In practice, logout in a federated environment seems to be
* A user logs into apps A, B, C (...)
* While using app C, the user clicks logout. App C trashes their cookies
* With luck(!) the IdP provides a low friction logout endpoint – think "GET /logout?redir=http://foo.bar/logged-out".
The app redirs to that endpoint, the IdP trashes cookies and directs back to the apps "you have been logged out" page.
Apps A and B? Go with god, and good luck. Keep your sessions short.