Administrator Guide

Table Of Contents
If the authentication is successful, then you are logged into the Citrix session.
Configuring Citrix NetScaler using Okta
Okta provides Single Sign-On (SSO) capability using Remote Authentication Dial-In User Service (RADIUS) for Citrix Virtual
Apps and Desktops. ThinOS supports Okta through the Citrix NetScaler Gateway 11.0 or later. The Okta RADIUS Agent is
used for user authentication. The Okta RADIUS server agent assigns the user authentication to Okta using single-factor
authentication (SFA) or multifactor authentication (MFA).
For more information about configuring Citrix NetScaler Gateway to use the Okta RADIUS Agent, see the Citrix NetScaler
Gateway Radius Configuration Guide at help.okta.com.
NOTE:
On the ThinOS client, you need FQDN at the login window. If you do not use username@fqdn during login, you must
set the following INI parameter:
pnliteserver=https://<fqdn of NS Server> CAGUserAsUPN=yes
After you enable this INI parameter, the domain must use the domain.com format in the login window.
Phone authentication by using Okta is supported only in US and Canada.
Limitation
ThinOS version 8.6 supports only Okta with NetScaler Radius mode.
Citrix Cloud services
ThinOS supports Citrix Cloud services. It acts as a single management console to deploy applications or desktops on any virtual
or cloud setup for a secure digital workspace. For more information about Citrix Cloud services, see the Citrix Cloud article at
docs.citrix.com.
Configuring the connection brokers
99