Blog

Enhancement: Log Out from Identity Provider when using ISC Authentication

Author

  • mwoodberry

    SailPoint

Currently, if NERM is configured to use ISC Authentication and a user logs out of NERM, they remain logged in to ISC and their identity provider (IDP). Since logging out of NERM does not terminate the ISC and IDP sessions, the user will be able to access NERM again without re-authenticating through their IDP. This behavior is not desirable, particularly in cases where NERM is being accessed through a shared workstation, as it presents a security risk by allowing users to tailgate on a previous ISC session.

What is changing?

With this enhancement, when NERM is configured to use ISC Authentication, NERM will follow the log out process defined in ISC. This means that based on ISC configuration, logging out of NERM will terminate the NERM, ISC, and IDP sessions, requiring the user to re-authenticate through their IDP.

Action Needed

For the log out process to work as expected, ISC Administrators should ensure the configuration of the Logout URL in ISC points to the logout URL of their corresponding IDP. The ISC Logout URL configuration is on the > Admin > Global > Security Settings > Service Provider page.

 

When is this change happening?

This update will be enabled Thursday, October 31.