OneLogin

Last Updated: August 18, 2026

An identity provider (IdP) uses an authentication token to vouch for a person's identity. Vasion Automate uses IdPs for several tasks, including logging in to the Admin Console and portals, deploying printers, releasing print jobs, and more.

If you use an IdP, the Control Panel Application (CPA) supports only badge and PIN authentication.

Configure Connection

To add and configure app properties for the Vasion Automate connection do the following:

  1. Create OneLogin SAML App
  2. Set Authentication Type
  3. Configure Single Sign On
  4. Add X509 Certificate
  5. Configure Provisioning
  6. Add PrinterLogic Admins

1. Create OneLogin SAML App

  1. In your preferred browser, log in to your OneLogin portal. You can add your domain name to the following URL to access your portal.

    https://<your domain>.onelogin.com/login

  2. Hold the pointer over Applications in the top menu, and then select Applications.

    OneLogin portal showing expanded Applications menu and Applications option.

  3. Select Add App in the upper-right corner of the Applications screen.
  4. Search for and select SAML Custom Connector (Advanced).
  5. Enter a name for the application in the Display Name field.
    1. (Optional) Adjust the icons or add a description.
  6. Select Save in the upper-right corner.

Leave the current browser on the new app page. To continue app configuration, open the Vasion Automate or PrinterLogic Admin Console in a new browser, and access the service provider information.

2. Set Authentication Type

In a separate browser window, log in to Vasion Automate, and do the following:

  1. Select Admin from the left-side navigation.
  2. Select the Authentication option.
  3. Select the + New Authentication button.

    Authentication page showing + (add) New Authentication button.

  4. Select the IdP that you want to configure.
  5. Select Next.
  6. Give your IdP a unique name.
    1. (Optional) Add a description.
  7. Select SAML2 in the Authentication Protocol section.
  8. In the Provisioning section, if you are using Systems for Cross-domain Identity Management (SCIM), leave the Just-in-Time (JIT) option deselected.

  9. Leave the IdP Information page open. You need this information for the next step.

IdP Information window showing different configuration fields and Service Provider Information section.

3. Configure Single Sign On

  1. Select the Configuration option from the OneLogin app's left-side menu.
  2. Copy the Vasion Automate Identifier (Entity ID) and paste it into the OneLogin Audience (EntityID) field.
  3. Copy the Vasion Automate Relay State and paste it into the OneLogin RelayState field.
  4. Copy the Vasion Automate Reply Url (ACS) into the following OneLogin app configuration fields:
    1. Recipient.
    2. ACS (Consumer) URLValidator.
    3. ACS (Consumer) URL.
  5. Select the Parameters option from the OneLogin app's left-side menu.
  6. Select the NameID Value entry and update the Value to Username using the Value drop down.
  7. Select SSO from the OneLogin app's left-side menu.
  8. Copy the OneLogin Issuer URL and:
    1. Paste it into the Vasion Issuer URL field.
    2. Cut the alphanumeric portion after metadata/ and paste it into the Issuer ID field.
    3. Example: Issuer URL: https://oneloginURL/metadata/, Issuer ID: 1e877fb7-550g56-4aa8-9b18-06d93d9fa65f
  9. Copy the OneLogin SAML 2.0 Endpoint (HTTP) value and paste it into the Vasion SSO URL field.

SSO screen showing Issuer URL and SAML 2.0 Endpoint (HTTP) fields.

4. Add the X-509 Certificate

  1. Select the SSO option from the OneLogin app's left-side menu.

  2. In the X.509 Certificate section, right-click the View Details link and select Open in new tab.
    SSO screen showing View Details link under X.509 Certificate section.

    If you don't open the link in a new tab, that's fine. After completing this section, navigate back to the app you created. Hover over Applications in the top-menu, select Applications, then select your app from the Applications page.

  3. Copy the certificate body, including the Begin / End Certificate headers, and paste it into the Vasion X509 Certificate field.

    Certificate window showing x-509 certificate content highlighted, excluding begin and end certificate portions.

  4. Select Save in Vasion Automate.

IdP Information screen showing fields for URLs and X509 certificate.

5. Configure Provisioning

The provisioning steps vary depending on whether you are using SCIM or JIT provisioning. Please choose the appropriate option below to view the corresponding steps for the method you are using.

SCIM Provisioning

Configure SCIM Provisioning

  1. In your preferred browser, sign in to your OneLogin portal. You can add your domain name to the following URL to access your portal.

    https://<your domain>.onelogin.com/login

  2. Hold the pointer over Applications in the top menu, and then select Applications.

    OneLogin portal showing expanded Applications menu and Applications option.

  3. Select Add App in the upper-right corner of the Applications screen.
  4. Search for and select SCIM Provisioner with SAML (SCIM v2 Enterprise).
  5. Select the Configuration option from the OneLogin app's left-side menu.
  6. Copy the Vasion Automate SCIM Tenant URL and paste it into the OneLoginSCIM Base URL field.
  7. In the SCIM Token section Vasion Automate's Edit IdP page, select the Generate New Token button.
  8. Copy the SCIM Token and paste it into the SCIM Bearer Token field.

    API Connection section showing status, Enable button, and SCIM Bearer Token field.

  9. In the OneLogin portal, select Provisioning in the left menu.
  10. Select Enable provisioning.
    1. Configure other user management options as desired.
  11. Select the OneLogin app's Configuration option from the left-side menu.
  12. Select the API Status Enable button.
  13. Select Save in OneLogin.

Provisioning screen showing enabled Workflow settings.

Add Users / Groups

Follow the steps below to add individual users to the application. If using OneLogin Roles for group provisioning, skip to Add Groups.

Add Users
  1. Hover over the top menu Users option and select the Users sub-option.
  2. Search for and select the desired user.
  3. Select Applications from the left-side menu.
  4. Select the Plus icon on the far-right.
  5. In the Select application drop-down, select both the SAML Custom Connector (Advanced) and the SCIM Provisioner with SAML (SCIM v2 Enterprise) applications.
  6. Select Continue.
  7. Review the user information and select Save at the bottom.
  8. With the user now displayed on the Users page of the SCIM Provisioner with SAML (SCIM v2 Enterprise) application, check their Provisioning State.
  9. If pending, select Pending.
  10. In the Create modal, select Approve.
  11. Select Save User in the upper right.

Users begin provisioning once approved.

"Assign new login to" dialog box showing application selected.

If the Provisioning State lists Unknown, select the Apply to all dropdown and select the Reset option.

Add Groups

To provision groups, we'll use OneLogin Roles. The steps below guide you through setting the parameters and creating and assigning a new role.

1. Create / Assign Roles

The steps below guide you through creating a new role. If you already have roles created, proceed to the next step.

  1. Hover over the Users option in the OneLogin top-menu and select the Roles sub-option.

    Expanded Users menu showing Users, Roles, and Groups options.

  2. Select the New Role button in the upper-right.
  3. Use the field in the upper-left to enter the role name, then select the checkmark.

    Roles dialog box showing Role Name field, checkmark button, and cancel button.

  4. In the Select Apps to Add section, select select both the SAML Custom Connector (Advanced) and the SCIM Provisioner with SAML (SCIM v2 Enterprise) applications.
  5. Select Save in the upper-right.
  6. Select your role from the list, then select the left-side Users option.
  7. In the Check existing or add new users to this role section:
    1. Search for the user(s).
    2. Select the user, then select Check.
    3. Select Add To Role.
    4. Repeat as needed for each user.
  8. Select Save when finished.

Roles dialog box showing users added automatically and manually.

2. Set Parameters
  1. Navigate back to your OneLogin app, and select the Parameters option.
  2. In the Value column, select Groups.
  3. In the Edit Field Groups modal, select Include in User Provisioning.
  4. Select Save in the Edit Field Groups Modal.
  5. Select the Save button on the Application Parameters page.

Edit Field Groups dialog box showing Include in User Provisioning flag enabled.

3. Create Rules
  1. Select Rules from the OneLogin app's left-side menu.
  2. Select Add Rule.
  3. In the New Mapping modal:
    1. Enter a name for the rule.
    2. Under Actions, select Set Groups in <Application Name>.
    3. Select Map from OneLogin.
    4. Set For each to role.
    5. Set the with value that matches to the role name previously created.
    6. Select Save in the modal.
  4. Repeat as needed for additional roles.
  5. Select Save in the Rules window.

"New mapping" dialog box showing conditions and actions for new rule.

4. Approve Pending Users
  1. Select the OneLogin app's left-side Users option.
  2. In the Provisioning state column, select the Pending option.
  3. In the Create modal, select Approve, or the approve bulk logins option.

Users begin provisioning once approved.

Applications screen showing provisioned users.

If the Provisioning State lists Unknown, select the Apply to all dropdown and select the Reset option.

Enable IdP

  1. In Vasion Automate, close the IdP Information page.
  2. In the Authentication page, select the button next to the configured IdP to turn it on.

CyberArk showing Authentication tab and IdP turned on.

JIT Provisioning

Enable IdP

  1. In Vasion Automate, close the IdP Information page.
  2. In the Authentication page, select the button next to the configured IdP to turn it on.

CyberArk showing Authentication tab and IdP turned on.

JIT Provisioning

JIT does not support the provisioning of group membership associations, so you cannot apply Role-Based Access Control (RBAC) roles, printer deployments, or portal security roles to groups. You must create assignments individually for each user.

When using JIT provisioning, the app creates users during the first sing-in attempt:

  1. Access your Vasion instance, and select Sign In With <IdP Name>.
  2. Attempt to sign in with your IdP credentials.
  3. This sign-in attempt fails and returns you to the sign-in screen.

    This behavior is expected. With JIT, this action triggers user creation in the Vasion instance.

  4. The second sign-in attempt with valid credentials initiates a typical sign-in sequence.

For admins who need access to the Admin Console, you still need to add them to the Users page located in Tools then Users.

6. Add PrinterLogic Admins

For steps on assigning users and roles to the PrinterLogic and Vasion Automate Admin Console, refer to Admin Console Users.