Skip to content

Deyda.net

Deyda Consulting Blog

  • Start Page
  • Consulting
  • About me
    • Privacy Policy
    • Imprint
    • Contact me
    • GitHub
  • NeverRed – Update your Software, the lazy way
    • NeverRed – Changelog
  • LinkedIn
  • Xing
  • Instagram
  • Twitter
  • E-Mail
Deyda.net

Tag: AD FS Proxy

Citrix ADC as AD FS Proxy

Citrix ADC as AD FS Proxy

This article is about creating an AD FS Proxy from Citrix ADC (version 12). The AD FS Proxy is used to authenticate e.g. external SaaS applications or websites via AD FS. The following should be achieved by the AD FS Proxy:

  • URL / DoS Protection
  • Suitable external authentication (MFA, Forms instead of Kerberos)
  • Account Lockout Protection
  • Availability (Load Balancing)

What is AD FS ?

Active Directory Federation Services (AD FS) is a feature in the Windows Server operating system that allows identity information to be shared outside of the corporate network. Users can access applications (e.g. Office365, Salesforce.com, etc.) without being prompted to provide credentials again. These applications can be hosted locally, in the cloud, or even by other companies. The user accounts can be managed by the administrator in a single location, the Active Directory.

A normal deployment of AD FS for external clients consists of AD FS Proxy and AD FS Server. The AD FS Server is a member of the domain and perform the authentication. The AD FS Proxy is usually located in a separate network zone (DMZ) so that it can be reached externally and forward the requests inwards.

Continue reading “Citrix ADC as AD FS Proxy”
Author Manuel WinkelPosted on February 26, 2019April 28, 2020Categories ADC, Azure, Citrix, Microsoft, Office365Tags AD FS, AD FS Proxy, Citrix, Citrix ADC, Citrix Gateway, Content Switching, Federated Domain, FederationMetadata.xml, IdPinitiatedSignOn.htm, Load Balancing, Microsoft, NetScaler, Office365, Principal, Rewrite, Single-Sign On3 Comments on Citrix ADC as AD FS Proxy

Sprachen

  • Deutsch
  • English

Manuel Winkel Follow

Citrix Technology Professional (CTP) - Presales Engineer at @ControlUp - Deyda Consulting - CCE-V - CCE-N - CCP-M - MCSA - MCSE - Father of 3

Deyda84
samilaiho Sami Laiho @samilaiho ·
11 May

Microsoft Teams will soon block screen capture during meetings

Reply on Twitter 1921554453368328452 Retweet on Twitter 1921554453368328452 7 Like on Twitter 1921554453368328452 20 Twitter 1921554453368328452
christian_joens Christian JΓΆns @christian_joens ·
1 Mar

🚨🚨🚨 Check your Citrix License Servers.
We had issues with Build 51000 that the License are no longer available. Downgrade to Build 49000 as Workaround #citrix

Reply on Twitter 1895743833176240488 Retweet on Twitter 1895743833176240488 8 Like on Twitter 1895743833176240488 23 Twitter 1895743833176240488
jakob_davidson Julian Jakob @jakob_davidson ·
25 Feb

2/2 The root cause is, after HA-Failover, the WAF profile ns-aaa-default-appfw-profile is gone. The User gets a Connection-Reset when trying to browse to any NSGW-URL (with Auth-Profiles in use)
Workaround is to disable WAF or set to "VPN" only.
Issue will be fixed in 14.1 43.x

Reply on Twitter 1894496772078117346 Retweet on Twitter 1894496772078117346 1 Like on Twitter 1894496772078117346 4 Twitter 1894496772078117346
Load More...

Categories

  • Basic (1)
  • Citrix (42)
    • ADC (13)
    • StoreFront (3)
    • Virtual Apps and Desktops (20)
    • WEM (13)
  • Microsoft (20)
    • Azure (8)
    • Exchange (1)
    • FSLogix (4)
    • Office365 (11)
    • PowerShell (3)
    • SQL (2)
  • NVIDIA (1)

Tag Cloud

Citrix Virtual Apps NetScaler LoadBalancer Teams Azure AD Active Directory Upgrade Universal Profile Management Configuration Set UEM User Environment Management WEM Workspace Environment Management Virtual Desktop Single-Sign On Windows Server Unified Gateway SQL Express Performance Management Citrix Gateway AppLocker Norskale Broker Service ADMX Administration Console Citrix ADC StoreFront UPM PowerShell Office Microsoft Intelligent CPU Optimization Intelligent I/O Optimization Canonical Name NetScaler Gateway XenDesktop Applet Name Intelligent Memory Optimization SAML NetScaler Folder Redirection Remote Desktop XenApp SQL Server Office365 FSLogix

Recent Posts

  • Install new Microsoft Teams (version 2) in Citrix May 17, 2024
  • Checklist for NetScaler (Citrix ADC) CVE-2023-4966 December 12, 2023
  • SAML Authentication between Citrix & Microsoft with Azure MFA September 8, 2023
  • Checklist for NetScaler (Citrix ADC) CVE-2023-3519 July 19, 2023
  • Web Authentication Action in NetScaler October 13, 2022

Meta

  • Log in
  • Entries feed
  • Comments feed
  • WordPress.org
  • Start Page
  • Consulting
  • About me
    • Privacy Policy
    • Imprint
    • Contact me
    • GitHub
  • NeverRed – Update your Software, the lazy way
    • NeverRed – Changelog
  • LinkedIn
  • Xing
  • Instagram
  • Twitter
  • E-Mail
Deyda.net Privacy Policy Proudly powered by WordPress