Configure SAML single logout for Microsoft Entra

Who can do this?
Role: Organization admin
Atlassian Cloud: Atlassian Guard Standard
Atlassian Government Cloud: Not available

Before you begin

Before you can enable SAML single logout for Microsoft Entra, make sure you’ve completed the following steps:

Atlassian supports SAML single logout only for identity providers Microsoft Entra and Okta. Configure SAML single logout for Okta

What is service provider-initiated single logout?

Service provider-initiated single logout means that when a user logs out of an Atlassian app, such as Jira, they are also logged out of your identity provider in a single action. This helps prevent unauthorized access to your Atlassian organization’s data.

Enable service provider-initiated single logout

Once you’ve connected your Microsoft Entra identity provider to Atlassian and configured SAML for single sign-on, you can enable service provider-initiated single logout.

To enable service provider-initiated single logout:

  1. Go to Atlassian Administration. Select your organization if you have more than one.

  2. Select Security > User security > Identity providers.

  3. Select your SAML configuration for Microsoft Entra.

  4. Under Single logout, select Enable.

  5. Copy the Service provider logout URL to Microsoft Entra.

  6. Copy the logout URL from Microsoft Entra and paste it into Identity provider logout URL.

  7. Select Save.

After completing these steps, logging out of Atlassian will also log users out of their Microsoft Entra SAML session.

Edit service provider-initiated single logout

You may need to update your single logout URL to maintain a secure connection.

To edit service provider-initiated single logout:

  1. Go to Atlassian Administration. Select your organization if you have more than one.

  2. Select Security > User security > Identity providers.

  3. Select your Microsoft Entra directory.

  4. Select View SAML configuration.

  5. Make edits, then select Save.

Delete service provider-initiated single logout

When you delete your service provider-initiated single logout configuration, we no longer log users out from both Atlassian and your Okta identity provider with a single action.

To delete service provider-initiated single logout:

  1. Go to Atlassian Administration. Select your organization if you have more than one.

  2. Select Security > User security > Identity providers.

  3. Select your Microsoft Entra directory.

  4. Select View SAML configuration.

  5. Under Single logout, select the More actions icon (•••) > Delete service provider-initiated logout.

Still need help?

The Atlassian Community is here for you.