A method is presented in which federated domains interact within a
federated environment. Domains within a federation can initiate federated
single-sign-on operations for a user at other federated domains. A
point-of-contact server within a domain relies upon a trust proxy within
the domain to manage trust relationships between the domain and the
federation. Trust proxies interpret assertions from other federated
domains as necessary. Trust proxies may have a trust relationship with
one or more trust brokers, and a trust proxy may rely upon a trust broker
for assistance in interpreting assertions. When a user requests to logoff
from a domain that has initiated federated single-sign-on operations for
the user at other federated domains, the domain initiates a consolidated
logoff operation by requesting logoff operations at those other federated
domains, which may also initiate logoff operations in a cascaded fashion
to the domains at which they have initiated federated single-sign-on
operations.