Understanding MSAL Token Authentication
-
When an app is launched in iOS or Android, the app contacts Microsoft. The user is prompted to log on with user credentials. After a successful logon, the app gets an MSAL token.
-
This MSAL token is presented to a NetScaler Gateway, which has been configured to validate the MSAL token.
-
NetScaler Gateway validates the signature of the MSAL token with the corresponding certificate from Microsoft.
-
After a successful validation, NetScaler Gateway extracts the User’s Principal Name (UPN) and grants the app VPN access to the internal resources.