Jump to content
Welcome to our new Citrix community!

Manage Security Questions with SSPR Storefront 3.7


Jeroen Ensink

Recommended Posts

I have also noticed the Tasks icon missing in the dev environment I have just set up.  The "Account Self Service" link shows on the logon page after SSPR is enabled in the Authentication settings for the Store but once logged in the button is missing.  Will be reviewing the logs on the IIS server to see if I can find out what is going on. 

Link to comment
Share on other sites

I initially used an OU but when that gave nothing I changed the config to use Domain Users for the group to catch everything just in case.

 

Have also found that disabling sspr in the store auth config sometimes does not have an effect and the self service link is still on the login page. After a restart of the website and the mmc, sspr shows as enabled still but now disabling it will work.

Link to comment
Share on other sites

Same issue - no Tasks tab.

Try to use the link on the storefront landing page and the users are told "you cannot use account self service"

 

Accessing the store directly, no netscaler configured, SSPR config set to Domain Users.

 

I've followed the citrix guide and Carl's but no joy so far. Can't see what I've missed.

 

Storefront 3.7.0.39, XenDesktop 7.11 Platinum, License server 7.11.0.86, SSPR 1.0

Link to comment
Share on other sites

You're definitely hitting storefront directly? 

 

I was getting 'you cannot use account self service' for domain admin accounts - im guessing because the service account cant change passwords of users with higher permissions.

Link to comment
Share on other sites

Thanks for the reply Mike. Yep, definitely directly to the storefront server - even tested while RDPd on the server itself.

 

Based on your suggestion I made both the proxy and service roles use domain admin accounts as a test. Made no difference, even basic users get the 'you cannot use' message.

 

I'll start from scratch again tomorrow and post if I crack it.

Link to comment
Share on other sites

  • 1 month later...

I'd check the permissions of the SSPR self service (sync) account if you get the "you cannot use" message.

The sync account would need to have Domain Admin rights for SSPR to work with Domain Admin accounts.

SSPR for Domain Admin accounts is of course not recommended, for obvious reasons - though no doubt some customers and partners would find it useful.  

Iain, the issue you describe is normally due to the user not being in an OU or group that's configured in the SSPR console in User Configuration.

Link to comment
Share on other sites

  • 3 months later...

Did you manage to get this working?

 

I still can't get the Tasks > Manage security questions tab to show in StoreFront.

 

I have a load balanced pair, I'm accessing the StoreFront servers internally and do not have NetScaler gateway configured.

 

I followed the instructions at https://blog.infrashare.net/2016/09/28/how-to-configure-citrix-self-service-password-reset-sspr/ which mentions this issue in the troubleshooting steps. However, I've tried an iisreset as well as disabling and re-enabling the authentication method and propagating changes each time but it still doesn't work.

 

Any ideas?

Link to comment
Share on other sites

  • 4 months later...
  • 2 years later...

stuck on this same issue for a while now. The manage Tasks tab just doesnt show up.

Used a domain admin account for both Data proxy and the self service account.

on the storefront Receiver for Web URL i see the "Account self Service " option under the Logn button, however i cannot use it before setting up the Security questions( Which i am unable to as i don't see the 'Tasks' tab on logon)

 

any inputs are greatly appreciated.

Link to comment
Share on other sites

  • 1 year later...

Has anyone made headway on this problem.  I am seeing the same issue.  I get the "Account self Service" menu at the storefront login page.  But i never get the task icon once i have authenticated.  Both my DataProxyAccount and SelfServiceAccount are in the DomainAdmin goup.  I am not coming through a NSG, but am going directly to the Storefront url.  I have totally rebuilt both the SSPR server and Storefront server twice, with no progress.

Link to comment
Share on other sites

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now
×
×
  • Create New...