Vendors › Identity & Access Management › OneLogin (Unified Access Management)
OneLogin (Unified Access Management)
OneLogin (One Identity)
Combined score
Security incident on record — February 2022 — attacker accessed OneLogin database for approximately 3 months before detection
▪ Editorial verdict
OneLogin covers the standard IAM requirements - SSO, MFA, and basic lifecycle management - at a price point below the market leaders. For mid-market organisations that need functional IAM without the complexity or cost of Okta or Microsoft, it covers the essentials adequately.
The February 2022 breach, where an attacker had undetected access to production systems for three months, is the central buyer concern. The breach exposed both customer data and the authentication system itself. OneLogin has made improvements since, but the incident track record is a material consideration when evaluating an identity platform.
The verdict: the breach history makes OneLogin difficult to recommend over alternatives with clean security records. Organisations evaluating mid-market IAM should compare JumpCloud and Cisco Duo as alternatives with comparable functionality and better security track records.
Last reviewed: May 2026
G2
Gartner
PeerSpot
Identity & Access Management assessment
Strongest: Authentication strength
Watch out for: Scale & reliability
Strengths & limitations
Strengths
Watch out for
Best for
Budget-conscious mid-market organisations wanting Okta-like SSO/MFA at lower cost — evaluate 2022 breach history before purchasing.
Not suitable for: Security-sensitive orgs — 2022 breach had 3-month undetected access
Compliance coverage
Switching intelligence
Switching from
Common migration paths based on review data
- Active Directory (cloud)
- ADFS