PROBLEM

Enterprise logins cache user credentials

Last Published: April 25, 2020

Description

Attempting to log in to ArcGIS Online with an enterprise login on a shared machine automatically logs in with the last used enterprise account, despite logging out from the previous session. This unintentionally allows users to log in to ArcGIS Online with a previously logged out administrator account, providing non-authorized personnel access to sensitive information and critical system settings.

Cause

The security settings for enterprise logins are not configured.

Solution or Workaround

Follow the steps below to resolve the issue:

  1. Log in to ArcGIS Online with an administrator account.
  2. Navigate to Organization > Settings > Security > Enterprise Logins > Edit Enterprise Login.
  3. Click Show advanced settings.
  4. Check the Enable Signed Request, Sign using SHA256, Propagate logout to Identity Provider, Update profiles on sign in, and Enable SAML based group membership check boxes. Click Update Identity Provider.
Check the necessary check boxes
  1. Download the service provider metadata and reapply it to the enterprise identity provider (IDP).
  2. Clear the web browser cache.

The system now prompts for a sign in when accessing ArcGIS Online, and no longer automatically signs in with the last used account.

Article ID:000022073

Software:
  • ArcGIS Online

Receive notifications and find solutions for new or common issues

Get summarized answers and video solutions from our new AI chatbot.

Download the Esri Support App

Related Information

Discover more on this topic

Get help from ArcGIS experts

Contact technical support

Download the Esri Support App

Go to download options