Administrator Guide

Table Of Contents
Figure 56. PASSCODE
If the authentication is successful, then you are logged into the Citrix session.
Okta Integration through Citrix NetScaler
Okta provides Single Sign-On (SSO) capability using Remote Authentication Dial-In User Service (RADIUS) for Citrix Virtual
Apps and Desktops. ThinOS Lite supports Okta through the Citrix NetScaler Gateway 11.0 or later. The Okta RADIUS Agent
is used for user authentication. The Okta RADIUS server agent assigns the user authentication to Okta using single-factor
authentication (SFA) or multifactor authentication (MFA).
For more information about configuring Citrix NetScaler Gateway to use the Okta RADIUS Agent, see the Citrix NetScaler
Gateway Radius Configuration Guide at help.okta.com.
NOTE:
On the ThinOS Lite-based client, if you do not use username@fqdn, you must set the following INI parameter:
pnliteserver=https://<fqdn of NS Server>
CAGUserAsUPN=yes
After you enable this INI parameter, the domain must use the domain.com format in the login window.
Phone authentication by using Okta is supported only in US and Canada.
Configuring ICA connections
To configure the ICA connections, use the following guidelines:
NOTE: Set the INI EnableLocal=yes to show the Default ICA icon in connect manager.
1. Go to Home icon > Connect Manager > Default ICA > Edit.
2. Click the Connection tab, and use the following guidelines:
Configuring the connection broker
77