How to do Global single signout?

Asad Shaikh 0 Reputation points
2025-10-07T10:04:07.82+00:00

Hello, I wanted to implement single sign out feature for a my app. But i want something like this: When i logout of my app, I want the user to log out of all other apps as well.

Like i logout of my app 'X' then it should also logout the user from apps registered under same tenant as well as microsoft's app like Microsoft Viva engage, etc.
I am able to log the user out of the apps registered under my tenant, but unable to logout the user from Viva engage app. I also tried using the revokeSignInSessions, but it doesnt logout the user instantly from microsoft's app. This is what i have tried:

I hit this endpoint:
https://login.microsoftonline.com/<tenant_id>/oauth2/v2.0/logout?post_logout_redirect_uri=http%3A%2F%2Flocalhost%3A8080%2Fauth%2Fentra%2Flogout%2Fcallback

After callback is received, I use revokeSignInSessions which was successful: https://graph.microsoft.com/v1.0/me/revokeSignInSessions

still when I open the Viva Engage on browser, it somehow logs in the user tokens stored in it's cache (i guess)
I want instant logout from every app (apps registered under my tenant as well as microsoft's apps).

Is there a way to implement this? something like a global logout? Is this possible?

Microsoft Security | Microsoft Entra | Microsoft Entra ID
0 comments No comments

Answer recommended by moderator
Asad Shaikh 0 Reputation points
2025-10-10T06:41:42.0766667+00:00

Hi @Tom Tran (WICLOUD CORPORATION) ,

Thank you for the detailed clarification.

After reviewing your recommendations, I have finalized the following approach for our logout flow:

  1. RP-initiated logout: I am implementing the standard OIDC RP-initiated logout to ensure that users are signed out through Microsoft Entra ID and all other relying parties (apps) under the same tenant are notified through front-channel logout.
  2. Session revocation: Post logout, I am calling the Microsoft Graph /revokeSignInSessions API to invalidate refresh tokens and revoke any active sessions for the user. This helps ensure that future token refreshes are blocked.
  3. User prompt for browser closure: Since certain applications (like Viva Engage) maintain local session data or caches that are not directly cleared via Entra logout, I will display a user prompt recommending the closure of the browser window to complete the logout process cleanly (because I can't clear Viva Engage's cookies).

We have intentionally not reduced the access token lifetime, for the following reasons:

  • User Experience: Shorter access token lifetimes would result in frequent re-authentications or background token refresh calls, potentially degrading usability.
  • Performance Considerations: Reducing token validity increases network traffic and token issuance volume, which could impact performance and cause throttling under high load.
  • Limited Security Benefit: Even with shorter lifetimes, active tokens remain valid until expiration. Therefore, this approach does not provide true real time revocation, unlike CAE and session revocation.

Thank you!

Was this answer helpful?

0 comments No comments

1 additional answer

Sort by: Most helpful
  1. Tom Tran (WICLOUD CORPORATION) 5,945 Reputation points Microsoft External Staff Moderator
    2025-10-08T04:13:51.16+00:00

    Hi @Asad Shaikh ,

    Thanks for the details!

    So you’re looking for a global single sign-out so that logging out of your app also signs the user out of other apps in the same tenant and Microsoft apps like Viva Engage. After looking into this topic:


    Is there a way to implement this? something like a global logout? Is this possible?

    A truly instant global logout across all Microsoft 365 apps is not currently possible. Here’s why:

    • Microsoft Entra ID can end its own session and revoke refresh tokens, but active access tokens remain valid until they expire (usually ~1 hour) unless the app supports Continuous Access Evaluation (CAE).
    • Each app controls its own session cookies. Entra can signal logout, but the app must clear its own state.

    What you can possibly do:


    End the Entra session using RP-Initiated Logout

    https://login.microsoftonline.com/{tenant_id}/oauth2/v2.0/logout?id_token_hint={id_token}&post_logout_redirect_uri={redirect_uri}
    

    This clears the central session and broadcasts front-channel logout to apps that support it.

    Reference: RP-Initiated Logout


    Implement Front-Channel Logout in your apps

    Each app should have a logout page that clears cookies/local storage when loaded in an iframe.

    Reference: Front-Channel Logout


    Revoke refresh tokens

    Use Microsoft Graph:

    POST https://graph.microsoft.com/v1.0/me/revokeSignInSessions
    

    This invalidates refresh tokens but may take a few minutes to propagate. Reference: revokeSignInSessions


    Leverage Continuous Access Evaluation (CAE)

    CAE-enabled apps (Exchange, SharePoint, Teams) will drop tokens almost instantly after revocation. Viva Engage may not fully support CAE yet. Reference: CAE Overview


    Global sign-out is a layered process - central logout, token revocation, and app-specific cleanup. Some apps will sign out immediately, others after token expiry or their next validation.


    Hope this helps! If you have any questions, please leave a comment below!

    Was this answer helpful?


Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.