Screenata

Integrations / Identity & access

Screenata + OneLogin

How do you prove SOC 2, ISO 27001, and HIPAA access controls in OneLogin?

Quick answer

OneLogin is where logical access control is proved. It is the first thing an auditor samples under SOC 2 CC6.1, and the account roster is where quarterly access reviews get their source of truth. An access control policy existing on paper is not the control. The control is the enforced setting in OneLogin plus the record that it operated for every user across the audit period. Screenata runs 2 native checks against that configuration on a schedule and turns each result into signed evidence mapped to the control it satisfies.

Screenata connects to OneLogin read-only and runs 2 native checks against your account: MFA enforcement, password requirements, and session timeout settings. Each finding becomes a signed, timestamped evidence artifact mapped to SOC 2, HIPAA, and ISO 27001 controls through a shared control catalog.

2 native checks · read-only · signed evidence

What it proves

OneLogin evidence, mapped to controls.

Each area below is scanned on a schedule. A finding is not a green checkmark: it is a signed artifact an auditor can verify, mapped to the exact requirement it satisfies.
Evidence area
What the checks verify
Maps to
MFA enforcement

Whether MFA policies cover your users and how enforcement is configured.

Proof that workforce access requires strong authentication, the first thing an auditor samples.

SOC 2CC6.1HIPAA§164.312(d)ISO 27001A.8.5
Password requirements

Password length, complexity, and rotation settings in force on the account.

Configuration snapshot showing the policy in force on the scan date.

SOC 2CC6.1ISO 27001A.5.17
Session timeouts

Session lifetime and idle timeout settings across policies.

Proof that unattended sessions expire, which HIPAA names explicitly as automatic logoff.

SOC 2CC6.1HIPAA§164.312(a)(2)(iii)

Control references are the requirements each evidence area supports, via the shared control catalog. Your auditor decides sufficiency; the artifacts are theirs to verify.

Compliance checks

What Screenata checks on OneLogin, and why each matters.

Each row is a real native check, the framework control it produces evidence for, and the risk it closes. This is what continuous OneLogin compliance actually looks like. Checks run on a schedule; a failing check opens a ticket and re-verifies after a human applies the fix.
Check & why it matters
Maps to

Admin Accounts Limited

Each broad-privilege admin account widens the blast radius of a compromise. An auditor confirms the number of users holding wide administrative privilege stays within a defined threshold.

SOC 2CC6.1SOC 2CC6.3

Dormant Accounts

Dormant but enabled accounts are the classic path for a departed employee or an unnoticed attacker to retain access. Auditors verify active accounts with no recent login are reviewed and deprovisioned.

SOC 2CC6.2SOC 2CC6.3ISO 27001A.5.18HIPAA§164.308(a)(3)(ii)(C)

Drawn from Screenata’s OneLogin check library. Control refs are the requirements each check produces evidence for; your auditor decides sufficiency.

How it connects

Read-only, revocable, yours.

You create read-scoped API credentials and Screenata uses them for scheduled scans. Vera never receives write access to your account, and credentials never touch the Screenata database. Findings are hashed and stored as evidence the moment they land.

Read-only by construction

OAuth scopes and IAM roles are scoped to read. Vera never gets write access to your systems.

Signed findings

SHA-256 per artifact, RSA/ECDSA signatures, RFC 3161 timestamps. Verifiable without a Screenata account.

Mapped to controls

Each finding lands on the shared control catalog, so one scan satisfies SOC 2, HIPAA, and ISO 27001 at once.

OneLogin FAQ

What teams ask before connecting.

Full provider list on the integrations page.
What access does Screenata need to OneLogin?

Read-scoped API credentials that you create and control. Screenata uses them for scheduled scans and never receives write access to your account. You can revoke them at any time from the OneLogin admin console.

Does the OneLogin integration feed access reviews?

Yes. User and application assignment state feeds the quarterly access reviews Vera schedules and orchestrates, with every decision left to a human reviewer, and the completed review recorded as signed evidence.

What happens when a OneLogin check fails?

Vera opens a ticket describing the failing configuration and re-verifies after a human applies the fix. Nothing in your account is changed by Screenata; the connection is read-only by construction.

What are the steps to implement SOC 2 with OneLogin?

Connect OneLogin read-only with scoped API credentials. Let the first scan establish a baseline so you can see which settings already pass and which do not. Fix what fails: keep the number of users holding wide administrative privilege inside a defined threshold, and review and deprovision dormant accounts with no recent login. Tighten the surrounding policy settings the areas above describe, MFA enforcement, password requirements, and session timeouts, so the configuration matches what your access control policy claims. Collect the passing results as signed evidence on a schedule, so you hold coverage across the whole audit period rather than one snapshot. Then hand the evidence package to an independent auditor. The audit is a separate engagement with a CPA firm; Screenata prepares the evidence and does not issue the report.

How do you automate user access reviews?

OneLogin supplies the authoritative list of accounts and application assignments. The HR roster supplies who should still have them. Screenata reconciles the two, schedules the review, routes each account to the right reviewer, and records the reviewer's decision as signed evidence. The access decision stays with the human reviewer. What the automation covers is gathering, routing, chasing, and recording.

Do auditors accept evidence Screenata collects from OneLogin?

Yes. Every finding is exported as a signed, timestamped artifact, a SHA-256 hash with an RSA or ECDSA signature and an RFC 3161 timestamp, that an auditor verifies outside Screenata with a free CLI. A person reviews and approves the evidence before it reaches the auditor. Screenata collects and signs it; it does not decide the audit result.

Connect and see

Fifteen minutes after connecting OneLogin, you know your real posture.

Pricing

Related: Okta · JumpCloud · Auth0 · Google Workspace