Vigilance AI is OneLogin’s proprietary engine for analyzing a wide variety of threat factors and user behaviors that could compromise your organization’s security, automatically protecting you from threats based on a calculated risk score.
When a user logs in, Vigilance AI tracks a wide variety of factors taking place during the login attempt, such as:
- Is the user logging in from an IP address flagged as a threat in AlienVault Open Threat Exchange or block-listed by Project HoneyPot?
- Is Tor network access being used during the login attempt?
- What browser, operating system, IP address, and device are being used for the login attempt?
- Where is the user’s geographic location?
- What time of day is the user logging in?
Based on these factors and more, login attempts are assigned scores on a scale of 0-100, which are then ranked into levels of No Risk (0-4), Low Risk (5-25), Medium Risk (26-50), and High Risk (51-100).
Meanwhile, Vigilance AI learns from each trusted login, building up a profile of each user’s usual login patterns and what counts as normal activity for them. Each time the user logs in with the same consistent habits, Vigilance AI lowers their risk score. When the pattern is broken, for example if the user signs in during the middle of the night, from a new country, or using an unfamiliar device, their risk score is raised again.
Only trusted events teach Vigilance AI what is normal, and a log-in event is trusted unless you say otherwise. To see how the Vigilance AI APIs fit together in a login flow, and when to send each event, read the Login Flow Guide.
Before you start
To make any calls to the Vigilance AI API, you need at least:
- Smart MFA or Smart Access enabled on one of your security policies.
- That security policy assigned to at least one user.
If your calls to the Vigilance AI API return 401 errors, check that both of these are in place.
Have a Question?
Found a problem or a bug? Submit a support ticket.
Looking for walkthroughs or how-to guides? Check out our Knowledge Base.
Have a product idea or request? Share it in our Ideas Portal.