Skip to main content

Overview

The OneLogin integration enables ThreatAware to connect with your OneLogin identity platform to collect authentication and access management data, helping you validate identity controls and monitor access patterns across your organisation.
Connection Method: API Setup Time: 10 minutes Access Required: OneLogin Administrator account

Data collected

The OneLogin integration provides:
  • User authentication events
  • Access management policies
  • Identity security indicators
  • MFA and authentication data

Use cases

Identity Monitoring

Track authentication patterns and user access events

Access Validation

Verify identity controls are properly configured

Security Compliance

Monitor identity-based security controls for compliance

Audit Support

Generate reports on authentication and access management

Setup instructions

1

Log in to ThreatAware

Navigate to your ThreatAware dashboard and go to Settings → Integrations.
2

Find and Connect OneLogin

  • Use the search bar to locate OneLogin
  • Click Connect - a pop-up window will appear with configuration options
3

Determine Your API Region

  • OneLogin operates multiple API regions such as api.eu.onelogin.com
  • Contact OneLogin Support to confirm your organisation’s API region
  • Note the region for the next steps in ThreatAware
4

Generate API Credentials

  • Log in to your OneLogin Admin console
  • Click Developers in the top navigation bar
  • Go to the API Credentials page
  • Click the New Credential button
  • Provide a suitable name (e.g., “ThreatAware Integration”)
  • Select Manage all for permissions
  • Click Save
  • Copy the Client ID and Client Secret that are displayed
  • Click Done
5

Configure in ThreatAware

In the ThreatAware pop-up window, enter:
  • Client ID: The Client ID from OneLogin
  • Client Secret: The Client Secret from OneLogin
  • API Region: The API region (e.g., api.eu.onelogin.com)
  • Click Authorize to establish the connection
6

Verify Connection

  • Check the systems list to verify OneLogin status shows as Active
  • Data collection will begin within 1 hour
  • Monitor the integration status in Settings → Integrations

Required credentials

Field Name: OneLogin Client ID Type: String Description: The unique identifier for your OneLogin API applicationThis is generated in the OneLogin Admin console under API Credentials.
Field Name: OneLogin Client Secret Type: Password (encrypted) Description: The secret key used to authenticate API requests to OneLogin
Store this credential securely in your organisation’s password manager for future reference.
Field Name: OneLogin API Region Type: String Description: The regional API endpoint for your OneLogin instanceExamples:
  • api.eu.onelogin.com (Europe)
  • api.us.onelogin.com (United States)
  • Contact OneLogin Support to confirm your region

Verification and testing

After setup, verify the integration is working correctly:
  1. Check Integration Status
    • Navigate to Settings → Integrations in ThreatAware
    • Confirm OneLogin shows Active status
    • Check the last sync timestamp
  2. Verify Data Collection
    • Wait 60 minutes for the initial data poll
    • Check for OneLogin events in your device or user records
  3. Test Queries
    • Create a test query to filter data by OneLogin authentication events
    • Verify the data matches your expectations

Troubleshooting

Symptoms: Integration status shows authentication failureSolutions:
  • Verify the Client ID and Client Secret are correct
  • Ensure credentials were copied completely without extra spaces
  • Check that the credentials have not expired in OneLogin
  • Verify the API Region is correct for your OneLogin instance
Symptoms: Integration fails when validating the API regionSolutions:
  • Contact OneLogin Support to confirm your organisation’s API region
  • Verify the region format (e.g., api.eu.onelogin.com)
  • Check that the region is accessible from ThreatAware infrastructure
Symptoms: Integration connects but fails to retrieve dataSolutions:
  • Verify the API credentials were created with Manage all permissions
  • Check that the OneLogin account has not been revoked or disabled
  • Ensure the API credentials have not expired
  • Regenerate credentials if needed and update ThreatAware
Symptoms: Integration shows active but no data appearsSolutions:
  • Verify there is authentication data in OneLogin to collect
  • Check API rate limits haven’t been exceeded
  • Review ThreatAware integration logs (contact support if needed)
  • Confirm the connection status remains Active

Additional resources

OneLogin API Documentation

Official OneLogin API documentation for detailed setup and permissions

ThreatAware Support

Contact ThreatAware support for integration assistance

Best practices

API Credential Security
  • Create a dedicated API credential for ThreatAware integration
  • Store credentials securely in your organisation’s password manager
  • Rotate API credentials annually or per your security policy
  • Monitor OneLogin logs for API usage activity
Integration Maintenance
  • Regularly verify the integration status remains active
  • Test the connection periodically to ensure uninterrupted data flow
  • Review OneLogin audit logs for any suspicious API activity
  • Keep credentials updated if OneLogin access policies change