Administrator Guide

Table Of Contents
Federated Authentication Service with Azure active directory
OKTA
Citrix two-factor authentication
ThinOS supports Citrix two-factor authentication that authenticates the identity of the user twice before granting access,
adding an extra level of security.
For local authentication, there must be a user profile that is created in the Citrix ADC database. For external authentication,
the username and password that is entered must be the same as registered in the authentication server. After a successful
validation of the username and password, the user is requested for another level of authentication.
ThinOS supports LDAP, RSA+LDAP, SMS Passcode, DUO, OKTA, and Azure MFA authentications by default. The user must only
provide the Citrix ADC gateway address.
To log in to NetScaler Gateway that uses LDAP with RSA authentication, you must select LDAP+RSA in the Wyse
Management Suite policy. You can also go to Admin Policy Tool and configure the NetScaler/ADC Authentication Method
option in the Citrix Broker Settings window.
For specific users who want to use Citrix ADC authentication methods, such as LDAP with MFA, it is recommended that you
configure the NetScaler/ADC Authentication Method with LDAP either using the Wyse Management Suite policy or the
Admin Policy tool.
Configure Citrix ADC using LDAP and RSA
About this task
This section describes how to configure the Citrix ADC (formerly NetScaler) using LDAP and RSA authentication.
Steps
1. Go to NetScaler > NetScaler Gateway > Virtual Servers, and click Edit.
2. Set the primary and secondary authentications based on the following scenarios:
If you use LDAP and RSA login, ensure that the primary authentication is LDAP and secondary authentication is RADIUS.
You must also ensure that the NetScaler Gateway Authentication Method in the Wyse Management Suite policy or
the Admin Policy Tool is configured as LDAP+RSA.
If you use RSA and LDAP login, ensure that the primary authentication is RADIUS and secondary authentication is LDAP.
If you use only LDAP login, ensure that the primary authentication is LDAP and secondary authentication is none.
3. Go to System Setup > Remote Connections > Broker setup, enter the Citrix ADC server address in the Broker Server
field.
4. Log off from the client desktop, or restart the thin client.
The login window for Citrix ADC is displayed.
For more information about configuring Citrix ADC with LDAP, RSA authentication, see the Citrix NetScaler Gateway Guide
at www.citrix.com.
Configuring Citrix ADC using DUO
About this task
To configure the Citrix ADC (formerly NetScaler) using DUO authentication, do the following:
Steps
1. Go to NetScaler > NetScaler Gateway > Virtual Servers, and click Edit.
2. Ensure that the primary authentication is RADIUS that is configured with the DUO authentication RADIUS.
3. Ensure that the secondary authentication is none.
4. Enter the broker address in the ThinOS user interface.
Configuring the connection brokerCitrix
79