After NetScaler Gateway authentication, logon page gets stuck at /cgi/login for a user of a particular group. Users of other groups have no issue.
Complete the following steps to troubleshoot this issue:
Verify the aaad.debug logs to examine if the user is a member of the group that log on fails for.
Verify if the group on the NetScaler has session policy configured. If not, add session policy to that group.