When you create an enterprise app in Azure AD and configure SAML-based single sign-on, the portal shows you the Login URL and Logout URL that your application needs to use. For most applications from the catalog (including the Google Cloud one), it looks like this: If you look closely, you notice that the Login URL and Logout URL are the same – both read https://login.microsoftonline.com/[Tenant-Id]/saml2. This is consistent with the federation metadata: <IDPSSODescriptor protocolSupportEnu...