Thanks guys - Preston it's SAML auth so ssousername isn't applicable in this case, but I've played around with extracting samAccountName from the saml assertion and presenting that using a traffic policy.
Mike, I tried disabling SSO on the session profile and it broke a bunch of other internal access, so I've tried the traffic policy and had some limited success - it looks like first NTLM attempt presents upn username and hostname NETSCALER, receives a 401 then second NTLM attempt it presents domain\username and succeeds. I'll post up screenshots of the trace and policies if I still can't get it going.