Prior to downloading this Software, you must review the Software Transaction Agreement located here and confirm, by clicking the I agree check box below, that your organization accepts and is bound by the terms and conditions of the Software Transaction Agreement for this Software.
If you purchased the licenses for this Software by executing an order form with Quest or if you have an agreement with Quest that states that all purchases are governed by such agreement, then the terms and conditions of that agreement supersedes and takes precedence over the Software Transaction Agreement.
The Account Owner of a OneLogin tenant has exclusive access to account-level settings located the OneLogin admin portal under Settings > Account Settings. These options determine broadly-applied account policies that are unlikely to change frequently and should usually be configured during during your initial OneLogin setup.
User Policies User policies provide you and your organization with the best security requirements for your needs, by allowing you to choose specific security restrictions and protocols, then apply them to either individual users or to Groups. This article goes over how to configure and manage user policies. Related Documentation App PoliciesIntroduction to User ManagementAdding Multi-Factor Aut...
Deactivating a OneLogin Account This document walks OneLogin Account Owners through the process of deactivating their OneLogin account. Please note that deactivating your account is PERMANENT; theres is currently no method for undoing account deactivation. Prerequisites Access to the Account Owner account
OneLogin Protect for iOS is a mobile authenticator app that provides a one-time-password (OTP) as an additional authentication factor. Since you likely always have your phone nearby, it makes for an easy and convenient way to authenticate your account. OneLogin Protect is also available for Android. Prerequisites: A mobile device running iOS 11.0 or above
This article provides an overview of administrative privileges in OneLogin. The following topics are included. Prerequisites Only account owners and super users have the ability to grant privileges to other users.
Multi-factor authentication (MFA), also sometimes called two-factor authentication or 2FA, adds an extra layer of security to user accounts, drastically reducing the chances that bad actors can steal sensitive information. This guide gives a brief overview of how MFA works and walks you through the process of enabling authentication factors and assigning them to your users. Prerequisites ...
Whether you're using OneLogin internally or providing it to your customers, it's important to have control over your platform's appearance and create an environment that reflects the visual personality of your organization. Our powerful branding options allow you to customize your OneLogin tenant with the colors, icons, and messaging that make your brand unique, so that it gives your u...
For an organization whose users use many SAML applications, having multiple SAML certificates is a convenient and powerful way to ensure stronger security between those applications and OneLogin. Using multiple certificates also lets you gracefully handle the process of updating expiring certificates.To access your X.509 certificates, go to Security > Certificates. All certificates used by your...
This article covers the following topics:About rolesCreating rolesAdding users to roles manuallyAdding users to roles automatically using mappingsDelegating role management
OneLogin Protect for Android is a mobile authenticator app that provides a one-time-password (OTP) as an additional authentication factor. Since you likely always have your phone nearby, it makes for an easy and convenient way to authenticate your account. OneLogin Protect is also available for iOS. Prerequisites: A mobile device running Android 5.0 (Lollipop) or above Update: As of April, 2023 ...
This document details how to install and uninstall OneLogin Desktop for the macOS. This document is intended for Admins. The End-User Installation Guide is found here. The latest version of OneLogin Desktop (3.2.2) is compatible with the following macOS versions: Ventura (13.x.x)Monterey (12.x.x)Big Sur (11.x.x) Earlier versions of OneLogin Desktop are not compatible with macOS Monterey or later. ...
OneLogin's trusted identity provider (TIdP) feature enables you to configure multiple identity providers to securely sign users into OneLogin and OneLogin-protected applications. This guide walks you through how to create and configure TIdPs for your OneLogin tenant. This feature requires a OneLogin subscription that includes Advanced Directory. Speak with your account representative for more ...
Installing & Configuring Active Directory Connector 5 OneLogin's Active Directory Connector (ADC) is the perfect tool for companies that use Microsoft Active Directory as a domain controller (DC). Active Directory Connector 5 provides significant performance improvements, firewall-friendliness, and support for HTTP proxy servers. If your HTTP proxy server requires authentication, ADC 5 ...
Introduction Many network appliances can be configured to use a RADIUS server for user authentication. For example, when a user establishes an IPsec VPN using their desktop VPN client, the network appliance can send an Access-Request to a RADIUS server, which authenticates the entered credentials against a user store. OneLogin provides a RADIUS interface that processes RADIUS authentication reques...
OneLogin can sign users into applications using various mechanisms, of which the most robust and secure is SAML. SAML works in all browsers, but unfortunately not all applications support SAML. As an alternative, OneLogin can use "form-based authentication" to inject user credentials into an application's login page to log the user in. Sometimes this can be done with a simple HTTP PO...
OneLogin Domains and IP addressesWe have updated the list of IP addresses we recommend organizations explicitly allow for outbound traffic coming from our on-premises agents such as Active Directory Connectors, LDAP Connectors, Proxy Agents as well as other applications provisioned by OneLogin.
Note: The SAML Custom Connector (Advanced) is the new name for the SAML Test Connector (Advanced) there is no need for those using SAML Test Connector (Advanced) to migrate to the SAML Custom Connector (Advanced).The OneLogin SAML Custom Connector (Advanced) allows you to build a custom application connector for applications that are unavailable in the OneLogin catalog, e.g. internally developed a...
This topic describes how to configure OneLogin as the federation service that provides SSO for Office 365.For more information about how OneLogin works with Office 365, see Introduction To Office 365 Integration With OneLogin or watch the video training below.
When logging into SPP the first time with a user that has OneLogin MFA enabled as secondary authentication, the first login attempt fails with the following error: A system error occurred and has been logged. Please try again later or contact your administrator. Trying to login again a second time works successfully. RSTS logs show the following: [TimeStamp] [D] OneLogin API request error. Cleari...