SAML Logout Name Identifier Not Found Error

Microsoft.ActiveDirectoryFederationServices.2016.TokenAcceptanceSamlLogoutNameIdentifierNotFoundErrorRule (Rule)

Knowledge Base article:


SAML logout failed because the SAML Single Logout request does not correspond to the logged-in session participant.


The following are possible causes for this event:


Verify that the claims provider trust or the relying party trust configuration is up to date. Use the AD FS snap-in to make the format of the name ID rule for this partner and its SPNameQualifier value match the name ID that is present in the logout request.

Element properties:

Alert GenerateTrue
Alert SeverityWarning
Alert PriorityNormal
Alert Message
SAML Logout Name Identifier Not Found Error
The SAML Single Logout request does not correspond to the logged-in session participant. Check the Alert Context tab for event details about the requester and the logged-in session participant.
Event Log$Target/Host/Host/Property[Type="Microsoft.ActiveDirectoryFederationServices.2016.FederationServer"]/ADFSEventLog$

Member Modules:

ID Module Type TypeId RunAs 
DS DataSource Microsoft.Windows.EventProvider Default
Alert WriteAction System.Health.GenerateAlert Default

Source Code:

<Rule ID="Microsoft.ActiveDirectoryFederationServices.2016.TokenAcceptanceSamlLogoutNameIdentifierNotFoundErrorRule" Enabled="true" Target="Microsoft.ActiveDirectoryFederationServices.2016.TokenAcceptance" ConfirmDelivery="true" Remotable="true" Priority="Normal" DiscardLevel="100">
<DataSource ID="DS" TypeID="Windows!Microsoft.Windows.EventProvider">
<XPathQuery Type="UnsignedInteger">EventDisplayNumber</XPathQuery>
<Value Type="UnsignedInteger">368</Value>
<XPathQuery Type="String">PublisherName</XPathQuery>
<Pattern>(^AD FS$)</Pattern>
<WriteAction ID="Alert" TypeID="Health!System.Health.GenerateAlert">