This message was deleted.
# citrix-netscaler
s
This message was deleted.
k
The NetScaler Gateway is acting as a SAML SP in this case? Are you able to add a claim or sth stating the CA result?
m
Sometimes when it seems to tricky to get the claims I need from the SAML IDP and I need eg Domain Groups I just add a LDAP Policy with authentication disabled and search for the username in the nfactor flow. Maybe this can help your case? Can you match Delievery Group Membership to AD Groups? Or do you really need who has permissions to the delievery group itself in Citrix ?
k
What if the CA policy detects what kind of location the user is accessing the environment from or something regarding their endpoint device? This is something you cannot control with groups.
I'd check if there's something you could use from the Intune Integration (https://docs.citrix.com/en-us/citrix-gateway/13/microsoft-intune-integration.html). The thing is that the Gateway needs to get a "signal" from AAD in the SAML claim and somehow process this so that the Virtual Apps can intepret the result and make decisions.
I'd say that every possible component needs to be Premium licensed 😄
🤣 1
... and it still might be impossible