1Y0-312 Advanced Security and Access Control Practice Question
An administrator is configuring Citrix Gateway to use SAML authentication with Microsoft Microsoft Entra ID as the identity provider. The requirement is that users must authenticate using Microsoft Entra ID and then be authorized to access specific published applications based on their group membership in Microsoft Entra ID. The administrator has configured the SAML action and policy on Citrix ADC and imported the Microsoft Entra ID certificate. Which Citrix ADC feature should be configured to extract the group membership from the SAML assertion and use it for authorization?
⚠ Common exam trap
The trap here is assuming that SAML authentication alone provides group-based authorization, when in fact an authorization policy must be configured to evaluate the group attribute extracted from the SAML assertion.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Configure a Citrix ADC authorization policy that evaluates the SAML group attribute.
After SAML authentication, Citrix ADC can extract attributes from the assertion using SAML attribute configuration. To authorize users based on group membership, an authorization policy must be created that evaluates the extracted group attribute. This policy can then be bound to the gateway to allow or deny access to specific resources. This approach leverages the SAML assertion to enforce granular access control, meeting the requirement without additional LDAP queries.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Enable Session Policy evaluation with the SAML attribute.
Why it's wrong here
Session policies are evaluated after authentication to apply settings like timeouts and split tunneling. While they can use SAML attributes, they are not specifically designed to extract group membership for authorization. The authorization decision for accessing specific applications is typically handled by Citrix ADC authorization policies or by the Citrix Gateway's SmartAccess policies, which can evaluate group membership. Session policies alone do not provide the granular application access control required.
- ✗
Use Citrix ADC's LDAP integration to query Microsoft Entra ID for group membership.
Why it's wrong here
Using LDAP to query Microsoft Entra ID is not feasible because Microsoft Entra ID does not support direct LDAP queries without additional services like Microsoft Entra Domain Services. This would complicate the architecture and is not the intended method for SAML-based authentication. The group membership should be obtained from the SAML assertion itself, not through a separate LDAP query. This option is a distractor as it introduces unnecessary complexity and does not leverage the SAML authentication already configured.
- ✗
Configure a SAML attribute and bind it to the authentication policy.
Why it's wrong here
Configuring a SAML attribute allows the ADC to extract specific attributes from the SAML assertion, such as group membership. However, simply configuring the attribute does not automatically use it for authorization. The extracted attribute must be mapped to a session variable or used in a policy expression. Binding it to the authentication policy is part of the process, but it is not the complete feature needed to enforce authorization based on group membership.
- ✓
Configure a Citrix ADC authorization policy that evaluates the SAML group attribute.
Why this is correct
Authorization policies in Citrix ADC can evaluate attributes extracted from SAML assertions, such as group membership. By configuring a SAML attribute to extract the groups and then creating an authorization policy that checks for specific group values, the administrator can grant or deny access to published applications. This is the correct approach to enforce group-based authorization after SAML authentication. The policy can be bound to the gateway virtual server to control access.
About these practice questions
This 1Y0-312 question is part of Courseiva's 186-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Citrix exam blueprint
This 1Y0-312 practice question is part of Courseiva's free Citrix certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 1Y0-312 exam.