Users can't sign out of Office 365 web services

Article ID: 2507767 - View products that this article applies to.

Not sure what release of Office 365 you're using? Go to the following Microsoft website:
Am I using Office 365 after the service upgrade?
Expand all | Collapse all

On This Page

PROBLEM

Users experience one of the following scenarios in Microsoft Office 365:

Scenario 1

  • When a user signs out of Office 365 portal or out of Outlook Web App, the user isn't signed out of Microsoft SharePoint Online.
  • When a user signs out of SharePoint Online, the user isn't signed out of the Office 365 portal or out of Outlook Web App.

Scenario 2

  1. A user signs in to an Office 365 web service such as the Office 365 portal, Outlook Web App, or SharePoint Online.
  2. The user tries to take one of the following actions:
    • To sign out of the web service
    • To sign in to the web service as a different user by using the user interface link on the webpage
In this scenario, the user can't sign out of the web service or sign in to the web service as a different user.

For example, when the user clicks Sign out, the user isn't signed out of the web service. Instead, the web browser reloads the current webpage.

SOLUTION

To work around this behavior and sign in to Office 365 resources as a different user, use one of the following methods.

Method 1

  1. Clear the web browser cache and cookies.
  2. Close the web browser, and then reopen the web browser.
  3. Visit the webpage for the resource that you want to access, and then sign in as a different user.

Method 2

Use the InPrivate Browsing feature in Internet Explorer to access Office 365 web services.

Method 3

Remove microsoftonline.com entries from the Trusted sites zone and from the Local Intranet zone in Internet Explorer.

Note This method doesn't work for Scenario 1 of the "Symptoms" section.

MORE INFORMATION

This behavior is by design. Office 365 web sessions are maintained by web browser cookies.

The sign-out process for web services forces the session cookies to expire. These session cookies are used to maintain the application session. However, because the web browser is still running, the user still has a valid authentication cookie and isn't required to sign in to the resource again. By default, this authentication cookie is valid for eight hours. It is force-cleared only when the user closes the web browser.

Therefore, when the web browser tries to reload the application sign-in screen when a user signs out, the session cookie is cleared. However, the web browser is instantly authenticated by the authentication cookie. This authentication signs the user back in to the web application, and a new session cookie is generated.

All web portals store a session cookie in memory that has a Time to Live (TTL) value. When the session cookie expires, the web browser is redirected to the logon server to obtain a new service token at the following website:
https://login.microsoftonline.com
When the web browser is closed, the session cookie is removed from memory, and the user must sign in again. However, web services maintain a cookie for several hours. This means that the following conditions are true:
  • When you close and then reopen your web browser, you aren't prompted to enter your credentials to access the site. Instead, you're automatically signed in to the site.
  • The session cookie can be used by Office rich client applications.

Still need help? Go to the Office 365 Community website.

Properties

Article ID: 2507767 - Last Review: May 31, 2013 - Revision: 25.0
Applies to
  • Microsoft Office 365 for enterprises (pre-upgrade)
  • Microsoft Office 365 for small businesses  (pre-upgrade)
  • Microsoft Office 365 for education  (pre-upgrade)
  • Microsoft SharePoint Online
  • Microsoft Exchange Online
Keywords: 
o365 o365a o365e o365p o365062013 after upgrade o365062011 pre-upgrade o365m KB2507767

Give Feedback