Skip to content

Commit ed4919a

Browse files
committed
more edits
1 parent 6109ce9 commit ed4919a

File tree

2 files changed

+69
-57
lines changed

2 files changed

+69
-57
lines changed

articles/active-directory/saas-apps/citrix-netscaler-tutorial.md

Lines changed: 26 additions & 24 deletions
Original file line numberDiff line numberDiff line change
@@ -51,7 +51,7 @@ In this tutorial, you configure and test Azure AD SSO in a test environment. The
5151

5252
## Add Citrix NetScaler from the gallery
5353

54-
To integrate Citrix NetScaler with Azure AD, first add Citrix NetScaler from the gallery to your list of managed SaaS apps:
54+
To integrate Citrix NetScaler with Azure AD, first add Citrix NetScaler to your list of managed SaaS apps from the gallery:
5555

5656
1. Sign in to the [Azure portal](https://portal.azure.com) using either a work or school account, or a personal Microsoft account.
5757
1. In the left menu, select **Azure Active Directory**.
@@ -70,37 +70,39 @@ To configure and test Azure AD SSO with Citrix NetScaler, complete the following
7070
1. **[Create an Azure AD test user](#create-an-azure-ad-test-user)** - to test Azure AD SSO with B.Simon.
7171
1. **[Assign the Azure AD test user](#assign-the-azure-ad-test-user)** - to enable B.Simon to use Azure AD SSO.
7272
1. **[Configure Citrix NetScaler SSO](#configure-citrix-netscaler-sso)** - to configure the SSO settings on the application side.
73-
* **[Create a Citrix NetScaler test user](#create-a-citrix-netscaler-test-user)** - to have a counterpart of B.Simon in Citrix NetScaler that is linked to the Azure AD representation of the user.
73+
1. **[Create a Citrix NetScaler test user](#create-a-citrix-netscaler-test-user)** - to have a counterpart of B.Simon in Citrix NetScaler that is linked to the Azure AD representation of the user.
7474
1. **[Test SSO](#test-sso)** - to verify whether the configuration works.
7575

7676
## Configure Azure AD SSO
7777

78-
Follow these steps to enable Azure AD SSO in the Azure portal:
78+
To enable Azure AD SSO by using the Azure portal, complete these steps:
79+
80+
1. In the [Azure portal](https://portal.azure.com/), on the **Citrix NetScaler** application integration pane, under **Manage**, select **Single sign-on**.
7981

80-
1. In the [Azure portal](https://portal.azure.com/), on the **Citrix NetScaler** application integration pane, under **Manage**, select **single sign-on**.
8182
1. On the **Select a single sign-on method** pane, select **SAML**.
82-
1. On the **Set up single sign-on with SAML** pane, select the edit/pen icon for **Basic SAML Configuration** to edit the settings.
83+
84+
1. On the **Set up Single Sign-On with SAML** pane, select the pen **Edit** icon for **Basic SAML Configuration** to edit the settings.
8385

8486
![Edit Basic SAML Configuration](common/edit-urls.png)
8587

8688
1. In the **Basic SAML Configuration** section, to configure the application in **IDP-initiated** mode:
8789

8890
1. In the **Identifier** text box, enter a URL that has the following pattern:
89-
`https://<<Your FQDN>>`
91+
`https://<Your FQDN>`
9092

9193
1. In the **Reply URL** text box, enter a URL that has the following pattern:
92-
`https://<<Your FQDN>>/CitrixAuthService/AuthService.asmx`
94+
`https://<Your FQDN>/CitrixAuthService/AuthService.asmx`
9395

9496
1. To configure the application in **SP-initiated** mode, select **Set additional URLs** and complete the following step:
9597

9698
* In the **Sign-on URL** text box, enter a URL that has the following pattern:
97-
`https://<<Your FQDN>>/CitrixAuthService/AuthService.asmx`
99+
`https://<Your FQDN>/CitrixAuthService/AuthService.asmx`
98100

99101
> [!NOTE]
100-
> * These values are not real. Update these values with the actual values for Sign-On URL, Identifier, and Reply URL. Contact the [Citrix NetScaler client support team](https://www.citrix.com/contact/technical-support.html) to get these values. You can also refer to the patterns shown in the **Basic SAML Configuration** section in the Azure portal.
101-
> * To set up SSO, these URLs must be accessible from public websites. You must enable the firewall or other security settings on the Citrix NetScaler side to enble Azure AD to post the token at the configured URL.
102+
> * The URLs that are used in this section aren't real values. Update these values with the actual values for Identifier, Reply URL, and Sign-on URL. Contact the [Citrix NetScaler client support team](https://www.citrix.com/contact/technical-support.html) to get these values. You can also refer to the patterns shown in the **Basic SAML Configuration** section in the Azure portal.
103+
> * To set up SSO, the URLs must be accessible from public websites. You must enable the firewall or other security settings on the Citrix NetScaler side to enble Azure AD to post the token at the configured URL.
102104

103-
1. On the **Set up single sign-on with SAML** pane, in the **SAML Signing Certificate** section, for **App Federation Metadata Url**, copy the URL and save it in Notepad.
105+
1. On the **Set up Single Sign-On with SAML** pane, in the **SAML Signing Certificate** section, for **App Federation Metadata Url**, copy the URL and save it in Notepad.
104106

105107
![The Certificate download link](common/certificatebase64.png)
106108

@@ -110,7 +112,7 @@ Follow these steps to enable Azure AD SSO in the Azure portal:
110112

111113
### Create an Azure AD test user
112114

113-
In this section, you'll create a test user in the Azure portal called B.Simon.
115+
In this section, you create a test user in the Azure portal called B.Simon.
114116

115117
1. On the left menu in the Azure portal, select **Azure Active Directory**, select **Users**, and then select **All users**.
116118
1. Select **New user** at the top of the pane.
@@ -142,7 +144,7 @@ In this section, you enable the user B.Simon to use Azure SSO by granting the us
142144

143145
Select a link for steps for the kind of authentication you want to configure:
144146

145-
- [Configure Citrix NetScaler SSO for Kerberos-based authentication](#configure-citrix-netscaler-sso-for-kerberos-based-authentication)
147+
- [Configure Citrix NetScaler SSO for Kerberos-based authentication](#publish-the-web-server)
146148

147149
- [Configure Citrix NetScaler SSO for header-based authentication](header-citrix-netscaler-tutorial.md)
148150

@@ -186,7 +188,7 @@ To configure the load balancer:
186188

187189
To bind the load balancer with the virtual server:
188190

189-
1. Under **Services and Service Groups**, select **Load Balancing Virtual Server Service Binding**.
191+
1. In the **Services and Service Groups** pane, select **No Load Balancing Virtual Server Service Binding**.
190192

191193
![Citrix NetScaler configuration - Load Balancing Virtual Server Service Binding pane](./media/citrix-netscaler-tutorial/bind01.png)
192194

@@ -198,7 +200,7 @@ To bind the load balancer with the virtual server:
198200

199201
To publish this service as SSL, bind the server certificate, and then test your application:
200202

201-
1. Under **Certificate**, select **Server Certificate**.
203+
1. Under **Certificate**, select **No Server Certificate**.
202204

203205
![Citrix NetScaler configuration - Server Certificate pane](./media/citrix-netscaler-tutorial/bind03.png)
204206

@@ -208,6 +210,8 @@ To publish this service as SSL, bind the server certificate, and then test your
208210

209211
## Citrix ADC SAML profile
210212

213+
To configure the Citrix ADC SAML profile, complete the following sections:
214+
211215
### Create an authentication policy
212216

213217
To create an authentication policy:
@@ -230,7 +234,7 @@ To create an authentication policy:
230234

231235
To create an authentication SAML server:
232236

233-
1. Go to the **Create Authentication SAML Server** pane, and then complete the following steps:
237+
* Go to the **Create Authentication SAML Server** pane, and then complete the following steps:
234238

235239
1. For **Name**, enter a name for the authentication SAML server.
236240

@@ -240,7 +244,7 @@ To create an authentication SAML server:
240244

241245
1. For **Issuer Name**, enter the relevant URL.
242246

243-
1. Select **Create**.
247+
1. Select **Create**.
244248

245249
![Citrix NetScaler configuration - Create Authentication SAML Server pane](./media/citrix-netscaler-tutorial/server01.png)
246250

@@ -266,17 +270,15 @@ To create an authentication virtual server:
266270

267271
Modify two sections for the authentication virtual server:
268272

269-
1. On the **Advanced Authentication Policies** pane, select **Authentication Policy**.
273+
1. On the **Advanced Authentication Policies** pane, select **No Authentication Policy**.
270274

271275
![Citrix NetScaler configuration - Advanced Authentication Policies pane](./media/citrix-netscaler-tutorial/virtual01.png)
272276

273-
1. On the **Policy Binding** pane, select the authentication policy.
274-
275-
1. Select **Bind**.
277+
1. On the **Policy Binding** pane, select the authentication policy, and then select **Bind**.
276278

277279
![Citrix NetScaler configuration - Policy Binding pane](./media/citrix-netscaler-tutorial/virtual02.png)
278280

279-
1. On the **Form Based Virtual Servers** pane, select **Load Balancing Virtual Server**.
281+
1. On the **Form Based Virtual Servers** pane, select **No Load Balancing Virtual Server**.
280282

281283
![Citrix NetScaler configuration - Form Based Virtual Servers pane](./media/citrix-netscaler-tutorial/virtual03.png)
282284

@@ -383,7 +385,7 @@ To configure the Citrix traffic policy and traffic profile:
383385

384386
![Citrix NetScaler configuration - Configure Traffic Policy pane](./media/citrix-netscaler-tutorial/kerberos05.png)
385387

386-
### Bind the traffic policy to a virtual server in Citrix
388+
### Bind a traffic policy to a virtual server in Citrix
387389

388390
To bind a traffic policy to a virtual server by using the GUI:
389391

@@ -419,7 +421,7 @@ To bind a traffic policy to a virtual server by using the GUI:
419421

420422
### Create a Citrix NetScaler test user
421423

422-
In this section, a user called B.Simon is created in Citrix NetScaler. Citrix NetScaler supports just-in-time user provisioning, which is enabled by default. There is no action item for you in this section. If a user doesn't already exist in Citrix NetScaler, a new one is created after authentication.
424+
In this section, a user called B.Simon is created in Citrix NetScaler. Citrix NetScaler supports just-in-time user provisioning, which is enabled by default. There is no action for you to take in this section. If a user doesn't already exist in Citrix NetScaler, a new one is created after authentication.
423425

424426
> [!NOTE]
425427
> If you need to create a user manually, contact the [Citrix NetScaler client support team](https://www.citrix.com/contact/technical-support.html).

0 commit comments

Comments
 (0)