nerdexam
Citrix

1Y0-253 · Question #126

A Citrix Administrator is configuring MicroVPN with MDX wrapped apps to support StoreFront. Which two settings must the administrator configure in the NetScaler Gateway Global settings under…

The correct answer is A. StoreFront URL C. App Controller Host name. See the full explanation below for the reasoning.

Question

A Citrix Administrator is configuring MicroVPN with MDX wrapped apps to support StoreFront. Which two settings must the administrator configure in the NetScaler Gateway Global settings under "Configure Domains for Clientless Access"? (Choose two.)

Options

  • AStoreFront URL
  • BXenMobile Gateway URL
  • CApp Controller Host name
  • DSecure Ticketing Authority

How the community answered

(43 responses)
  • A
    72% (31)
  • B
    16% (7)
  • D
    12% (5)

Community Discussion

6
Grace U.Grace U.Jun 26, 2026

The correct answers are A and C. When you configure domains for clientless access in NetScaler Gateway Global settings, the gateway needs the StoreFront URL so MDX wrapped apps can reach the store, and it needs the App Controller host name because MDX policy enforcement flows through App Controller, so both domains have to be explicitly trusted for the MicroVPN tunnel to work end to end.

15
Orla P.Orla P.Jun 29, 2026

The App Controller piece is correct, but worth noting that in newer Receiver/Workspace builds the App Controller role has been absorbed into StoreFront and Citrix Cloud, so if anyone is on a current deployment they may only see the StoreFront URL requirement and no separate App Controller host name field at all.

0
Thekla S.Thekla S.Jun 17, 2026

The "Configure Domains for Clientless Access" section on NetScaler Gateway is where the gateway learns which backend resources to proxy without a full VPN tunnel, and for MDX-wrapped apps that use MicroVPN, it needs two anchor points, the StoreFront URL so that resource enumeration and authentication tickets flow through the correct store, and the App Controller hostname so the gateway knows which controller is brokering the per-app tunnel for those wrapped apps. STA is configured at the virtual server level, not here, so D is a trap for people who confuse session ticket infrastructure with clientless domain scope. XenMobile Gateway URL in option B sounds relevant but that value lives in the XenMobile Server console when you configure the NetScaler Gateway connector, not in this specific Global settings dialog. Quick question for anyone who has lab time on this, when you add the App Controller hostname under clientless access domains, does your environment require that you also toggle "Use App Controller URL" in the session policy, or does the global domain entry alone satisfy the MicroVPN handshake for the MDX container?

5
Orla P.Orla P.Jun 18, 2026

In my lab the global domain entry alone was not enough, the session policy toggle was required before the MDX container would complete the MicroVPN handshake, so you will want that set even if the docs make it sound optional.

0
Kemal J.Kemal J.Jun 26, 2026

D trips up half the room because STA is all over Gateway config, but that setting lives elsewhere and has nothing to do with clientless access domain entries. A and C are correct, StoreFront URL and App Controller hostname, though I will say whoever wrote "App Controller Host name" as two words clearly typed this at 11pm before a deadline.

4
Grace U.Grace U.Jun 28, 2026

The "Host name" split is peak last-minute copy-paste energy, but honestly if you know why D fails (STA lives in the Gateway virtual server, not the clientless access policy), you have already learned the harder thing on this objective.

0
Full 1Y0-253 Practice