Blog

Non-Employee Risk Management Enhancement: Log Out from Identity Provider when using ISC Auth

Author

  • mwoodberry

    SailPoint

Previously, if NERM was configured to use ISC Authentication and a user logged out of NERM, they remained logged in to ISC and their identity provider (IDP). Since logging out of NERM did not terminate the ISC and IDP sessions, the user could access NERM again without re-authenticating through their IDP. This behavior was not desirable, particularly in cases where NERM is accessed through a shared workstation, as it presented a security risk by allowing users to tailgate on a previous ISC session.

What changed?

With this enhancement, when NERM is configured to use ISC Authentication, NERM will follow the log out process defined in ISC. This means that based on ISC configuration, logging out of NERM will terminate the NERM, ISC, and IDP sessions, requiring the user to re-authenticate through their IDP.

Action Needed

For the log out process to work as expected, ISC Administrators should ensure the configuration of the Logout URL in ISC points to the logout URL of their corresponding IDP. The ISC Logout URL configuration is on the > Admin > Global > Security Settings > Service Provider page.

When is this change happening?

This update is available now.