When checked, single sign-out is enabled: whenever the user logs out of CAS (e.g. when logging out of another CAS-enabled application), the corresponding Jenkins session will be destroyed and the local user logged out as well.

Note that for this to work, the CAS server must be able to communicate with Jenkins using the service URL that was passed to it during login.