Managed to get nfactor working i have a login schema with username only bound to my AAA vserver that just does group extraction next factor looks at AD group membership if your a member of AD group MFA1 you get the policy label mfa1 as next factor which does ldap/radius using mobile pass with a dual auth login schema. If your a member of AD group MFA2 you get the policy label MFA2 which does ldap/radius for azure mfa. I might look at swapping the MFA2 policy label out by removing ldap/ radius and use a saml auth provider as the IDP such as okta instead. If i did this how could i control the session profiles that configure the WI address as would like a seperate storefront store as would have to enable FAS on it ? Session policys linked to AAA groups? I already got citrix fas set up for cert based logons to vdas when using saml