Uploaded image for project: 'Atlassian Guard'
  1. Atlassian Guard
  2. ACCESS-592

Logging out of Atlassian account does not log out of SAML provider

    • 109
    • Hide

      Update June 11, 2024 

      This feature has now shipped. 

      https://support.atlassian.com/security-and-access-policies/docs/what-is-saml-single-logout/

      https://support.atlassian.com/security-and-access-policies/docs/configure-saml-single-logout-for-okta/

      Update December 17, 2024

      Thank you for all of your feedback, we are now actively working on this feature request. We understand the importance of it, and we are prioritizing it accordingly. Please stay tuned for updates on a targeted launch date, we will have that for you in the new year. in the meantime, please do continue to leave your feedback here.

      Show
      Update June 11, 2024   This feature has now shipped.  https://support.atlassian.com/security-and-access-policies/docs/what-is-saml-single-logout/ https://support.atlassian.com/security-and-access-policies/docs/configure-saml-single-logout-for-okta/ Update December 17, 2024 Thank you for all of your feedback, we are now actively working on this feature request. We understand the importance of it, and we are prioritizing it accordingly. Please stay tuned for updates on a targeted launch date, we will have that for you in the new year. in the meantime, please do continue to leave your feedback here.
    • Our product teams collect and evaluate feedback from a number of different sources. To learn more about how we use customer feedback in the planning process, check out our new feature policy.

      If a user is logged in to an external Identity provider (SAML), when they log out of Atlassian account they do not get logged out of the IdP.

      This can mean that if a user logs out of an Atlassian product to then try and log in with a different email on the same domain, the login will fail as Atlassian receives a different email from the IdP.

      Many SAML providers support 'single sign out' which would solve this issue if integrated.

            [ACCESS-592] Logging out of Atlassian account does not log out of SAML provider

            Holcomb, Amber added a comment -

            Seconding Nick's comment/question. If I'm waiting for the rest of the SAML/Idp fixes (we do not use Okta), should I stay watching this ticket or do I need to start following a different one now that this is marked "Closed"?

            Holcomb, Amber added a comment - Seconding Nick's comment/question. If I'm waiting for the rest of the SAML/Idp fixes (we do not use Okta), should I stay watching this ticket or do I need to start following a different one now that this is marked "Closed"?

            Nick E Buono added a comment -

            So the feature is only available if you're using Okta?? Do you plan on releasing this for any of your other supported IdPs?

            Nick E Buono added a comment - So the feature is only available if you're using Okta?? Do you plan on releasing this for any of your other supported IdPs?

            Sudesh Peram added a comment - This feature has now shipped.  https://support.atlassian.com/security-and-access-policies/docs/configure-saml-single-logout-for-okta/ https://support.atlassian.com/security-and-access-policies/docs/what-is-saml-single-logout/

            Peter Müller added a comment - - edited

            Hey all,

            any news to SLO for users and customers/portal-only customers ?

            An update, even a short one, and maybe when a release could be expected, would be appreciated.

             

            Thanks and regards !

            Peter Müller added a comment - - edited Hey all, any news to SLO for users and customers/portal-only customers ? An update, even a short one, and maybe when a release could be expected, would be appreciated.   Thanks and regards !

            Hello all, 

            The end of June has finally arrived. What is the expected release for this update?

            Thanks

            Dimitri Golyshev added a comment - Hello all,  The end of June has finally arrived. What is the expected release for this update? Thanks

            hi 4bcd3952f2c7 I confirm that this is being worked on by my team and on track of release by end of June 

            Reda Zerrad added a comment - hi 4bcd3952f2c7 I confirm that this is being worked on by my team and on track of release by end of June 

            Totally agree, 10b3db809bd1!

            9296fec66f8a eee30c920d0f, I do not see anything in the Cloud Roadmap or App updates in Atlassian Administration regarding this update being pushed, please confirm if your team is still on track to roll this out by end of June. Thank you!

            Dimitri Golyshev added a comment - Totally agree, 10b3db809bd1 ! 9296fec66f8a eee30c920d0f , I do not see anything in the Cloud Roadmap or App updates in Atlassian Administration regarding this update being pushed, please confirm if your team is still on track to roll this out by end of June. Thank you!

            Peter Müller added a comment - - edited

            Will Single-Logout be implemented for portal-only customers that use SSO via SAML too ?

            At the moment a portal-only customer has to close his browser to "finish" a logout from a service portal. If he does not close his browser (or deletes his session cache/cookies/etc), logs in again with another account, he could get access to the before logged in account.

            Thats a big security risk !

            Peter Müller added a comment - - edited Will Single-Logout be implemented for portal-only customers that use SSO via SAML too ? At the moment a portal-only customer has to close his browser to "finish" a logout from a service portal. If he does not close his browser (or deletes his session cache/cookies/etc), logs in again with another account, he could get access to the before logged in account. Thats a big security risk !

            l.liesse added a comment -

            Hello, is it ok now?

            l.liesse added a comment - Hello, is it ok now?

            9296fec66f8a, thank you, please be sure to update us. Appreciate your help!

            Dimitri Golyshev added a comment - 9296fec66f8a , thank you, please be sure to update us. Appreciate your help!

              e902c0832f88 Sudesh Peram
              jevans@atlassian.com Jeremy Evans
              Votes:
              161 Vote for this issue
              Watchers:
              143 Start watching this issue

                Created:
                Updated:
                Resolved: