---
title: Implement SSO and SLO
description: Implement SAML 2.0 single sign-on and single logout using integrated or standalone mode with PingAM
component: pingam
version: 7.5
page_id: pingam:am-saml2:saml2-sso-slo
canonical_url: https://docs.pingidentity.com/pingam/8.1/am-saml2/saml2-sso-slo.html
llms_txt: https://docs.pingidentity.com/pingam/llms.txt
docs_for_agents: https://developer.pingidentity.com/build-with-ai/docs-for-agents.md
keywords: ["SAML 2.0", "Single Sign-on (SSO)", "Federation"]
page_aliases: ["saml2-guide:saml2-sso-slo.adoc"]
superseded_by: https://docs.pingidentity.com/pingam/8.1/am-saml2/saml2-sso-slo.html
---

# Implement SSO and SLO

AM provides two options for implementing SSO and SLO with SAML 2.0:

* Integrated mode

  Integrated mode single sign-on and single logout uses a SAML2 authentication node or module on a service provider (SP), thereby integrating SAML 2.0 authentication into the AM authentication process. The authentication node or module handles the SAML 2.0 protocol details for you.

  Note that **integrated mode supports SP-initiated single sign-on only**, because the authentication service that includes the SAML 2.0 node or module resides on the SP. You cannot trigger IDP-initiated single sign-on in an integrated mode implementation.

  Integrated mode with chains supports both IDP-initiated and SP-initiated SLO.

  Integrated mode with trees does not support SLO.

* Standalone mode

  Standalone mode requires that you invoke JSPs pages to initiate single sign-on and SLO. When implementing standalone mode, you do not require an AM authentication chain.

|   |                                                                                                                                                                         |
| - | ----------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
|   | You can also configure web and Java agents to work alongside AM when performing SSO and SLO. See [Web or Java agents SSO and SLO](using-saml2-with-policy-agents.html). |

The following table provides information to help you decide whether to implement integrated mode or standalone mode for your AM SAML 2.0 deployment:

**Integrated or Standalone Mode?**

| Deployment task or requirement                                                                                                                                                 | Implementation mode                                |
| ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------ | -------------------------------------------------- |
| You want to deploy only SAML 2.0 SSO using the easiest technique.                                                                                                              | Use [integrated mode](saml2-integrated-mode.html). |
| You want to deploy both SAML 2.0 SSO and SLO.                                                                                                                                  | Use [standalone mode](saml2-standalone-mode.html). |
| You want to integrate SAML 2.0 authentication into an authentication chain, letting you configure an added layer of login security by using additional authentication modules. | Use [integrated mode](saml2-integrated-mode.html). |
| You want to trigger SAML 2.0 IdP-initiated SSO.                                                                                                                                | Use [standalone mode](saml2-standalone-mode.html). |
| You want to use the SAML 2.0 Enhanced Client or Proxy (ECP) single sign-on profile.                                                                                            | Use [standalone mode](saml2-standalone-mode.html). |
| Your IDP and SP instances are using the same domain name; for example, `mydomain.net`.(1)                                                                                      | Use [standalone mode](saml2-standalone-mode.html). |

(1) Due to the way integrated mode tracks authentication status by using a cookie, it cannot be used when both the IDP and SP share a domain name.
