Overview
The OneLogin integration enables ThreatAware to connect with your OneLogin identity platform to collect authentication and access management data, helping you validate identity controls and monitor access patterns across your organisation.Connection Method: API
Setup Time: 10 minutes
Access Required: OneLogin Administrator account
Data collected
The OneLogin integration provides:- User authentication events
- Access management policies
- Identity security indicators
- MFA and authentication data
Use cases
Identity Monitoring
Track authentication patterns and user access events
Access Validation
Verify identity controls are properly configured
Security Compliance
Monitor identity-based security controls for compliance
Audit Support
Generate reports on authentication and access management
Setup instructions
1
Log in to ThreatAware
Navigate to your ThreatAware dashboard and go to Settings → Integrations.
2
Find and Connect OneLogin
- Use the search bar to locate OneLogin
- Click Connect - a pop-up window will appear with configuration options
3
Determine Your API Region
- OneLogin operates multiple API regions such as
api.eu.onelogin.com - Contact OneLogin Support to confirm your organisation’s API region
- Note the region for the next steps in ThreatAware
4
Generate API Credentials
- Log in to your OneLogin Admin console
- Click Developers in the top navigation bar
- Go to the API Credentials page
- Click the New Credential button
- Provide a suitable name (e.g., “ThreatAware Integration”)
- Select Manage all for permissions
- Click Save
- Copy the Client ID and Client Secret that are displayed
- Click Done
5
Configure in ThreatAware
In the ThreatAware pop-up window, enter:
- Client ID: The Client ID from OneLogin
- Client Secret: The Client Secret from OneLogin
- API Region: The API region (e.g.,
api.eu.onelogin.com) - Click Authorize to establish the connection
6
Verify Connection
- Check the systems list to verify OneLogin status shows as Active
- Data collection will begin within 1 hour
- Monitor the integration status in Settings → Integrations
Required credentials
Client ID
Client ID
Field Name: OneLogin Client ID
Type: String
Description: The unique identifier for your OneLogin API applicationThis is generated in the OneLogin Admin console under API Credentials.
Client Secret
Client Secret
Field Name: OneLogin Client Secret
Type: Password (encrypted)
Description: The secret key used to authenticate API requests to OneLogin
API Region
API Region
Field Name: OneLogin API Region
Type: String
Description: The regional API endpoint for your OneLogin instanceExamples:
api.eu.onelogin.com(Europe)api.us.onelogin.com(United States)- Contact OneLogin Support to confirm your region
Verification and testing
After setup, verify the integration is working correctly:-
Check Integration Status
- Navigate to Settings → Integrations in ThreatAware
- Confirm OneLogin shows Active status
- Check the last sync timestamp
-
Verify Data Collection
- Wait 60 minutes for the initial data poll
- Check for OneLogin events in your device or user records
-
Test Queries
- Create a test query to filter data by OneLogin authentication events
- Verify the data matches your expectations
Troubleshooting
Invalid Credentials Error
Invalid Credentials Error
Symptoms: Integration status shows authentication failureSolutions:
- Verify the Client ID and Client Secret are correct
- Ensure credentials were copied completely without extra spaces
- Check that the credentials have not expired in OneLogin
- Verify the API Region is correct for your OneLogin instance
API Region Not Found
API Region Not Found
Symptoms: Integration fails when validating the API regionSolutions:
- Contact OneLogin Support to confirm your organisation’s API region
- Verify the region format (e.g.,
api.eu.onelogin.com) - Check that the region is accessible from ThreatAware infrastructure
Permission Denied
Permission Denied
Symptoms: Integration connects but fails to retrieve dataSolutions:
- Verify the API credentials were created with Manage all permissions
- Check that the OneLogin account has not been revoked or disabled
- Ensure the API credentials have not expired
- Regenerate credentials if needed and update ThreatAware
No Data After 1 Hour
No Data After 1 Hour
Symptoms: Integration shows active but no data appearsSolutions:
- Verify there is authentication data in OneLogin to collect
- Check API rate limits haven’t been exceeded
- Review ThreatAware integration logs (contact support if needed)
- Confirm the connection status remains Active
Additional resources
OneLogin API Documentation
Official OneLogin API documentation for detailed setup and permissions
ThreatAware Support
Contact ThreatAware support for integration assistance