TECHNOLOGIES: ONELOGIN

OneLogin Security Review

A OneLogin mapping can grant a role automatically, but the change only applies once a user record updates or mappings are reapplied. We test what your credential scopes, mappings and policies enforce. CREST-certified testers, fixed price from £3,290 for a 2-day single-tenant scope, quoted within 24 hours.

  • Unlimited retesting
  • Unlimited pre-retesting
  • No hidden fees
Accredited & recognised
Cyber Essentials certified Cyber Essentials Plus certified IASME certifying body ISO 27001 certified ISO 9001 certified Crown Commercial Service supplier UK Cyber Security Council member
CREST
Approved Provider
10
OneLogin Test Areas
FREE
Retest Until Closed
24h
Scope to Active Test
CLIENT REFERENCE
“I would highly recommend EJN Labs to any organisation seeking reliable, detailed, and well-managed penetration testing services, particularly for government or enterprise-level projects.”
SquareOneImran SaghirProject Lead, SquareOneRead the SquareOne case study →
CLIENT REFERENCE
“There wasn’t another company we could find that could deliver what we needed in the timeframe we needed. The client loved it, and we got instant ROI from the engagement.”
CelloriDan WilcocksonFounder, CelloriRead the Cellori case study →
See all case studies →
WHY IT MATTERS
Mappings

OneLogin mappings apply role, group and attribute changes automatically based on conditions such as Active Directory group membership. A mapping edited through the API is not retroactively applied to existing users until a user record changes or mappings are reapplied, so a tenant can be running on rules that no longer match what is configured.

Why OneLogin findings sit in mappings and policies, not the login screen

An API credential pair is created with one of five scopes, from Authentication Only through Read Users and Manage Users to Read All and Manage All, and the access token it generates is valid for 10 hours before it must be regenerated. We test which scope every credential pair in use actually holds against what the integration calling it needs, and whether an expired, disabled or deleted pair still works anywhere.

User mappings work as a condition and an action, for example granting a role when a user’s memberOf attribute matches a directory group, and OneLogin’s own documentation notes that a mapping change is not automatically applied to existing users until a user record is created or updated, or Reapply Mappings is run from the admin console. We test what every mapping currently does against what your team believes it does, and whether a user who should have lost access under a changed rule still has it.

The Security Policy resource applies to either users or apps, a setting fixed at creation, and carries the password, lockout and session-timeout rules a tenant relies on. Separately, OneLogin can act as an OAuth authorisation server for a business’s own APIs, issuing scoped access tokens to registered client apps. We test both: whether the policy actually applied to a user or app matches the one intended, and whether an OAuth scope registered for one client app is enforced against every client that requests it.

SCOPE

What we pen test on a OneLogin tenant

OL-01

API Credential Pair Scope

Every credential pair is created with one of five scopes, from Authentication Only up to Manage All. We test which scope each pair in active use actually holds against what it is called for.

OL-02

Access Token Lifetime and Revocation

An access token is valid for 10 hours, and a credential pair can be revoked, disabled or deleted. We test whether a disabled or deleted pair’s tokens genuinely stop working immediately, not just in the admin console.

OL-03

Mapping Conditions and Actions

A mapping grants a role, group or attribute change when a condition on a user attribute is met. We test the conditions and actions configured against who actually holds the access they grant.

OL-04

Mapping Reapplication Timing

A mapping change is not retroactively applied to existing users until a record updates or Reapply Mappings runs. We test for a user still holding access under a rule that has since changed.

OL-05

Security Policy Password and Lockout Settings

A user-kind Security Policy sets minimum password length, complexity level, reuse history and lockout thresholds. We test which policy actually applies to which users, since only one policy can be the account default.

OL-06

Session Timeout Configuration

A policy can set both an idle session timeout and a fixed maximum session duration. We test what a session actually allows in practice against what the policy defines.

OL-07

App-Kind Policies and SSO App Configuration

An app-kind Security Policy and each app’s own SAML or OIDC configuration decide who can reach it and how. We test app configuration for a setting that grants broader access than the app needs.

OL-08

API Authorization Server and OAuth Scopes

OneLogin can issue its own OAuth access tokens, scoped to a specific client app, for a business’s own APIs. We test whether a scope registered for one client app is actually enforced against every app that requests it.

OL-09

App Configuration Replication Gaps

OneLogin’s own documentation notes that replicating an app’s configuration through the API does not carry over its provisioning, roles or rules. We test a replicated or sandbox-to-production app for exactly that gap.

OL-10

Multi-Factor Authentication Enforcement

MFA can be required per policy or per app rather than tenant-wide. We test for a user, app or login path that falls outside the MFA requirement your policy is meant to enforce.

OUR PROCESS

OneLogin Security Review: From Scope to Attestation

01

Scope and Access

We agree the tenant boundary and you issue a scoped API credential pair and test accounts covering your different roles and mappings.

02

Tenant Testing

CREST-certified testers work through credential scopes, mappings, security policies and app configuration against the rows above.

03

Findings and Retest

Every finding is tied to a specific mapping, policy or credential, with a free retest once you have fixed it.

04

Report and Sign-off

You get a report ready for an auditor or your own security team, plus a fixed retest window until every finding is closed.

CREDENTIALS

Verified Accreditations Auditors Accept

Every credential below is independently verifiable. UK procurement teams, FCA supervisors, ISO 27001 / SOC 2 auditors, and cyber insurance underwriters all recognise these standards.

GET YOUR QUOTE

Get a CREST OneLogin pen test quote in 24 hours

A fixed-price quote back in one business day, from a named CREST assessor. No sales pipeline, no chasing.

  • CREST and IASME accredited. Testing your auditors and clients already recognise.
  • Fast-track testing within 24 hours where required. Free retest of every fix included.
  • Live findings via your client portal, not a four-week PDF.
  • Fixed price from £3,500 for a single-role, single-app scope, agreed up front. Most engagements run £5,000 and up. No day-rate surprises.
What clients say
There wasn’t another company we could find that could deliver what we needed in the timeframe we needed. The client loved it, and we got instant ROI from the engagement.
CelloriDan WilcocksonFounder, Cellori

Under NDA Further named references available on a scoping call.

What happens next
  1. We reply within one business day with a fixed-price quote from a named CREST assessor.
  2. You approve the scope and we book a start date, usually within 24 hours.
  3. Live findings land in your client portal as we test, with a free retest of every fix.
Accredited & recognised
CREST member Cyber Essentials certified Cyber Essentials Plus certified IASME certifying body ISO 27001 certified ISO 9001 certified UK Cyber Security Council Crown Commercial Service supplier

Get your fixed pen test quote in 24 hours

⚡24h reply ✓CREST tester ↻Free retests

or book a 20-min scoping call first

We reply within one business day. Your data stays with us. No newsletter signup.

COMPLIANCE READY

Reports Mapped to Every Framework

Findings are written so your team can reference the report against each framework without translation work.

ISO 27001:2022

Annex A.8.8 management of technical vulnerabilities plus A.5.15-5.18 and A.8.2-8.5 access control validation.

SOC 2 Type I & II

CC6 logical access, CC7 system operations, CC8 change management evidence.

PCI DSS

Requirement 11.4 application penetration testing across cardholder data environments, including ecommerce penetration testing for online retail platforms.

FCA SYSC

SYSC 4.1.1R, 6.1.1R, 13 mapped to each finding for FCA-regulated firms.

UK GDPR

Article 32 effectiveness testing, customer-data security controls, ICO-acceptable evidence.

Cyber Essentials Plus

Direct certification through our IASME body status, single-vendor delivery.

PRICING

Transparent OneLogin Security Review Pricing

Pricing depends on the number of roles, integrations and environments in scope. See our pricing page for how we quote.

✦ ALWAYS · ON EVERY TIER · NO EXCEPTIONS ✦
✓Free retests, no time limit
✓Free rescheduling
✓No cancellation fees
✓24-hour scope to active testing
✓Live findings to client portal
✓Executive + technical report
✓60-min walkthrough call
✓Letter of attestation
SMALL / SMB
£3,290–£4,840
2 to 3 testing days

Single user role, basic CRUD application, marketing website with auth. Around 5 working days from kickoff to report.

Get a fixed quote
ENTERPRISE
£7,730–£11,780
5 to 7 testing days

Multi-tenant platform, complex authorisation matrix, integration-heavy applications. Around 15 to 20 working days from kickoff to report.

Get a fixed quote

Full UK pen test cost guide

WHY EJN LABS

What You Get From OneLogin Security Review

Six concrete differentiators competitors don’t all match.

CREST-Certified Testers, Verifiable

Every test by a CREST-certified pen tester (CRT, CCT APP, CCT INF where applicable). Verify our company status at crest-approved.org.

24-Hour Startup, Where Required

From signed scope to active testing in a single business day for incident response, audit deadlines, or regulator-driven timelines.

Live Findings, Not 4-Week PDFs

Critical issues reported during testing through your client portal. Your team remediates while testing continues.

Audit-Ready Reports

Executive summary plus full technical report with CVSS scores and explicit framework mappings (ISO 27001, SOC 2, PCI DSS, FCA SYSC).

Free Retests, Standard

Verify remediation of every finding before close-out. Letter of attestation for audit submission included. Most competitors charge £1,500-£3,000 per retest.

UK-Based CREST Testers

Every engagement performed by vetted, UK-based CREST-certified testers, matched to your needs, security clearance, and compliance scope.

FAQ

Frequently Asked

What access do you need to test our OneLogin tenant?

A read-only admin account or an API credential pair scoped no higher than Read All, plus test accounts covering your different roles and mappings. We do not need Manage All access to complete most of the scope.

Does testing touch live employee or customer data?

We work with test or dummy accounts wherever your tenant allows it. Where a mapping or policy can only be verified against a real user, we agree the safest way to do that with you during scoping.

Do you test OneLogin’s own platform or our tenant?

Your tenant: the mappings, security policies, app configurations and API credentials you control. OneLogin’s own hosting and core service are not something we test.

What is out of scope?

OneLogin’s underlying infrastructure and any app you have connected but do not manage the configuration of. We agree the exact app and mapping list in scope before testing starts.

Does OneLogin have a vendor testing or disclosure policy?

We confirm OneLogin’s current terms for security testing directly with you during scoping, since these can change and we would rather quote you the current position than an out of date one.

How long does a OneLogin tenant review take?

A single tenant with a typical set of mappings and apps is usually a 2-day scope. A tenant with heavy custom OAuth API Authorization use or many mapping rules may need more, which we confirm during scoping.

Can you test our own OAuth apps registered through OneLogin?

Yes, if your business uses OneLogin’s API Authorization feature to issue OAuth tokens for its own APIs, the authorisation server, its scopes and the client apps registered against it are in scope.

Do you need our OneLogin admin credentials?

No. A credential pair created for the engagement, scoped to what we actually need to test, is enough and is easier for you to revoke afterwards.

EXPLORE EVERY SERVICE

20+ CREST-accredited testing services in one place

Web, mobile, API, cloud, AI, infrastructure, red team. Pick the test that fits your environment.

Penetration testing services
READY TO START

Get a fixed price for your OneLogin tenant

A OneLogin mapping can grant a role automatically, but the change only applies once a user record updates or mappings are reapplied. We test what your credential scopes, mappings and policies enforce. CREST-certified testers, fixed price from £3,290 for a 2-day single-tenant scope, quoted within 24 hours.