Administrator Guide

Table Of Contents
9. If you are using mobile app, approve the notification. If you are using the authentication phone, verify your information
through a phone call or a text code.
10. Log in to Citrix ADC and launch the session.
Enable Azure AD Self-Service Password Reset function for Citrix ADC Single
Sign-on with SAML authentication
Prerequisites
1. Create an Azure AD user in Azure Active Directory.
2. Add the user to Azure AD Citrix ADC (formerly NetScaler) Enterprise application users and groups.
3. Ensure that the shadow account of the user exists in local domain users group.
4. Ensure that Self-Service Password Reset Enabled option is selected in Azure AD for the user.
About this task
This section describes how to enable Azure AD Self-Service Password Reset function for Citrix ADC Single Sign-on with SAML
authentication.
Steps
1. On the Broker setup tab, enter the Citrix ADC Gateway URL, and click OK.
The login window is displayed.
2. Enter the user credentials of the Azure AD user and click Next.
3. On the Don't lose access to your account! page, configure the following options:
Authentication Phone
a. Click Set it up now.
b. From the drop-down list, select your country code.
c. Enter your phone number.
d. Click either text me or call me.
A verification code is received on your phone by call or text message.
e. Enter the verification code and click Verify.
Authentication Email
a. Click Set it up now.
b. Enter the valid email address.
c. Click email me.
A verification code is sent to your email.
d. Enter the verification code and click Verify.
4. Click Finish.
5. Continue with the user login.
Configure Citrix NetScaler using Okta
Okta provides Single Sign-On (SSO) capability using Remote Authentication Dial-In User Service (RADIUS) for Citrix Virtual
Apps and Desktops. ThinOS supports Okta through the Citrix NetScaler Gateway 11.0 or later. The Okta RADIUS Agent is
used for user authentication. The Okta RADIUS server agent assigns the user authentication to Okta using single-factor
authentication (SFA) or multifactor authentication (MFA).
For more information about configuring Citrix NetScaler Gateway to use the Okta RADIUS Agent, see the Citrix NetScaler
Gateway Radius Configuration Guide at help.okta.com.
NOTE:
On the ThinOS client, you need UPN at the login window.
Phone authentication by using Okta is supported only in US and Canada.
82 Configuring the connection brokerCitrix