Configure domain and security token authentication for Citrix Endpoint Management
You can configure Citrix Endpoint Management to require users to authenticate with their LDAP credentials plus a one-time password, using the RADIUS protocol. This section describes the required {{page.gateway-onprem}} configuration for that two-factor authentication type.
Prerequisites
If you have not already run the {{page.citrix-adc-generic}} for Citrix Endpoint Management wizard, see the {{page.citrix-adc-generic}} for Citrix Endpoint Management Wizard section in Configuring Settings for Your Citrix Endpoint Management Environment. Make sure that your {{page.citrix-adc-generic}} configuration includes the following:
-
LDAP port number = 636 (which is the default port for secure LDAP connections)
-
Server Logon Name Attribute = samAccountName or the userPrincipalName as per your requirements
To configure domain and security token authentication
-
Go to {{page.gateway-onprem}} > Virtual Servers. Select the virtual server and then click Edit.
-
Click No CA Certificate.
-
In Select CA Certificate, choose a certificate, click OK, click Bind, and then click Done.
-
Go to Policies > Session > Session Profiles, select the profile, and click Edit.
-
Click the Client Experience tab.
-
In Credential Index, choose SECONDARY.
-
Click OK.
-
Go to Policies > Authentication > LDAP, click the LDAP Policy tab, and click Edit.
-
Use the following expression to use separate {{page.gateway-onprem}} VIPs for Citrix Endpoint Management and {{page.cvad-onprem-product-name}}.REQ.HTTP.HEADER User-Agent CONTAINS
CitrixReceiver -
Go to Policies > Authentication > RADIUS and then click the Servers tab.
-
Click Add, enter the RADIUS server details, and click Create.
-
Go to Policies and then click Add.
-
Enter a Name for the policy. From the Server drop-down menu, select the RADIUS server name that you have created.
-
In Expression, enter REQ.HTTP.HEADER User-Agent CONTAINS CitrixReceiver and click Create.
-
Select the virtual server and then click Edit.
-
Under Primary Authentication, click LDAP Policy.
-
Select the policy, click Unbind, and click Close.
-
On the Authentication row, click + to add the RADIUS authentication.
-
Under Choose Type, from Choose Policy, select RADIUS.
-
Click Bind.
-
Select the RADIUS authentication policy that you created earlier and then click Insert.
-
Click OK.
-
To add LDAP as the secondary authentication policy: On the Authentication row, click +.
-
From Choose Policy, choose LDAP.
-
From Choose Type, choose Secondary.
-
From Select Policy, choose the LDAP policy.
-
Select the policy and then click OK.
-
Click Bind.
-
Click Done.
-
Verify that the policies you created have the highest priority. This ensures that they have the highest priority even if more policies get added for non-mobile users. For more information, see Setting Priorities for Authentication Policies