If they support SAML logout then the metadata simple needs to contain those endpoints. The default SP config contains the SAML2 protocol token and requesting a logout of the SP will already automatically forward that to the IdP, there's nothing else to configure. -- Scott