SAML认证后关闭浏览器重开,ServiceNow如何识别已登录?
Awesome question—this is such a common gotcha with SAML SSO and how enterprise apps like ServiceNow hang onto your session! Let’s break this down clearly:
The short answer: Yes, your browser is storing persistent cookies that both ServiceNow and ADFS use to recognize your authenticated state. Here’s the full breakdown:
1. ServiceNow’s Persistent Session Cookie
Once you finish the ADFS SAML login flow, ServiceNow drops a session cookie in your browser (usually something like glide_session_id or JSESSIONID, depending on the instance setup). This cookie acts as a "proof of authentication"—ServiceNow’s backend uses it to look up your active user session and grant access without re-authenticating you.
Most enterprise apps (including ServiceNow) set these cookies with an explicit Expires or Max-Age attribute, making them persistent. Unlike session-only cookies (which get deleted when you close the browser), persistent cookies stick around until their expiration date. That’s why reopening the browser lets you jump right back in.
2. ADFS’s Persistent SSO Cookie
ADFS also plays a role here—it sets its own persistent cookies (like MSISAuth or MSISAuthenticated) in your browser when you first log in. If your ServiceNow session ever expires, accessing the app will redirect you to ADFS. Instead of asking for your username/password again, ADFS reads this cookie, confirms you’re still authenticated, and automatically sends a new SAML assertion to ServiceNow to re-establish your session.
How to Verify This Yourself
Want to see these cookies in action? It’s easy:
- Open your browser’s dev tools (hit F12)
- Go to the Application tab (Chrome) or Storage tab (Firefox)
- Expand the Cookies section in the left sidebar:
- Select your ServiceNow instance’s domain to see the app’s session cookie
- Select your ADFS domain to view the SSO-related cookies
Quick Summary
- ServiceNow uses its own persistent session cookie to recognize you immediately when you reopen the browser
- ADFS’s persistent cookie handles silent re-authentication if your ServiceNow session ever times out
内容的提问来源于stack exchange,提问作者Jay

