There are two methods for configuring the application for SMA1000 at OneLogin, and it is essential to understand when to use each.
If you have a user directory like AD on your premises, you do not need to send user group details to SMA1000 from OneLogin during user logins. In this case, you can create a OneLogin application using SonicWall application. See Configuring SMA1000 at OneLogin using the SonicWall application.
If you do not have a user directory on-premises, you can send group or roles details from OneLogin to SMA1000. In this case, you can create a OneLogin application using SAML Custom Connector (Advanced) application option. See Configuring SMA1000 at OneLogin using SAML Custom Connector.