Administrator Guide

Table Of Contents
If you access the Broker agent using SAML, lock terminal is not supported as it is a web-based authentication. When you try to
use lock terminal, a message is displayed where you can click either Continue to log off or click Cancel to stay on the screen.
You are automatically signed off from the account in sixty seconds for security purposes.
Figure 25. Unable to lock account
Enable Azure Multiple Factor Authentication for Citrix ADC Single Sign-on with SAML
Authentication
Prerequisites
Create an Azure AD user in Azure Active Directory.
Enable the Multiple Factor Authentication (MFA) for the user.
Add the user to Azure AD Citrix ADC (formerly NetScaler) Enterprise application users and groups.
Ensure that the shadow account of the user exists in local domain users group.
Ensure that the SAML authentication policy is enabled. For more information, see the NetScaler Gateway documentation at
docs.citrix.com.
About this task
This section describes how to log in to Citrix ADC using SAML with Azure Multiple Factor Authentication.
Steps
1. From the desktop menu, click System setup > Remote Connections.
The Remote Connections dialog box is displayed.
2. On the Broker Setup tab, select Citrix Virtual Apps and Desktops from the Broker Type drop-down list.
3. Enter the Citrix ADC Gateway URL in the Broker Server field, and click OK.
The login window is displayed.
4. Enter the username of the Azure AD user and click Next.
5. Enter the initial password for the Azure AD user, and click Sign in.
6. In the More information required window, click Next.
7. On the Additional Security Verification page, do the following:
a. From the How should we contact you? drop-down list, select any one of the following methods:
Authentication phone
Mobile app
b. If you select Authentication phone, enter your phone number. If you select Mobile App, click Set up and follow the
on-screen instructions to add an account to the Microsoft authenticator app.
c. Click Save.
8. Enter the Azure AD username with the initial password again.
9. If you are using mobile app, approve the notification. If you are using the authentication phone, verify your information
through a phone call or a text code.
10. Log in to Citrix ADC and launch the session.
Configuring connection brokers
71