-
Endpoint Management integration with Microsoft Endpoint Manager
-
Certificates and authentication
-
Client certificate or certificate plus domain authentication
-
Authentication with Azure Active Directory through Citrix Cloud
-
Authentication with Azure Active Directory through Citrix Gateway for MAM enrollment
-
Authentication with Okta through Citrix Cloud
-
Authentication with Okta through Citrix Gateway for MAM enrollment
-
Authentication with an on-premises Citrix Gateway through Citrix Cloud
This content has been machine translated dynamically.
Dieser Inhalt ist eine maschinelle Übersetzung, die dynamisch erstellt wurde. (Haftungsausschluss)
Cet article a été traduit automatiquement de manière dynamique. (Clause de non responsabilité)
Este artículo lo ha traducido una máquina de forma dinámica. (Aviso legal)
此内容已经过机器动态翻译。 放弃
このコンテンツは動的に機械翻訳されています。免責事項
이 콘텐츠는 동적으로 기계 번역되었습니다. 책임 부인
Este texto foi traduzido automaticamente. (Aviso legal)
Questo contenuto è stato tradotto dinamicamente con traduzione automatica.(Esclusione di responsabilità))
This article has been machine translated.
Dieser Artikel wurde maschinell übersetzt. (Haftungsausschluss)
Ce article a été traduit automatiquement. (Clause de non responsabilité)
Este artículo ha sido traducido automáticamente. (Aviso legal)
この記事は機械翻訳されています.免責事項
이 기사는 기계 번역되었습니다.책임 부인
Este artigo foi traduzido automaticamente.(Aviso legal)
这篇文章已经过机器翻译.放弃
Questo articolo è stato tradotto automaticamente.(Esclusione di responsabilità))
Translation failed!
Authentication with Okta through Citrix Cloud
Citrix Endpoint Management supports authentication with Okta credentials through Citrix Cloud. This authentication method is available only to users enrolling in MDM through the Citrix Secure Hub.
Devices enrolling in MAM can’t authenticate using Okta credentials through Citrix Cloud. To use Citrix Secure Hub with MDM+MAM, configure Citrix Endpoint Management to use NetScaler Gateway for MAM enrollment. For more information, see NetScaler Gateway and Citrix Endpoint Management.
Citrix Endpoint Management uses the Citrix Cloud service, Citrix identity, to federate with Okta. Citrix recommends that you use the Citrix identity provider instead of a direct connection to Okta.
Citrix Endpoint Management supports authentication with Okta for the following platforms:
- iOS and macOS devices not enrolled in the Apple Business Manager or Apple School Manager
- iOS and macOS devices enrolled in the Apple Business Manager
- Android Enterprise devices (preview), for BYOD and fully managed modes
Authentication with Okta through Citrix Cloud has these limitations:
- Isn’t available for Citrix Endpoint Management local accounts.
- Doesn’t support authentication through Okta for enrollment invitations. If you send users an enrollment invitation that has an enrollment URL, users authenticate through LDAP instead of Okta.
Prerequisites
- Okta user credentials
- User groups in the Active Directory must match the user groups at Okta.
- User names and email addresses in the active directory must match the user names and email addresses at Okta.
- Citrix Cloud account with Citrix Cloud Connector installed for directory service synchronization.
- NetScaler Gateway. Citrix recommends that you enable certificate-based authentication for a full single sign-on experience. If you use LDAP authentication on the NetScaler Gateway for MAM registration, end users experience a dual authentication prompt during enrollment. For more information, see Client certificate or certificate plus domain authentication.
- In the enrollment profile for Android Enterprise, set Allow users to decline device management to Off. If users decline device management, they can’t enroll using an identity provider to authenticate. For more information, see Enrollment security.
Configure Citrix Cloud to use Okta as your identity provider
To configure Okta in Citrix Cloud, see Connect Okta as an identity provider to Citrix Cloud.
Configure Citrix identity as the IdP type for Citrix Endpoint Management
This configuration applies only to users enrolling through Citrix Secure Hub. After you configure Azure Active Directory in Citrix Cloud, configure Citrix Endpoint Management as follows:
-
In the Citrix Endpoint Management console, go to Settings > Identity Provider (IDP) and then click Add.
-
On the Identity Provider (IDP) page, configure the following:
- IDP Name: Type a unique name to identify the IdP connection that you are creating.
- IDP Type: Choose Citrix Identity Provider.
- Authentication Domain: Choose the Citrix Cloud domain. If you aren’t sure which one to choose, your domain appears on the Citrix Cloud Identity and Access Management > Authentication page.
-
Click Next. In the IDP Claims Usage page, configure the following:
- User Identifier type: This field is set to userPrincipalName. Make sure that you configure all users with the same identifier in your on-premises Active Directory and at Okta. Citrix Endpoint Management uses this identifier to map users on the identity provider with on-premises Active Directory users.
- User Identifier string: This field is automatically filled.
After this configuration, Citrix Secure Hub users who are domain-joined can use Citrix Secure Hub to sign in with their Okta credentials. Citrix Secure Hub uses client certificate authentication for MAM devices.
Citrix Secure Hub authentication flow
Citrix Endpoint Management uses the following flow to authenticate users with Okta as an IdP on devices enrolled through Citrix Secure Hub:
- A user starts Citrix Secure Hub.
- Citrix Secure Hub passes the authentication request to Citrix identity, which passes the request to Okta.
- The user types their user name and password.
- Okta validates the user and sends a code to Citrix identity.
- Citrix identity sends the code to Citrix Secure Hub, which sends the code to the Citrix Endpoint Management server.
- Citrix Endpoint Management gets an ID token by using the code and secret, and then validates the user information that’s in the ID token. Citrix Endpoint Management returns a session ID.
Share
Share
This Preview product documentation is Citrix Confidential.
You agree to hold this documentation confidential pursuant to the terms of your Citrix Beta/Tech Preview Agreement.
The development, release and timing of any features or functionality described in the Preview documentation remains at our sole discretion and are subject to change without notice or consultation.
The documentation is for informational purposes only and is not a commitment, promise or legal obligation to deliver any material, code or functionality and should not be relied upon in making Citrix product purchase decisions.
If you do not agree, select I DO NOT AGREE to exit.