<html><head><meta http-equiv="Content-Type" content="text/html charset=utf-8"></head><body style="word-wrap: break-word; -webkit-nbsp-mode: space; -webkit-line-break: after-white-space;" class="">Josh,<div class=""><br class=""></div><div class="">I would track down Scott’s suggestion about metadata, but there’s at least one interesting thing in the encoded message: they appear to be using the asynchronous logout extension, and I don’t know if that’s implemented here or not.  A quick search for “asynchronous” in the IDP30 wiki space reveals nothing relevant to me.</div><div class=""><br class=""></div><div class=""><aslo:Asynchronous xmlns:aslo="urn:oasis:names:tc:SAML:2.0:protocol:ext:async-slo"/></div><div class=""><br class=""></div><div class=""><a href="https://wiki.shibboleth.net/confluence/dosearchsite.action?queryString=asynchronous" class="">https://wiki.shibboleth.net/confluence/dosearchsite.action?queryString=asynchronous</a></div><div class=""><a href="http://docs.oasis-open.org/security/saml/Post2.0/saml-async-slo/v1.0/saml-async-slo-v1.0.html" class="">http://docs.oasis-open.org/security/saml/Post2.0/saml-async-slo/v1.0/saml-async-slo-v1.0.html</a></div><div class=""><br class=""></div><div class=""><div><blockquote type="cite" class=""><div class=""><div style="margin: 0in 0in 0.0001pt; font-size: 12pt; font-family: 'Times New Roman', serif; font-style: normal; font-variant: normal; font-weight: normal; letter-spacing: normal; line-height: normal; orphans: auto; text-align: start; text-indent: 0px; text-transform: none; white-space: normal; widows: auto; word-spacing: 0px; -webkit-text-stroke-width: 0px;" class=""><span style="font-size: 11pt; font-family: Calibri, sans-serif; color: rgb(31, 73, 125);" class="">It is amazing to me that there are ‘professional’ cloud services out there that offer SAML2 authentication and have no idea how to configure their SP software for SAML2 logout.  They just say ‘we don’t do that’ and offer to do post-local logout redirect.</span></div></div></blockquote><br class=""></div><div>Rule, not the exception, I’m afraid, but a lot of this has to do with the inherent nature of logout on the web.  I’ve never pushed for SAML 2 SLO protocol support because it immediately leads into a whole lot of logout orchestration questions.  The /idp/profile/Logout handler is way more predictable.</div></div><div><br class=""></div><div class="">Take care,</div><div class="">Nate.</div></body></html>