ADFS登出 [英] ADFS Sign Out

查看:168
本文介绍了ADFS登出的处理方法,对大家解决问题具有一定的参考价值,需要的朋友们下面随着小编来一起学习吧!

问题描述

我已成功配置SharePoint用于SAML身份验证.登录页面重定向到https://adfs.domain.com/adfs/ls,但是退出链接(右上角)没有重定向到"/?wa=wsignout1.0",只需获得SP的"_layouts/15/SignOut.aspx"即可 登出页面.问题在于,任何人显然都可以重新打开SP页面,而无需重新进行身份验证,直到令牌过期为止.我在某个地方遇到了有关SPTrustedIdentityTokenIssuer上名为ProviderSignOutUri的属性的讨论,但我没有 我可以看到它(SP版本15.0.4569.1506).我还确保启用了会话Cookie.

作为临时的解决方法,我启用了"-AlwaysRequireAuthentication".在AdfsRelyingPartyTrust上.此解决方案的问题是我已经发布了多个SP应用程序,并且希望ADFS在身份验证后自动对用户进行身份验证 到第一个SP应用程序.


I successfully configured SharePoint for SAML authentication. The sign-in page is redirected to https://adfs.domain.com/adfs/ls, but the sign-out link (upper right hand corner) does not redirect to "/?wa=wsignout1.0", i just get the SP "_layouts/15/SignOut.aspx" signout page. The problem is that anyone can obviously reopen the SP page w/o needing to re-authenticate until the token expires. I came across somewhere talking about a property called ProviderSignOutUri on the SPTrustedIdentityTokenIssuer, but i dont see it on my end (SP Version 15.0.4569.1506). I also made sure that session cookies are enabled. 

As a temp workaround solution, i enabled "-AlwaysRequireAuthentication" on the AdfsRelyingPartyTrust. Problem with this solution is that i have published multiple SP applications, and would like for ADFS to automatically authenticate users after authenticating to the first SP app.


推荐答案

JoeOs,

您可以通过PowerShell设置ProviderSignOutUri.

有类似的帖子:

更多参考:

使用SharePoint 2013和SAML退出.

https://samlman.wordpress.com /2015/02/27/signout-with-sharepoint-2013-and-saml/

如果要在对第一个SPFS应用程序进行ADFS身份验证之后自动对用户进行身份验证,则有一种解决方法,您可以通过将LogonTokenCacheExpirationWindow更改为小于以下值来增加SharePoint中会话的有效时间. SAML TokenLifetime.

if you want to automatically authenticate users after authenticating to the first SP app for ADFS, there is workaround, you can increase the valid time of the session in SharePoint by changing the LogonTokenCacheExpirationWindow to be less than the SAML TokenLifetime.

有关更多详细信息,请参阅下面的文章.

SharePoint应用程序的联合身份.

https://msdn.microsoft.com/en-us/library/hh446526. aspx

有类似的帖子:

https: //sharepoint.stackexchange.com/questions/79864/sharepoint-2013-adfs-login-local-token-cache-always-expired/81310#81310  

https://sharepoint.stackexchange.com/questions/79864/sharepoint-2013-adfs-login-local-token-cache-always-expired/81310#81310  

最诚挚的问候

萨拉范


这篇关于ADFS登出的文章就介绍到这了,希望我们推荐的答案对大家有所帮助,也希望大家多多支持IT屋!

查看全文
登录 关闭
扫码关注1秒登录
发送“验证码”获取 | 15天全站免登陆