
MatthewH.10249 (State of Iowa) asked a question.
We have 2 Okta tenants that we have established an Org2Org hub-and-spoke model. When an OIDC app is established on the Hub tenant that has users that redirect to the spoke tenant for authentication, is there a way to log them out of both Hub and Spoke tenant using SLO? Currently we only are able to log them out of the Hub app. The issue with this is that we want to force MFA every login and when the user logs out of the app and then tries to log back in they are redirected to the Spoke app for which they already have an active session and thus not prompted for a password or MFA and are automatically redirected and reauthenticated in the Hub app. Mainly looking for a way to force MFA every time someone tries to access the app on the Hub tenant.

Hello @MatthewH.10249 (State of Iowa) Thank you for posting on our Community page!
There are a few things you can do here:
Okta has a specific feature called "Single Logout for IdPs". This is designed exactly for your situation!
When you log out of your Hub app, this feature tells the Spoke Okta tenant to also end its session for that user. For this you need to reach out to Okta Support to have this feature enabled for your tenants.
Thank you for reaching out to our Community and have a great day!
--
Help others in the community by liking or hitting Select as Best if this response helped you.
Just released: More Okta Community badges just added.