Genesys Cloud - Main

 View Only

Sign Up

  • 1.  Auto login issue

    Posted 9 hours ago

    Hi everyone,

    We are investigating an issue in Genesys Cloud where an agent logs out normally, but is automatically logged back in without taking any action.

    We observed this with one agent, and are trying to determine whether anyone else has experienced something similar.

    What we are seeing

    The sequence appears to be:

    1. The agent logs out of Genesys Cloud.
    2. The Genesys Cloud session appears to terminate successfully.
    3. The agent does not perform any further action.
    4. After some time, the agent is automatically logged back into Genesys Cloud.
    5. The agent becomes available/on queue again.
    6. Incoming calls are then routed to the agent.
    7. Since the agent is no longer physically at the workstation, the calls eventually go into "NOT RESPONDING."

    What we are investigating

    One possible explanation we are considering is related to our SSO configuration and Single Logout.

    Our understanding is that if the Genesys Cloud session is terminated but the Identity Provider (IdP) session remains active, the browser could potentially authenticate the user again automatically.

    We are therefore checking whether the following SSO settings could be relevant:

    • Single Logout URI
    • Single Logout Binding Identity Provider
    • The behavior of the Identity Provider session after logging out of Genesys Cloud
    • Browser cookies/session tokens that may still be active

    However, we have not yet confirmed that SSO is the root cause.

    Questions for the community

    Has anyone experienced a similar situation where:

    • An agent logs out of Genesys Cloud;
    • The agent is automatically logged back in without any interaction;
    • The agent subsequently becomes available/on queue;
    • Calls are routed to the agent and eventually show as "NOT RESPONDING"?

    If yes, could you please share:

    • Which Identity Provider/SSO solution you are using?
    • Whether Single Logout is configured?
    • Whether the issue occurs for one user or multiple users?
    • Whether it happens consistently or only occasionally?
    • Whether the browser is left open after logout?
    • Whether you identified the cause or a permanent fix?

    Any similar experiences, troubleshooting steps, or recommendations would be greatly appreciated.

    Thanks!


    #API/Integrations
    #Implementation
    #System/PlatformAdministration
    #Telephony
    #Other

    ------------------------------
    Sandor Berei-Ozsvath
    NA
    ------------------------------


  • 2.  RE: Auto login issue

    Posted 8 hours ago

    Hi Sandor,

    One thing I would check before focusing only on SSO is how the agent is leaving Genesys Cloud.

    When the agent logs out, are they still On Queue, or do they first go Off Queue and then log out?

    Genesys Cloud has an organization-level setting called Renew Presence on Reconnect, which can restore the user's previous presence when they reconnect within the configured time frame. This behavior can also be configured to restore the On Queue state.

    Reference:
    https://help.mypurecloud.com/articles/restore-previous-presence-for-agents-who-disconnect-and-then-reconnect-to-genesys-cloud/

    So, if the agent was still On Queue when the session disconnected and the SSO session caused an automatic reconnection, this could potentially explain why they returned On Queue without manually selecting it.

    However, if the agent explicitly goes Off Queue first and then logs out, but after the automatic login they still return On Queue, I would look for something else changing the routing status.

    For example, do you have any Trigger, Workflow, Data Action, integration, or external process that automatically places agents On Queue after login? I've seen implementations where this behavior is intentionally automated.

    I would test both scenarios separately:

    1. On Queue → Logout → automatic reconnect
    2. Off Queue → Logout → automatic reconnect

    That should help determine whether the On Queue behavior is related to presence restoration or to some separate automation.

    The SSO/Single Logout issue may explain the automatic authentication, but I would treat the automatic return to On Queue as a separate part of the investigation.



    ------------------------------
    Raphael Poliesi
    ------------------------------



  • 3.  RE: Auto login issue

    Posted 8 hours ago

    Hi Sandor,

    Good points above, particularly separating the automatic authentication from the return to On Queue.

    For the authentication side, I also found a Genesys FAQ describing similar behaviour where users can be automatically logged back in through SSO. Genesys recommends ensuring Single Logout is configured correctly, so I think the SSO/IdP session is definitely worth checking as part of the investigation.

    https://help.genesys.cloud/faqs/my-users-are-getting-logged-back-into-single-sign-on-automatically-after-supervisors-log-them-out-is-there-a-resolution/

    Since you're currently seeing this with only one agent, I'd also compare that user's browser/IdP session and other active Genesys clients with an unaffected user.

    Combining that with the On Queue vs Off Queue logout test suggested above should help isolate whether you're dealing with two behaviours: automatic SSO re-authentication and presence restoration.



    ------------------------------
    Phaneendra
    Technical Solutions Consultant
    ------------------------------



  • 4.  RE: Auto login issue

    Posted 7 hours ago

    Hi Phaneendra,

    Thank you for your answer!

    This happened in the past with a couple of agents , just we couldn't collect the logs for them at that time,

    as this was strange from the start , and we thought this could be a user error or something.

    We checked all the SSO configuration but everything is configured correctly , single sign-on uri, single sign-on Binding, single logout uri and binding as well.

    One thing in which I'm not sure is the "Redirect to IdP with ForceAuthn flag on Inactivity Timeout" if this option needs to be active or not , could this option be the culprit or there is something else.

    Thanks,

    Sandor



    ------------------------------
    Sandor Berei-Ozsvath
    NA
    ------------------------------



  • 5.  RE: Auto login issue

    Posted 6 hours ago

    Thanks Sandor. I had another look at the "Redirect to IdP with ForceAuthn flag on Inactivity Timeout" setting. From the description, this specifically controls the redirect behaviour when an inactivity timeout occurs, either redirecting the user to the IdP with ForceAuthn or to the Genesys Cloud login page.

    Based on that, I wouldn't expect this setting itself to explain a user who manually logged out, particularly the case where the agent subsequently shut down their PC but later appeared online and received calls.

    Given that you've confirmed Single Logout URI/binding are configured, Renew Presence on Reconnect is disabled, and this has now occurred periodically for multiple agents, I think it would be worth raising a Genesys Care case.

    If you can reproduce it again, capturing the exact logout/re-login timestamps, user details, audit events and any available client logs should hopefully allow Care to correlate them with the platform-side logs and determine what is re-establishing the session.

    Please keep us posted - I'd be very interested to know what the root cause turns out to be.



    ------------------------------
    Phaneendra
    Technical Solutions Consultant
    ------------------------------



  • 6.  RE: Auto login issue

    Posted 7 hours ago

    Hi Raphael,

    Thank you for your answer!

    The renew presence option is not enabled, so this could not affect this scenario.

    This was tested both ways but the issue is that this happens only periodically.

    Also when this issue first happened the agent (we dont know which method) logged out from Genesys then shut down the PC,

    after that the colleagues saw that was online and reports showed that calls arrived to her.

    while this agent was with his PC off.

    Thanks,

    Sandor



    ------------------------------
    Sandor Berei-Ozsvath
    NA
    ------------------------------



  • 7.  RE: Auto login issue

    Posted 8 hours ago
    Thank you for your question. After reviewing the available community discussions, we could not find any report that matches your exact scenario-where an agent is automatically logged back in after a manual logout. That said, your initial hypothesis regarding SSO and Single Logout (SLO) is highly plausible, and the existing documentation and community threads offer useful pointers for your investigation.
     
    Your suspicion about SSO is well founded. In Genesys Cloud, the Single Logout feature relies on a certificate that is used to sign and verify logout requests and responses. If this certificate is expired, misconfigured, or not properly synchronized between Genesys Cloud and your Identity Provider (IdP), the system may fail to process the logout correctly. This could leave the user session in an indeterminate state, potentially leading to automatic re-authentication if the IdP session remains active and the browser still holds valid cookies. A Genesys Cloud moderator has specifically highlighted two configuration settings as particularly relevant: the Single Logout URI, which defines the endpoint for logout requests, and the Sign Authentication Requests checkbox, which, when enabled, ties into certificate management and deeper SSO integration.
     
    To determine whether SSO misconfiguration is the root cause, start by navigating to Integrations > Single Sign-On in your Genesys Cloud admin console and reviewing your IdP settings. First, check whether the Single Logout URI field is populated-if it is blank, SLO is not configured, and the issue likely lies elsewhere. Second, verify whether the Sign Authentication Requests checkbox is selected; if it is, your system is signing authentication requests, which indicates a more complex SSO setup that could affect session handling. If either of these features is enabled, you should then confirm that the associated SSO certificate is current and correctly installed on both the Genesys Cloud and IdP sides.
     
    The community discussions reinforce a few key points. First, Single Logout is the primary feature to examine when troubleshooting unexpected login or logout behavior. Second, certificate misconfiguration is a common pitfall-Genesys Cloud uses a public certificate for signing SLO requests, and that certificate must be uploaded to your IdP for the process to work properly. Third, many organizations leave the Single Logout URI empty, which effectively disables SLO; those organizations typically do not encounter this type of issue and do not need to manage the associated certificates. While these insights are helpful, it is important to note that the exact behavior you are observing has not been widely reported, suggesting you may be dealing with a specific interaction between Genesys Cloud, your browser's persistent cookies, and your IdP's session handling logic.
     
    Based on this, we recommend the following troubleshooting steps. First, confirm your SLO and certificate settings in the Genesys Cloud admin console. Second, log in to your Identity Provider (Okta, Azure AD, etc.) and verify that the correct Genesys Cloud SSO certificate has been uploaded and that the Single Logout endpoint and binding settings match what Genesys Cloud expects. Third, check that the certificate has not expired and that the signature algorithm is supported by both systems. Finally, since you have observed this with a single agent so far, consider testing the behavior under controlled conditions-for example, with browser developer tools open to monitor network traffic and cookies-to determine whether the re-authentication is triggered by a new SAML assertion or by a silent redirect. As a further diagnostic step, you might temporarily disable SLO for a test user to see if the issue persists, which can help isolate whether SSO is indeed the trigger.
     
    In summary, while community discussions confirm that SLO and certificate management are common sources of session-related anomalies, the specific behavior you described is not widely documented. It is likely that you are encountering a unique interaction between the Genesys Cloud session, your browser's cookie persistence, and your IdP's session management. If you can confirm whether SLO is enabled and whether the certificate is correctly configured, we may be able to narrow down the root cause further. Please feel free to share any additional details about your IdP and SLO configuration, and we will do our best to assist you further.


    ------------------------------
    Camila Meneghini
    ------------------------------



  • 8.  RE: Auto login issue

    Posted 7 hours ago

    Hi Sandor,

    This is very basic but have we checked if the user has any other active Genesys Cloud clients connected (Desktop App, another browser profile, VDI session, mobile app, or a previously suspended workstation session). 

    We can review the user's login/authentication events and session activity around the exact timestamp of the logout and subsequent re-login. Also compare the source details (client type, IP address, user agent, workstation) between the logout and the later login event.

    Since it has been observed only for a single user (so far), the Org-wide-platform configuration is most-probably correct.

    thanks


    ------------------------------
    Ashiesh Sharma
    GCX- GCP, ARC, SCR, QM
    Producer | Conductor | Composer
    BT plc
    ------------------------------