Office365 Single-Sign out

Viewed 208

I have implemented Single-Sign on in an existing C# Asp.Net MVC 4.5 application and therefore used Owin middleware and OpenIdConnectAuthentication. The authentication and authorization works fine, but now I have following problem:

  1. I sign in to my application by using AzureAD as identity provider
  2. I sign in to Office365 in another browser tab
  3. I sign out of my application - get redirected to the identity provider and also automatically sign out there
  4. Office365 automatically signs out within the other tab

I do not have configured Single Sign out (so I didn't specified a Logout Url within the App Registration and neither in the configuration code), but I am still signed out of Office365. This is annoying for the customer, as he always uses Outlook365 within the browser.

How can I prevent Office365 from signing out the user automatically.

Here is a simplified code of my configuration of OpenIdConnect:

app.UseOpenIdConnectAuthentication(
            new OpenIdConnectAuthenticationOptions
            {
                ClientId = clientId,
                Authority = authority,
                Notifications = new OpenIdConnectAuthenticationNotifications
                {
                    AuthorizationCodeReceived = (context) =>
                    {
                        // ... my sign in logic ...
                        context.OwinContext.Response.Redirect(homeUrl);
                        return Task.FromResult(0);
                    },
                },
                AuthenticationType = OpenIdConnectAuthenticationDefaults.AuthenticationType
            });

And here is how I sign out of the application:

context.GetOwinContext().Authentication.SignOut(new AuthenticationProperties { RedirectUri = redirectUrl }, OpenIdConnectAuthenticationDefaults.AuthenticationType);
0 Answers
Related