
User16674172739835246828 (Customer) asked a question.
Making a logout request:
<LogoutRequest xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" xmlns:xsd="http://www.w3.org/2001/XMLSchema" ID="id7d1c88c01b4e40cbb0a610749e701ac4" Version="2.0" IssueInstant="2024-01-30T23:05:28.7518256Z" Destination="xxx.okta.xxx" Reason="urn:oasis:names:tc:SAML:2.0:logout:user" xmlns="urn:oasis:names:tc:SAML:2.0:protocol" ><Issuer xmlns="urn:oasis:names:tc:SAML:2.0:assertion">https://localhost:44371/federation/saml2/signin</Issuer><NameID Format="urn:oasis:names:tc:SAML:1.1:nameid-format:unspecified" xmlns="urn:oasis:names:tc:SAML:2.0:assertion" >xxx@xxx.com</NameID><SessionIndex>id2def9c7f8fc949c79edab6419d64381b</SessionIndex></LogoutRequest>
This fails with:
<saml2p:Status xmlns:saml2p="urn:oasis:names:tc:SAML:2.0:protocol"><saml2p:StatusCode Value="urn:oasis:names:tc:SAML:2.0:status:RequestDenied" /></saml2p:Status>
The problem is I don't know why, and the UI logs don't show any entries from failed events, just successful ones.

Hi @User16674172739835246828 (Customer) , Thank you for reaching out to the Okta Community!
Based on the description you provided, it’s unclear if you already tried this, but I recommend checking the System Logs for the following event to see if it’s listed:
user.authentication.slo
Beyond that, the following articles might provide some additional items to look at:
https://support.okta.com/help/s/article/slo-fails-with-malformed-request?language=en_US
https://support.okta.com/help/s/article/slo-failure-invalid-signature?language=en_US
If my answer helped, remember to mark it as best to increase its visibility for other members of the Okta Community who might have the same questions as you.
Hope my answer helps!
--------------------------------
Subscribe Today: The Okta Community is on YouTube