This message was deleted.
# citrix-netscaler
s
This message was deleted.
p
Your AAA logon has a SsoUsername field. If using nfactor you can specify the factor to use the username from in sso in the login schema at that step
c
Either disable SSO to webapps on your VPN session profile or create a trafficaction to disable SSO and bind it where you want to selectively disable sso.
Smoking gun for this is usually seeing "NETSCALER" as the client name in the auth attempt on the web service.
d
Thanks guys - Preston it's SAML auth so ssousername isn't applicable in this case, but I've played around with extracting samAccountName from the saml assertion and presenting that using a traffic policy. Mike, I tried disabling SSO on the session profile and it broke a bunch of other internal access, so I've tried the traffic policy and had some limited success - it looks like first NTLM attempt presents upn username and hostname NETSCALER, receives a 401 then second NTLM attempt it presents domain\username and succeeds. I'll post up screenshots of the trace and policies if I still can't get it going.