home

Mobile Endpoint Security

Lookout Product Documentation

Find answers about using and optimizing Lookout products.

Setting Up OneLogin

  1. Log in to the OneLogin administration console.
  2. In the top navigation bar, click APPS > Add Apps.
  3. In the Find Applications search bar, enter OneLogin SAML Test (IdP) w/ NameID (unspecified) and click the resulting entry to create a new app:


  4. On the Info tab, enter a name and optionally upload an icon.
  5. Click the Configuration tab and enter the SAML Consumer URL.
    This is the Lookout ACS URL for your tenant, provided by Lookout:


  6. Click the Parameters tab, then under Credentials are select Configured by admin.
  7. Add the following attributes by clicking Add parameter. For parameters with static values, select -Macro- as the value type and enter the desired value:




    OneLogin SAML … FieldValueDescription
    NameID (SAML Subject)EmailThe default ID field.
    ent- Macro -This is your Lookout enterprise tenant GUID, for example: " 78902dc0-b8ab-4abc-12c7-4a2b980ec23a"
    givennameFirst NameThe user's first name.
    mailEmailThe user's email.
    memberOf- Macro -

    This should be a "Contains" match against a common String in the user group names you use for Lookout MES Console Full Access, Restricted Access, Read-Only , and Enrollment Only administrators. For example, if your user groups are named:

    • Lookout-Full
    • Lookout-Restricted
    • Lookout-ReadOnly
    • Lookout-EnrollmentOnly

    Then the memberOf - Macro - Value should be:

    "Contains" = "Lookout"
    snLast NameThe user's last name.
    upnEmailThe user's principal name.
  8. Click MORE ACTIONS > SAML Metadata to download the SP metadata for Lookout: