Skip to main content
Connect OneLogin to automate user lifecycle management, group and role assignments, password resets, and application access through your service desk. Sync OneLogin users, groups, roles, and applications, then use to manage identities directly from Ravenna.

What you can do

User lifecycle management

Activate and suspend users in OneLogin from workflow actions

Group and role management

Add or remove users from OneLogin groups and roles, and check group membership

Password and authentication

Generate password reset tokens and set user passwords

Application sync

Sync visible OneLogin applications into your Ravenna application catalog, skipping hidden ones

User sync

Sync user profiles with department, manager, and company data

Group and role provisioning

Map access levels to OneLogin groups or roles so approved access requests provision automatically

Access provisioning

OneLogin supports the Group, Workflow, and Manual provisioning methods, the same set as every provider except Okta. An access level can map to either a OneLogin group or a OneLogin role, and the Group method covers both. Direct user-to-application assignment is not available, so Application is Okta only. Groups and roles provision differently, and the difference decides which one you should map:
A group-mapped grant for a user who already belongs to a different group fails with USER_BELONGS_TO_DIFFERENT_PRIMARY_GROUP and writes nothing to OneLogin. Ravenna will not displace a group it did not grant. Map to roles when a user needs to hold more than one grant at a time.
Revocation is equally conservative. Ravenna checks the user’s current group first, and if they have since been moved elsewhere it marks the entitlement skipped revocation with a reason and leaves OneLogin untouched rather than clearing a group it did not grant.
Learn more about access provisioning

User profile data

Ravenna syncs OneLogin user profiles for org hierarchy, approval workflows, and dynamic values.

Available fields

Only approved OneLogin users sync. An unapproved, rejected, or unlicensed user is skipped, and one who loses approval is removed from Ravenna on the next sync, so status reads 1 on every synced user.

Using profile data in workflows

Access these fields through the user’s OneLogin metadata when building conditions or actions:
  • Route approval requests based on department or company
  • Scope eligibility by job title
  • Include contact information in notifications
  • Build manager-based approval chains using the manager relationship

Group and role sync

OneLogin uses both groups and roles to organize users. Ravenna syncs both into user groups with clear labeling:
  • Groups sync with their original name (e.g., “Engineering Team”)
  • Roles sync with a “Role: ” prefix (e.g., “Role: Administrator”)
This distinction helps you target the correct OneLogin entity when building workflows, and it is how you tell the two apart in the access level dropdown. Both sync with their members, but only approved users do, so an unapproved or unlicensed member of a group does not appear in Ravenna even though OneLogin still counts them. Membership reflects the last sync rather than live OneLogin state. Roles also carry the applications they grant, which groups do not, so a role’s application associations show up in Ravenna and a group’s do not.
If an access level mapped to a group or role fails to provision with a metadata error, run a resync of the OneLogin integration. Provisioning reads the synced record to tell a group from a role.
Where a provisioning error reason names a group or role at all, it uses the numeric OneLogin ID rather than the name, so a failure reads “already belongs to OneLogin group 77”. Match the ID against the group in OneLogin to identify it.
Learn more about OneLogin workflow actions
Last modified on September 17, 2026