started evaluating OneLogin initially, completed the POC, and were very impressed with this solution. We started using this solution several years ago.
What other advice do I have?
I have already covered everything I wanted to share. My overall rating for OneLogin is 9 out of 10.
Centralized access has strengthened authentication with seamless sign-on and smart risk-based MFA
What is our primary use case?
I have been testing OneLogin for about six months. Single sign-on, multi-factor authentication, and user lifecycle management are my main use cases for OneLogin , and these are the things I have been testing with it. I have an application which I wanted to integrate with OneLogin for user lifecycle management. I want to provision my users to it and provide single sign-on to that application. When signing into that application, I also want it to integrate multi-factor authentication with it. These are the basic examples that I tried with OneLogin.
What is most valuable?
Single sign-on works reliably with OneLogin, and SCIM provisioning is also strong in OneLogin. Additionally, directory integrations are solid with OneLogin. OneLogin has more apps to integrate with, providing a great catalog. Smart Factor Authentication is a really worth mentioning feature that I appreciate.
OneLogin's app catalog already has pre-existing connectors, which reduces the normal effort to create a custom one. Regarding Smart Factor Authentication, it reduces multi-factor authentication friction. Multi-factor authentication is only prompted when the risk score is calculated as high, and Smart Factor Authentication decides this. These features are what I appreciate.
Smart Factor Authentication is something and the best feature I have implemented with this. It allows organizations, if implemented on a large scale, to provide better authentication when the risk is high by prompting the user for multi-factor authentication, which reduces entity risk. This is something that has an impact.
When integrating Smart Factor Authentication, in a normal scenario, if a user is not a desk risk, then the usual authentication process will be followed. More multi-factor authentication fatigue will not be asked for that user, which reduces the friction for that user to log in and access the applications. Multi-factor authentication is enabled only when the risk factor of that user is high, then I ask the user about multi-factor authentication so that I can confirm that the user is genuine. With that, I can improve the security layer in any organization that uses OneLogin.
OneLogin's ability to provide a seamless end-user experience for signing in and authenticating to needed applications is pretty good. The experience is very seamless in authenticating with the application using OneLogin.
What needs improvement?
OneLogin's online documentation could be improved with more information and clearer step-by-step instructions, which would help beginners understand these things better. OneLogin's APIs are limited regarding what can be done with the exposed APIs, and any SAML integration or custom SAML integration in any of the identity and access management platforms takes manual effort, which is something OneLogin could improve.
In custom SAML integration, I cannot improve anything. OneLogin could improve some user interface elements which would make users feel more comfortable integrating a custom solution.
Regarding artificial intelligence capabilities in OneLogin, that area still needs to be improved because the artificial intelligence developments in the security industry are not fully developed within OneLogin's capabilities.
More improvements are needed, specifically regarding APIs and user interface, but the remaining features are already good.
For how long have I used the solution?
I have been working in my current field for almost two and a half to three years.
What do I think about the stability of the solution?
OneLogin is stable.
What do I think about the scalability of the solution?
OneLogin's scalability is pretty good. It can work with large-scale users and applications, and in consideration of scalability, I would rate it an eight.
How are customer service and support?
Customer support is also good, but it is slow. If I have an issue, the resolution will be taken and support will be given, but it is not really quick.
Which solution did I use previously and why did I switch?
I did not switch to OneLogin. I have used many solutions previously. Comparatively, OneLogin is also one of the good ones.
How was the initial setup?
I did not actually implement OneLogin. I tested it on my local machine. OneLogin was tested on my local machine, and for the test one, it is on the cloud.
What about the implementation team?
I am using some setup that is given and generated by OneLogin tenant, though I did not go through the deployment setup myself.
What's my experience with pricing, setup cost, and licensing?
I did not go through that phase yet because I did not actually take the license. As far as I know about the license, I have seen them, and it is pretty much acceptable for the solutions and features that OneLogin is providing.
Which other solutions did I evaluate?
I have evaluated other options like Okta, Microsoft Entra ID , and Ping Identity as alternatives.
What other advice do I have?
This is a great feature, and how I balance this is something which is significant. When the integration of phishing-resistant device trust is not secure, I stop the authentication at that point and do not continue or give the session.
OneLogin does not have any human resources-driven identity management. As far as I configured it, I did not use any human resources system to get the users from. I used Active Directory integration. With Active Directory, the directory integrations are smooth. My organization may have human resources applications, but I have not tested them with OneLogin.
Time-saving reduces the payments along with the licensing cost for the applications that I use. I have less knowledge in this area regarding pricing and return on investment, because I would have to implement it to truly understand. Plan my policies and users, groups, and other things accordingly so that I get the best out of it.
OneLogin is a cool product for organizations to use for security. I would rate this review an eight overall.
Single sign-on has simplified identity workflows but customization and advanced features need work
What is our primary use case?
My use cases for OneLogin mainly include SSO integration and user onboarding, user lifecycle management from the source directory, which is Active Directory, and the different sources supported by OneLogin . I use this product for Single Sign-On , user onboarding, and user lifecycle management.
The integration of phishing-resistant device trust with OneLogin impacts my authentication processes positively because OneLogin has its own MFA provider, OneLogin Protect, which provides good service and push notifications to avoid phishing and other issues.
What is most valuable?
OneLogin is user-friendly, and any administrator can handle it easily. It has plenty of applications to integrate for Single Sign-On and supports multiple protocols. It is easier and faster, and it has good service.
The user identity synchronization across directories functionality in OneLogin enables real-time user synchronization operations. It supports real-time synchronization, and as soon as a user is created on the directory side, it reflects within a second. The speed of onboarding is efficient, and it supports load balancing. If one directory connection fails, it supports multiple directory connections.
Integrating with third-party authentication providers through OneLogin is manageable because it has built-in authenticators that are supportive, including hardware token-based authentication. I have also used the built-in MFA configurations for OneLogin.
I have used the adaptive login flows with Vigilance AI, which automatically triggers MFA based on the severity and risk score, making it a good feature provided by OneLogin security policies.
The ability of Vigilance AI to detect risky behavior and adjust authentication factors affects my processes significantly because it tracks multiple factors such as location and IPs in real-time. When a user suddenly relocates to a different location or logs in from a different IP address, it detects it as high risk and triggers the adaptive MFA factor for more security.
HR-driven identity management plays a crucial role in streamlining employee identity handling in my organization since OneLogin has an HRMS system to integrate for user onboarding, such as Workday . It also supports OneLogin developer APIs for customization, allowing for real-time onboarding for any other HRMS systems.
Enforcing MFA at the desktop level, regardless of online or offline status, impacts our security protocols because OneLogin Protect requires an internet connection, while other supported MFA factors, such as Google Authenticator , are TOTP-based and can be handled offline. Thus, both scenarios are usable.
The benefits of customer identity and access management for external clients in OneLogin are evident as it supports user registration flows and user authentication using OIDC flows. This product is customizable for CIAM use cases and supports MFA enrollment through the APIs, allowing for scalability to onboard multiple users efficiently.
OneLogin's SmartFactor Authentication adjusts authentication flows in real time depending on the risk score associated with login attempts, which is completely dependent on Vigilance AI detecting behaviors, device locations, and IP repetition to assess risk scores.
OneLogin's ability to provide a seamless end user experience for signing in and authenticating to needed applications is positive because it features a seamless authentication flow with multiple SSO protocols, such as OIDC and SAML. For different supported protocol applications, it seamlessly redirects to OneLogin for authentication and completes the MFA and authentication processes efficiently, redirecting to the respective application afterward.
What needs improvement?
More customization should be available in OneLogin, such as customizable branding and better API support, including multiple APIs for policy management and more user-friendly APIs.
I would appreciate seeing missing features such as an authorization server included in the future, and functionalities such as IdP redirection routing rules should be added.
For how long have I used the solution?
I have been using OneLogin for more than four years for OneLogin implementation such as SSO and integration, and IIM implementation for the organization.
What do I think about the stability of the solution?
OneLogin is stable.
I have not had any performance issues, crashes, or downtimes with OneLogin. If there is maintenance mode, they notify the administrator by email, and they have the status.onelogin.com portal to check the availability of different services.
What do I think about the scalability of the solution?
I can onboard multiple users to manage user lifecycle management effectively with OneLogin.
I generally use OneLogin for about 50,000 to 60,000 users, but there are some limitations for more than that. The API gets failed sometimes, not responding, and background jobs take too much time to process CSV onboarding, leading to some issues.
How are customer service and support?
OneLogin provides support, and I can raise tickets for any difficulty. They offer efficient support.
Which solution did I use previously and why did I switch?
In my previous experience, I have worked with multiple products such as Okta and Entra ID before switching to OneLogin.
How was the initial setup?
The initial setup process of OneLogin is straightforward. The account sign-up is easier than others, making it good.
What about the implementation team?
I am responsible for deploying OneLogin for different organizations.
My organization is a partner of OneLogin, not just a system integrator or implementer of the product.
What was our ROI?
OneLogin provides measurable benefits and good ROI for beginners and small organizations that want a user-friendly UI, making it a preferable option for that audience.
What's my experience with pricing, setup cost, and licensing?
I am not much aware of the pricing, setup costs, and licensing part of OneLogin, but I know that it tends to be on the lesser side compared to competitors, making it cheaper than others.
Which other solutions did I evaluate?
The key differences between OneLogin and its competitors include functionality balance, where OneLogin offers limited functionalities suitable for day-to-day use, while competitors such as Okta have major features including automation with Okta workflow.
What other advice do I have?
I have not tried integrating with any third-party authenticators, but I have used the built-in authenticators only.
Based on my experience, I would recommend OneLogin for its simplicity and easier administration for small organizations, but I would not recommend it for organizations seeking more feature-oriented and deeper IAM capabilities.
I have over six years of experience in the IAM domain. I overall rate OneLogin as a product at seven out of ten.