Tuesday, April 12, 2011

Signout issue from Claim enabled Site in SharePoint 2010 with adfs 2.0

While working with ADFS claim aware site in SharePoint 2010, there is one issue regarding the sigout from the portal. Even if the user sign out from the portal, the cookie still persists and when user tries to login again he will be automatically signed in without prompted for re-authentication.

We can overcome this issue by implementing below steps :

1. Signout url -->
To correctly log out, we need to browse to the ADFS sign out url like
https://your_sts_server/adfs/ls/?wa=wsignout1.0

2. Setting the FedAuth cookie to be session based -->
In order to have correct sign out behaviour (even after setting the signout url as shown in step 1) we need to make the FedAuth cookies as session based. We can achieve this by running the following powershell command :

$sts = Get-SPSecurityTokenServiceConfig
$sts.UseSessionCookies = $true
$sts.Update()
iisreset

The details for the FedAuth cookie behaviour can be found here

Hope this post will be helpful to resolve the sign out issue.

5 comments:

  1. Hi Nitesh,
    where should i set the signout url for the sharpeoint site?
    is it a site-only changes, or it will impact the whole farm?
    thank you

    ReplyDelete
  2. I Apologize for responding late.

    1. The sign-out url was configured on the custom button click used to sign-out from the application.

    2. Get-SPSecurityTokenServiceConfig return the security token service (STS) for the farm. So the changes are farm based changes.

    ReplyDelete
  3. The sign-out url was configured on the custom button click used to sign-out from the application.isabel marant dixie bottines suede ankle boots(dsf2012.4.11)

    ReplyDelete
  4. isabel marant sneakers Bag designing patterns from historical really are taking theirselves at developing a lot more impressive running footwear to accomplish the actual moyen desires of customers.

    ReplyDelete
  5. If your feet include challenges distinct to your problem such as bunions plus callouses, continue this stuff in the mind if purchasing shoes and boots. This may imply purchasing a dimension bigger which means shoe does not touch plus stroke. Even though a person inside soreness about the shop, generally consider what are the shoe would certainly in good shape by carrying out a painful flare-up.
    aawqqeerdsd isabel marant manly suede and leather knee boots

    ReplyDelete