Loading
Upcoming Mandatory Changes to Public Key Infrastructure (PKI)Read More
Salesforce Enforces New Security Requirements in Summer 2026Read More
Secure Your Salesforce Org
Table of Contents
Select Filters

          No results
          No results
          Here are some search tips

          Check the spelling of your keywords.
          Use more general search terms.
          Select fewer filters to broaden your search.

          Search all of Salesforce Help
          OAuth Access Policies for a Connected App: Enable Single and SAML Logout Control

          OAuth Access Policies for a Connected App: Enable Single and SAML Logout Control

          Single Logout is a mechanism that ensures that when a user logs out of either Salesforce or an external Identity Provider (IdP), the session is simultaneously terminated across all connected applications in the trust circle.

          Control Name

          External Client Apps: Configure OAuth Policies: Manage the Start URL for External Client Apps

          Recommended Configuration

          Enable Single Logout.

          Control Overview

          Single Logout is a mechanism that ensures that when a user logs out of either Salesforce or an external Identity Provider (IdP), the session is simultaneously terminated across all connected applications in the trust circle.

          Security Risk If Not Configured

          Without Single Logout, a user may "log out" of Salesforce but leave an active, valid session open at the IdP (or vice versa), creating a "zombie session" that allows unauthorized access to whoever next uses that device.

          Threat Scenarios

          In a shared workstation environment, a user clicks "Logout" in Salesforce and walks away, but the next person is able to re-enter the system without a password because the IdP session remains active.

          Estimated CVSS Score Range

          Critical (9.0–10.0).

          Risk Impact Considerations

          Incomplete session termination leads to unauthorized data access and account takeover, significantly increasing the risk of "Insider Threats" or accidental data exposure in public or shared environments.

          Higher Risk When

          The risk is significantly higher where multiple employees use the same physical hardware throughout the day.

          Low Risk When

          The scenario is lower risk when coupled with aggressive session timeouts and forced re-authentication policies that minimize the window of time an inactive session remains valid.

          Business and Integration Considerations

          Implementing Single Logout requires technical coordination with the IdP to ensure both "Front-Channel" (browser-based) and "Back-Channel" (server-to-server) logout requests are correctly formatted and accepted.

          Recommended Remediation

          Go to the Connected App or Auth. Provider settings, enter the Single Logout URL provided by your IdP, and select the appropriate Type (SAML or OpenID Connect).

          Security Health Review Guidance

          Security Health Review identifies Single Logout as a fundamental "Clean Exit" requirement, so that "Logout" is an absolute command that clears the user's entire digital footprint for that session.

           
          Loading
          Salesforce Help | Article