Logging out of Atlassian account does not log out of SAML provider

XMLWordPrintable

    • 113
    • Hide

      Update December 4, 2025 

      SAML Single logout for EntraID (formerly called Azure AD) is available now. 

      Update June 11, 2025 

      SAML single logout for Okta is available now. 

      https://support.atlassian.com/security-and-access-policies/docs/what-is-saml-single-logout/
      https://support.atlassian.com/security-and-access-policies/docs/configure-saml-single-logout-for-okta/

      We are also working on extending this to other large IDPs. 

      Update December 17, 2024

      Thank you for all of your feedback, we are now actively working on this feature request. We understand the importance of it, and we are prioritizing it accordingly. Please stay tuned for updates on a targeted launch date, we will have that for you in the new year. in the meantime, please do continue to leave your feedback here.

      Show
      Update December 4, 2025   SAML Single logout for EntraID (formerly called Azure AD) is available now.  Update June 11, 2025   SAML single logout for Okta is available now.  https://support.atlassian.com/security-and-access-policies/docs/what-is-saml-single-logout/ https://support.atlassian.com/security-and-access-policies/docs/configure-saml-single-logout-for-okta/ We are also working on extending this to other large IDPs.  Update December 17, 2024 Thank you for all of your feedback, we are now actively working on this feature request. We understand the importance of it, and we are prioritizing it accordingly. Please stay tuned for updates on a targeted launch date, we will have that for you in the new year. in the meantime, please do continue to leave your feedback here.

      If a user is logged in to an external Identity provider (SAML), when they log out of Atlassian account they do not get logged out of the IdP.

      This can mean that if a user logs out of an Atlassian product to then try and log in with a different email on the same domain, the login will fail as Atlassian receives a different email from the IdP.

      Many SAML providers support 'single sign out' which would solve this issue if integrated.

            Assignee:
            Sudesh Peram
            Reporter:
            Jeremy Evans
            Votes:
            162 Vote for this issue
            Watchers:
            145 Start watching this issue

              Created:
              Updated:
              Resolved: