diff --git a/x-pack/docs/en/security/authentication/saml-guide.asciidoc b/x-pack/docs/en/security/authentication/saml-guide.asciidoc index 1e1b9c56c16a8..b994a0709293f 100644 --- a/x-pack/docs/en/security/authentication/saml-guide.asciidoc +++ b/x-pack/docs/en/security/authentication/saml-guide.asciidoc @@ -402,6 +402,7 @@ services it offers. By default the Elastic Stack will support SAML SLO if the following are true: - Your IdP metadata specifies that the IdP offers a SLO service +- Your IdP releases a NameID in the subject of the SAML assertion that it issues for your users - You configure `sp.logout` - The setting `idp.use_single_logout` is not `false`