ADFS 3.0 Logout - allow two SAML Logout Endpoints

FS 21 Reputation points
2020-08-23T22:03:21.107+00:00

Hello,

I have searched low and high for a solution but could not find a definitive answer if my problem can be solved. Even just knowing that it cannot be solved would be extremely helpful.

We have a single identity service that has two DNS names assigned to it, and want to enable federation to a ADFS 3.0 RP. Requests to our identity service can come to either domain. The federated login is successful for all requests, independent of the domain, however, the logout callback from the ADFS 3.0 RP would always go to the first (default) configured SAML Logout Endpoint, irrespective from which domain the request came from. This creates downstream issues with cookies from our identity service being handled on the wrong domain, when the logout request did not come from the default domain.

I have tried using wreply to tell the RP which logout endpoint it should call, but the parameter got ignored.

I have found various suggestions in forums and blogs that say that two logout URLs are effectively not possible with ADFS 3.0 but no definite answer.

If anybody has had this scenario working, it would be great to know.

Kind Regards,
Florian

Active Directory Federation Services
Active Directory Federation Services
An Active Directory technology that provides single-sign-on functionality by securely sharing digital identity and entitlement rights across security and enterprise boundaries.
1,259 questions
0 comments No comments
{count} votes

1 answer

Sort by: Most helpful
  1. Vahid Ghafarpour 21,240 Reputation points
    2023-11-25T04:03:32.6433333+00:00

    Ensure that you are accounting for time zone differences between Outlook and Google Calendar. Both events should be in the same time zone, or you may need to convert the time appropriately during the mapping.

    0 comments No comments

Your answer

Answers can be marked as Accepted Answers by the question author, which helps users to know the answer solved the author's problem.