Configuring NetScaler version 12 OTP ended up with error "Failed to verify incoming OTP"
Scenario TWO: Users belonging to large Active Directory group are unable to register successfully for Native OTP functionality.
Time difference between client and NetScaler. Recommended user to move to a more reliable NTP server and it works.
Scenario TWO:
Working setup for OTP users belonged to at least 55 groups
In the Not working OTP users belong to more than 117 groups
Customer reduced the number of groups on the non-working setup to 51 after which this user was able to successfully register
Better workaround is unsetting groupAttribute in OTP Action. GUI seems to have an issue with unsetting groupAttr. Please do it from CLI or confirm from CLI.
NTP/Time mismatch between the client and the NetScaler.
Scenario TWO: A known bug (703995) exist which is getting fixed in 12.0-58+GA build