Universal Logout supported apps
The following apps support Universal Logout.
Okta apps
These apps share an identity stack. The user is signed out of all of these apps when Universal Logout is triggered for any of them.
- Admin Console
- End-User Dashboard
- End-User Settings
- Okta Browser Plugin: The app list appears in the plugin when Universal Logout is triggered for this app. Users must, however, reauthenticate if they want to access these apps.
Third-party apps
The permissions required, implementation requirements, and Universal Logout behaviors are different for each of these apps.
- Box: See Create jobs to terminate users session.
- Dropbox for Business: See /devices/list_member_devices and /devices/revoke_device_session_batch.
- Google Workspace and Google Cloud Platform: These apps share an identity stack. If a user has access to both of these apps, they're signed out of both apps when Universal Logout is triggered for Google Workspace. See Method: users.signOut.
- Microsoft 365, Defender for Cloud Apps, Defender for Endpoint, Defender for Office 365, and Azure Portal: These apps share an identity stack and only provide a partial Universal Logout. Universal Logout only revokes their refresh tokens. User sessions aren't terminated until the user's existing access tokens expire or the user signs out. The token expiration timeout is different for each app. See Revoke user access in Microsoft Entra ID.
- PagerDuty: See Delete a user's session.
- Salesforce: See AuthSession.
- Slack: You can only enable Universal Logout for Slack Enterprise's Slack account. See admin.users.session.reset.
- Surf: This product suspends a user when Universal Logout is triggered. To unsuspend a user, restore the session through the Surf console or API. Contact Surf for support.
- Zendesk: See Delete Session.
- Zoom: See Revoke a user's SSO token.
Unsupported Okta apps
Universal Logout isn't available for the following Okta apps:
- Access Gateway
- Access Requests
- Identity Governance
- Privileged Access
- Workflows