Overview

Product video
OneLogin by One Identity is a modern, cloud-based access management solution that seamlessly manages all digital identities for your workforce, customers and partners. OneLogin provides secure single sign-on (SSO), multi-factor authentication (MFA) with support for a wide array of passwordless authentication factors, adaptive authentication, desktop-level MFA, directory integration with AD, LDAP, G Suite and other external directories, identity lifecycle management and much more.
OneLogin uses powerful authentication and role-based user provisioning engine enabling you to implement least-privileged access controls and eliminate manual user management workflows. Moreover, OneLogin delivers multi-layer, context aware and risk-based protection, minimizing the most common attacks and resulting in increased security, frictionless user experiences, and compliance with regulatory requirements.
OneLogin has pre-built authentication connectors with thousands of third-party web applications with extensibility across your entire portfolio. With OneLogin, you can:
-Implement single sign-on (SSO) for users across mobile, web and desktop
-Enforce contextual multi-factor authentication (MFA) and access security policies, and automate user account provisioning
-Provision users with granular access permissions into the AWS Console/CLI or directly to AWS services
-Extend security controls across your cloud infrastructure by leveraging pre-built integrations with Amazon Control Tower, AWS IAM, AWS SSO, Amazon Cognito, and Amazon EventBridge
If interested in private offers, email us at partnercircle@oneidentity.com .
Highlights
- SSO: Automatically sync users across multiple directories in minutes to enable one-click access to all corporate applications, whether on-prem or in the cloud, and enforce strong security policies, plus self-service password reset.
- MULTI-FACTOR AUTHENTICATION (MFA): Supports many authentication methods, including passwordless, passkeys, one-time passcodes, push notifications, biometric data, security keys and more. With real-time reporting and monitoring capabilities, gain insights into authentication events, enabling proactive detection and response to potential security incidents.
- ADVANCED DIRECTORY: Acts as your secure directory in the cloud with an intuitive web-based interface that allows you to manage users, their manager relationship, authentication policies and access controls.
Details
Introducing multi-product solutions
You can now purchase comprehensive solutions tailored to use cases and industries.
Features and programs
Buyer guide

Financing for AWS Marketplace purchases
Pricing
Free trial
Dimension | Description | Cost/12 months |
|---|---|---|
OneLogin 1-App Plan | Standard User License, OneLogin 1-App Plan for AWS | $12.00 |
OneLogin Advanced Plan | Standard User License, OneLogin Advanced Plan | $48.00 |
OneLogin Professional Plan | Standard User License, OneLogin Professional Plan | $96.00 |
Custom | Private offers available - email partners@onelogin.com | $96.00 |
Vendor refund policy
Please refer to OneLogin terms of service https://www.onelogin.com/terms
How can we make this page better?
Legal
Vendor terms and conditions
Content disclaimer
Delivery details
Software as a Service (SaaS)
SaaS delivers cloud-based software applications directly to customers over the internet. You can access these applications through a subscription model. You will pay recurring monthly usage fees through your AWS bill, while AWS handles deployment and infrastructure management, ensuring scalability, reliability, and seamless integration with other AWS services.
Support
Vendor support
To learn more about OneLogin Customer Support, visit
AWS infrastructure support
AWS Support is a one-on-one, fast-response support channel that is staffed 24x7x365 with experienced and technical support engineers. The service helps customers of all sizes and technical abilities to successfully utilize the products and features provided by Amazon Web Services.

Standard contract
Customer reviews
Privileged access has been centralized and automation reduces audit and onboarding effort
What is our primary use case?
OneLogin by One Identity is being used as a PAM solution managing approximately 20,000 machines, with 60% being VMs and 40% being cloud-based access management. OneLogin by One Identity is also used for monitoring purposes with two devices deployed: one for session management and another for security management. Both devices provide strong privileged access management capability, including password vaulting, session monitoring, session recording, and session access for all users accessing the system. Reports can be generated whenever required.
An extra server takes backups from the sessions, and sessions that are not stored in OneLogin by One Identity are stored locally as history when long-term retention is needed. The integration of phishing-resistant device trust through OneLogin by One Identity has positively impacted authentication processes by helping identify phishing users effectively since awareness of who will access the system is maintained.
What is most valuable?
The standout features of OneLogin by One Identity include session monitoring, which provides access for the last year to see who accessed the system, what happened, and what commands they ran. If something happens with a Linux machine, potential attacks or issues can be investigated. For network-wide issues, monitoring and session recording can be reviewed and compared. A comprehensive audit trail can be generated and the kind of compliance desired on security investigations can be applied. Automated password rotation and role-based access are supported. For cloud monitoring, SCIM provisioning is used, and the system is authenticated through Azure, now Entra, by role-based access.
What needs improvement?
For large enterprise organizations that are also vendors for clients with differing requirements, all built-in features are considered, but sometimes new features based on client requirements need to be inbuilt. Customizing OneLogin by One Identity could be improved with processes to implement new features quickly without having to wait for months. For example, token-based access was needed, and implementing token-based or SCIM provisioning features took time. Reducing the time window for implementing custom solutions would enhance the product.
Documentation-wise, OneLogin by One Identity is one of the best found for any product, so there are no concerns there. Support-wise, OneLogin by One Identity is doing a great job. Support and management, including contacting OneLogin by One Identity for issues, are always straightforward.
For how long have I used the solution?
OneLogin by One Identity has been in use for the last four years with no concerns.
What do I think about the stability of the solution?
OneLogin by One Identity is very stable. Whenever problems are encountered, quick responses are received from OneLogin by One Identity's support team.
What do I think about the scalability of the solution?
Regarding scalability, if more resources are needed to manage clients and machines, resources can be easily scaled. The black box machine can be attached as required; currently, five are used for session management and five for password rotation. As many as needed can be added depending on the resources required to support the cluster. Scaling is very easy and can be done at any time.
How are customer service and support?
OneLogin by One Identity's support team is doing a great job, which is why the product has been used for the last four and a half years. Support and management, including contacting OneLogin by One Identity for issues, are always straightforward. Whenever problems are encountered, quick responses are received from OneLogin by One Identity's support team.
Which solution did I use previously and why did I switch?
CyberArk was previously used before switching to OneLogin by One Identity. After conversations with both sales teams, the sales pitch of OneLogin by One Identity stood out compared to CyberArk. OneLogin by One Identity was found to be a better solution in cost and resource management, which is why the switch was made.
How was the initial setup?
OneLogin by One Identity was deployed four years ago and is continuously being used with no issues. Currently, over 20,000 VMs and cloud environments are managed by OneLogin by One Identity. A cluster-based deployment is used, geo-redundant across three sites. It took one and a half months to build the lab environment. Once all problems and requirements for the environment setup were identified, the production deployment took around one month.
Since OneLogin by One Identity was implemented, a transition occurred from the old version, which was the TPAM solution. OneLogin by One Identity acquired that particular solution, and the transition was made to OneLogin by One Identity access management. This transition gave the capability to monitor, conduct comprehensive audits, and manage all resources easily whenever needed. Access control for admin personnel is very easy, and access can be managed. Whenever a system is required to be removed from the sync or out of the cluster, it is straightforward to remove from OneLogin by One Identity's Safeguard. The earlier PAM solution was quite difficult to set up, and this one has API Swagger development, making it easy to communicate. Whenever audits are needed, the REST API can be called, which is the biggest advantage.
What about the implementation team?
Once all problems and requirements for the environment setup were identified, the production deployment took around one month. In terms of return on investment, significant savings are being made. After implementation, fewer engineers in the team were needed to manage OneLogin by One Identity. Onboarding is automated, so there is no need to worry about the onboarding process, and using REST API calls for access management simplifies automation.
What was our ROI?
Significant savings are being made in terms of return on investment. After implementation, fewer engineers in the team were needed to manage OneLogin by One Identity. Onboarding is automated, so there is no need to worry about the onboarding process, and using REST API calls for access management simplifies automation. OneLogin by One Identity's Safeguard detailed Swagger build is quite helpful. Implementation time has been cut by 60 to 70%, and the number of people required for management has decreased by at least 60 to 70%. Once architecture is defined and deployed in the cluster, scaling becomes easy, and integration is straightforward for adding new systems.
What's my experience with pricing, setup cost, and licensing?
Regarding pricing, setup costs, and licensing, the virtual licensing option is suitable for small or midsize organizations. The black box developed by OneLogin by One Identity is not costly concerning the security features being provided.
Which other solutions did I evaluate?
Multiple options were evaluated before choosing OneLogin by One Identity, with CyberArk being one of them.
What other advice do I have?
My advice for others considering OneLogin by One Identity is that if a solution is needed that can scale easily in the future and currently does not manage many users and machines, OneLogin by One Identity can be chosen. If monitoring capabilities and session recording are needed, OneLogin by One Identity is one of the best solutions to recommend based on experience.
OneLogin by One Identity is a well-designed and impressive product. Even with the new AI features, it will change how security is implemented with policies, offering admins options to implement changes. If new features are needed, OneLogin by One Identity's Safeguard is always ready to help with implementation and provide those solutions. As a user, the user identity synchronization across directories functionality is really valuable to have.
The AI features in OneLogin by One Identity are new, so many components have not been implemented yet. Just started looking into the agent and its available AI functionality, so it cannot be fully assessed at this time. However, given the way the product is built and its architecture, it should be 100% useful for users.
The overall review rating for OneLogin by One Identity is ten out of ten.
Centralized identity has simplified secure access while reporting and admin controls still need improvement
What is our primary use case?
My main use case for OneLogin by One Identity is securing the digital identities of employees for organizations, enabling better access management, better authentication, active directory management, and SSO purposes.
A quick, specific example of how I use OneLogin by One Identity in my daily work is that we use it for access management. For example, if an employee is in the sales department, only the applications needed for that employee are assigned to them. No other extra applications are assigned to that employee. This is how we use it for access management.
How has it helped my organization?
Single sign-on has reduced password-related support requests, while automated provisioning and de-provisioning have significantly reduced the time required to onboard and offboard users. Adaptive MFA has strengthened our security posture without creating unnecessary friction for end users. Since implementing OneLogin by One Identity, we have seen faster user onboarding, fewer access-related support tickets, and improved consistency in enforcing access policies. The centralized management of identities has also simplified administration and helped us maintain compliance more effectively.
Since implementing OneLogin by One Identity, we have reduced user onboarding time by approximately 60 to 70 percent through automated provisioning. Password-related support tickets have decreased by around 40 to 50 percent due to single sign-on, and automated de-provisioning has helped us ensure users lose access immediately upon leaving the organization, improving both security and compliance.
What is most valuable?
OneLogin by One Identity offers excellent features including single sign-on, the smart factor, automated user provisioning and de-provisioning, and directory integration. It has a very large application catalog that can be integrated for passwordless login. Role-based access control is really helpful for compliance and reporting. Three features that most customers talk about OneLogin by One Identity are its single sign-on capabilities. For example, after logging in once, employees can access Salesforce, Microsoft 365, Slack, Jira, Zoom, and Workday. The benefits are faster access, fewer passwords, and fewer password reset tickets. The second feature is adaptive MFA. OneLogin by One Identity differentiates itself from basic MFA by not asking for MFA every time. When employees log in from the office on a trusted laptop, there is no MFA challenge. However, when the same employee logs in from another country on an unknown device, MFA is required. This really improves both security and user experience. The third is identity lifecycle management. OneLogin by One Identity automates the entire employee lifecycle. For example, when HR hires a new employee and creates the employee in Workday, OneLogin by One Identity automatically creates the AD account, provisions Microsoft 365, assigns Salesforce, grants Slack access, assigns the correct groups, and significantly reduces security risks.
Out of those features, the large app catalog, adaptive authentication, and identity lifecycle management, the biggest strength is combining single sign-on, adaptive MFA, and automated lifecycle management into a single platform that makes access both secure and simple. These three capabilities are generally considered core differentiators and are the features most organizations adopt first before expanding into broader identity governance.
OneLogin by One Identity provides a strong combination of SSO, adaptive MFA, and automated user provisioning, making identity management much simpler.
What needs improvement?
One area for improvement would be providing more granular reporting and analytics along with an even more intuitive administration interface for managing large-scale deployments.
I would like to see OneLogin by One Identity have more AI-driven capabilities such as risk-based access recommendations, anomaly detection, and predictive insights for identity threats. More granular dashboards and real-time compliance reporting would also add significant value for security teams.
One area for improvement would be in enhancing the admin experience for large-scale environments. Features such as more customizable dashboards, richer reporting with easier export options, and more granular audit logs would help administrators gain better visibility into user activity. Additionally, SaaS applications would make day-to-day administration even more efficient.
For how long have I used the solution?
I have been working in this field for the last one and a half years, and it is truly very interesting.
I have been using OneLogin by One Identity for the last one and a half years.
What other advice do I have?
I would rate OneLogin by One Identity at around a seven or eight because of its ease of use and its very good access management and SSO capabilities. I chose that number, seven or eight, because of its ease of use. It is very user-friendly and very easy to use. It has very good capabilities for managing SSO due to its application catalog. Directory integration is also very easy, and the security features are very good.
Regarding OneLogin by One Identity's AI capabilities, it currently leverages AI through its Vigilance AI engine. It drives features including smart MFA, and instead of relying on static, rigid access rules, it uses machine learning to analyze user behavior, location, and device context to assign risk scores in real time.
When evaluating OneLogin by One Identity's Vigilance AI from an operational perspective, accuracy and reliability come down to how machine learning evaluates risk scores in real time without causing friction or creating security blind spots. The accuracy of the risk scoring is achieved through Vigilance AI continuously calculating risk by comparing real-time login parameters such as IP reputation data, device fingerprint, and geographic velocity against a baseline of historical user behavior. It has a low false positive rate. In practice, the scoring engine is conservative enough to avoid nuisance MFA prompts for legitimate users operating within standard patterns. Edge case limitations exist where accuracy can dip slightly during sudden infrastructure shifts such as an organization rolling out a new corporate VPN or when users travel across regions with aggressive IP dynamic changes. In these cases, the AI initially flags normal traffic as high risk until the baseline recalibrates.
I purchased OneLogin by One Identity through the AWS Marketplace, and SmartFactor Authentication is immensely effective at this balancing act. When a user establishes a normal behavior pattern, the risk score remains low. The system can suppress multifactor authentication requirements to provide a frictionless login experience. It only introduces friction such as prompting for a password or denying access entirely when the risk score spikes due to anomalous behavior. This adaptive approach drastically reduces MFA fatigue for end users, which aligns with the goal of creating simplified, humanized cybersecurity experiences for non-technical audiences.
My overall rating for OneLogin by One Identity is seven out of ten.
Which deployment model are you using for this solution?
If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?
Centralized logins have improved security and support quick compliance-ready authentication
What is our primary use case?
I use OneLogin by One Identity for all logins, centralizing login access and adding more security to the system.
What is most valuable?
What I appreciate most about OneLogin by One Identity is that both single sign-on and multi-factor authentication help bring more security, which assists with compliance requirements.
The Smart Factor Authentication of OneLogin by One Identity stands out to me because it supports adjusting authentication flows in real time depending on the risk score associated with the login attempt. We check the servers and login attempts, then use Smart Factor Authentication to prevent unauthorized access when we detect potential risks.
OneLogin by One Identity provides a seamless end-user experience for signing in and authenticating to needed applications that is very quick and brings usability while maintaining security at the same time.
The single sign-on feature of OneLogin by One Identity is amazing. We compared this feature specifically while we were piloting, and comparatively, this is better than other players in the market. I know about Ping Identity and Okta, but we chose OneLogin by One Identity.
What needs improvement?
What I dislike about OneLogin by One Identity is that there have been some instances where the team experienced server issues while trying to log in. Users were unable to log in and had to redo the process. The server issues caused the system to keep loading, forcing users to go back and try again.
For how long have I used the solution?
I have been using OneLogin by One Identity for approximately 11 months to one year.
What do I think about the stability of the solution?
OneLogin by One Identity experiences certain downtimes, but the server issues I mentioned are the only stability concerns. Other than that, it is stable.
What do I think about the scalability of the solution?
OneLogin by One Identity is highly scalable and can be scaled multifold at any time.
How are customer service and support?
I have not contacted the technical support or customer support for OneLogin by One Identity directly, nor have I interacted with them. However, I have seen some emails from their support team, and they appear to be good. We discuss support internally, and we are satisfied with it.
Which solution did I use previously and why did I switch?
I have worked with Ping Identity as an alternative to OneLogin by One Identity in my previous organization. In my current organization, we were trying Okta.
How was the initial setup?
The initial deployment of OneLogin by One Identity was acceptable. It was neither easy nor difficult, but it was doable. It took approximately four weeks to fully set up OneLogin by One Identity, completing all training for the team.
What about the implementation team?
For the deployment of OneLogin by One Identity, we had a dedicated team that divided KRAs accordingly. The initial pilot and training team consisted of four members.
What was our ROI?
After the deployment of OneLogin by One Identity, it does require maintenance on our end. Two staff members maintain the system because employees do face issues and need to flag them. Although this reduced the login issues and tickets that came in initially, the IT support team, specifically two people, work on this alongside other software to solve issues related to logins.
What's my experience with pricing, setup cost, and licensing?
OneLogin by One Identity is way cheaper than Okta, which is all I know to compare. Cost was one of the reasons we went ahead with this solution. We initially ran a free trial pilot, which worked out for our team, and then we purchased licenses.
Which other solutions did I evaluate?
If I compare OneLogin by One Identity with Okta, OneLogin by One Identity is way better. The server issues we faced with Okta are not present with OneLogin by One Identity. Licensing-wise, OneLogin by One Identity is cheaper, which helps significantly.
What other advice do I have?
I am aware of the adaptive login flows with Vigilance AI in OneLogin by One Identity, but I do not have any feedback or thoughts on that at this time. My overall review rating for OneLogin by One Identity is 8 out of 10.
Single sign-on has simplified daily access and now provides secure centralized user management
What is our primary use case?
We have been using OneLogin by One Identity for one and a half years for the primary use case of SSO for enterprise applications that we have, along with MFA that is used for secure user access and centralized identity and access management, followed by secure remote access for employees, integration with AD, and cloud-based applications.
What is most valuable?
The main feature of OneLogin by One Identity is SSO that makes it seamless for end users while reducing password fatigue, followed by MFA authentication, which addresses an extra layer for security without introducing excessive complexity.
OneLogin by One Identity provides a seamless end-user experience for signing into applications, particularly where the feature makes access seamless for the end user by reducing password fatigue. In this scenario, while logging into multiple applications, you just have to log in once, utilizing the password for it, making it really seamlessly accessible to multiple applications via the same browser.
What needs improvement?
We are using multiple SSO tools for our management team, but based on the comparison with the earlier used products, it would be better to have customized options for the dashboards that will include a dashboard for the usage of user accounts that can be added to it, providing better visibility along with some granular reporting and analytics for authentication trends.
Enhanced API documentation with additional implementation examples will be helpful, as in our scenario, we have not utilized that particular portion that much. The suggestion for improvement is that OneLogin by One Identity should have enhanced API documentation for better additional implementation in our environment.
For how long have I used the solution?
I have been using this product for one and a half years in my career.
What do I think about the stability of the solution?
OneLogin by One Identity is really stable, and in the scenarios that we have encountered, it has been very stable with no delays or extended maintenance windows. We have not faced any such issues.
What do I think about the scalability of the solution?
The scalability of OneLogin by One Identity is highly effective because it can comfortably support organizations ranging from small businesses to large enterprises with thousands of users. Adding new user applications or authentication policies is straightforward without requiring significant infrastructure changes, making it more scalable.
How are customer service and support?
Our IT team might help us, but directly as an end user, I have not reached out to support.
Which solution did I use previously and why did I switch?
Compared to Okta, which we used earlier and which provided limited solutions, OneLogin by One Identity helps us in SSO and MFA. Additionally, the parameters that it provides, such as centralized identity and access management along with user lifecycle management, which we miss in competitors like Okta, as well as secure remote access and integration with AD and cloud-based applications, serve as the main differentiators that lead me to rate this application highly.
How was the initial setup?
The initial deployment of OneLogin by One Identity was not much complicated. We cannot say it is easy, but with the help of our IT team, it was easier, and there were no complications.
The integration with third-party authentication providers was complicated internally, but since our IT team is very knowledgeable about integrating those portals, we did not require an external implementation partner or support from OneIdentity, so it was not much complicated. It was hard at the initial level, but once we referred to the available guide, it became easy.
What about the implementation team?
One individual is enough to manage this. We have an organization of two hundred fifty people, and while managing it, that one person was sufficient.
Which other solutions did I evaluate?
We cannot say that we have particularly used any alternative, but for authentication, we use AD authentication and regular MFA with solutions such as Okta, which is the first type of application we have.
What other advice do I have?
I have not gone through the aspect of smart factor authentication to adjust authentication flows in real time depending on the risk score.
As an end user, I am not aware of the pricing for OneLogin by One Identity.
I use the single sign-on feature provided by OneLogin by One Identity, which is the purpose I mentioned already.
OneLogin by One Identity does not require much maintenance. Sometimes there is a bit of delay, but I did not solve it with the help of support, so there was no maintenance required in that particular duration.
I would rate this review a nine out of ten.
Unified sign-on has simplified workforce access and now secures passwords across all SaaS tools
What is our primary use case?
What is most valuable?
Password vaulting is also a very useful feature for us because it helps to secure passwords. The benefits include improved productivity. OneLogin by One Identity eliminates password fatigue, as employees no longer have to remember different passwords for various SaaS tools.
We have multiple SaaS solutions, and users were having multiple passwords and multiple user IDs. OneLogin by One Identity reduced that to just one click, and the SaaS tool is logged in and ready to use. It is useful that users no longer need to remember or update their passwords, as it is completely managed by OneLogin by One Identity.
What needs improvement?
When looking specifically at OneLogin by One Identity's AI capabilities, the consensus is very strong on security, while governance is effective but relies on broader platform integration to truly shine. First, the security aspect is exceptional and proactive. Second, governance is strong but requires leveraging the broader One Identity fabric. Third, overall, the security aspect of OneLogin by One Identity's AI is seamless and top-tier, balancing robust protection with a frictionless user experience. The governance piece is excellent if you leverage the unified One Identity platform, though managing deep governance policies natively inside the standalone OneLogin by One Identity admin dashboard can feel a bit segmented.
Its accuracy is high, particularly in risk scoring and anomaly detection. The primary output of OneLogin by One Identity's AI is a real-time risk score calculated during login attempts. Its accuracy is highly dependable because it evaluates explicitly measurable data vectors. Additionally, the reliability in automated enforcement is essential because the AI output triggers automated security policies, such as forcing an MFA prompt or blocking access, making operational reliability critical.