This message was deleted.
# citrix-netscaler
s
This message was deleted.
k
We'll if you had local authentication before, the Gateway "knew" your credentials (user/pass), but now you have the SAML claim for the GW/AAA vServer, so SSO is not possible.
If you need to capture the on-prem credentials during logon, you could achieve that with nFactor, but I think that's not a valid option end uesr-wise. The best option would be to have the internal applications modernized so that they accept SAML/OIC. Then you just need to decide whether to use the GW/AAA as the IdP or the AAD. Latter one is more common I think.
c
Hi Kari, this is what I thought was happening, thanks for validating.