<html><head><meta http-equiv="Content-Type" content="text/html; charset=us-ascii"></head><body style="word-wrap: break-word; -webkit-nbsp-mode: space; line-break: after-white-space;" class=""><br class=""><div><br class=""><blockquote type="cite" class=""><div class="">On Jan 19, 2022, at 2:12 PM, Wessel, Keith <<a href="mailto:kwessel@illinois.edu" class="">kwessel@illinois.edu</a>> wrote:</div><br class="Apple-interchange-newline"><div class=""><span style="caret-color: rgb(0, 0, 0); font-family: Helvetica; font-size: 18px; font-style: normal; font-variant-caps: normal; font-weight: normal; letter-spacing: normal; text-align: start; text-indent: 0px; text-transform: none; white-space: normal; word-spacing: 0px; -webkit-text-stroke-width: 0px; text-decoration: none; float: none; display: inline !important;" class="">The manual route is what we did, proxying logout to ADFS which would be very similar to proxying to Azure. It's not SAML logout, but since we haven't been propagating logout to other SPs, anyway, it really doesn't matter in the grand scheme of things. We truly just have a meta-refresh tag in out logout template that's redirecting to the Microsoft IdP's logout page.</span></div></blockquote><br class=""></div><div>And if you are not trying to propagate logout anyways, another option might be you simply do not have the Shib IdP keep a session in the first place, and list an Azure AD logout endpoint that does not require a SAML logout message (just like the Shib IdP's profile/Logout endpoint) as the logout endpoint when you configure the SP with the Shib IdP. (Assuming Azure AD has such a logout endpoint.) </div><br class=""><div class="">
<div>--<br class="">Michael A. Grady<br class="">IAM Architect, Unicon, Inc.</div><div class=""><br class=""></div><br class="Apple-interchange-newline">

</div>
<br class=""></body></html>