My main use case for OneLogin is to complete compliance checks, as I use it to detect if there are issues in ISO 27001, SOX, HIPAA, or GDPR.
A few months ago, I had a client that was a hospital for oncologies, and I had to use some AWS services to store data. I needed to check if it was compliant with GDPR.
I also use OneLogin to detect anomalous behaviors in real time.
OneLogin offers several best features that include helping me audit who accessed the system, when, and what they did. It helps me detect anomalous behavior, and it also has a single sign-on that allows me to control these features.
Additionally, OneLogin has Vigilance AI and threat detection, which provides real-time threat detection that protects against credential-based attacks.
OneLogin has positively impacted my organization because it gives me audit logs and compliance, both of which are very important for many of my clients, especially for this oncology hospital.
I think OneLogin is good, but it would be better if it could provide a mobile app that includes specific features, for example, to check logs or compliance.
I have been using OneLogin for around two years.
OneLogin's scalability is very easy. I only need to follow a few wizards, and then I can scale up or down at any time I want.
I advise others looking into using OneLogin that it is very easy to use. I can deploy it in minutes, and playing with the functionalities can yield good results.
I believe there is time saved because I can generate reports in seconds or minutes, allowing me to detect all users and their devices. I don't have exact return on investment numbers since I don't manage that account directly, but I think my organization needs fewer employees and saves time.
From what I've heard, pricing is interesting as it's cheaper than other solutions. The setup cost and licensing are also inexpensive because I don't have to spend a lot to access all these functionalities, which would be more expensive with other providers.
I haven't evaluated other options before choosing OneLogin because it was already in use by my client, who explained that they utilized this solution, and I needed to adapt my development around it.
I think the user identity synchronization across directories functionality is very reliable and well-integrated. If I am running modern and cloud-first applications, it's very good, but if I am in a complex hybrid environment, I need to invest a bit more time to configure it.
The integration of phishing-resistant device trust has significantly reduced phishing attacks because I now have all devices registered from my users, requiring users to register new devices and unregister previous ones. I can't control everything, such as users clicking on suspicious emails, but this solution helps mitigate the problem.
I think the solution provides a very user-friendly experience for signing in and authenticating to needed applications. Nowadays, many users are accustomed to logging in with social networks, so they feel familiar with the process through this application.
I have used SmartFactor Authentication to adjust authentication flows in real time based on the risk score associated with the login attempt, and I find it very helpful. I first identify all the users entering the system, then I check all the devices, and then I start creating an entry system without rules, progressively adding more rules as I learn the user behavior.
I have not used the adaptive login flows with Vigilance AI, but I have seen a demo. The challenge I face is that I don't have access to a client that has implemented this. However, I heard it's spectacular because it shows real-time detection of spikes, regular behavior, and suspicious behavior, offering insights on how to control or mitigate risk.
HR-driven identity management plays a special role in streamlining employee identity handling in my organization because it helps identify all users and devices. Nowadays, users can have multiple devices such as smartwatches, iPods, iPads, and more.
My overall review rating for OneLogin is ten out of ten.
Good Description