<iframe src="https://www.googletagmanager.com/ns.html?id=GTM-M74D8PB" height="0" width="0" style="display:none;visibility:hidden">
Loading
Skip to NavigationSkip to Main Content
0D54z0000880unlCAAOkta Classic EngineSingle Sign-OnAnswered2024-04-02T16:02:14.000Z2022-09-23T21:10:50.000Z2022-09-23T23:25:27.000Z

RobM.62038 (Customer) asked a question.

Does Okta support SLO when used as a Service Provider (SP) in an inbound federation scenario?

We are using Okta in an inbound federation scenario where it is configured as a Service Provider (SP) that communicates via SAML with an external IdP. The setup is configured using the Okta Identity Provider configuration screen. We have had a great deal of success with this configuration for login scenarios. When the user navigates to our application Okta communicates via SAML with the third party IdP. The IdP displays a login screen, authenticates the user, and sends the SAML response to complete the login. Logout has been a problem in this configuration. When users logout of our OIDC application we logout of Okta but we cannot figure out how to initiate a single logout (SLO) to the third party IdP. As a result the user is not prompted for credentials the next time they navigate to our application. The Okta Identity Provider screen does not have any way to configure a SLO URL that I can find. Is SLO supported in this configuration? If so, how do I configure my Okta SP to make it work?


This question is closed.
Loading
Does Okta support SLO when used as a Service Provider (SP) in an inbound federation scenario?