Few users are denied access to Citrix infra and are not part of AD group that provide access to okta and citrix resources
Those users who do not have access for citrix infra with IDP – okta are receiving an error as : “An error was encountered while handling the remote login”
After reached out to okta to verify if access denied is passed on from okta to citrix.
Okta has confirmed that access denied is passed to cloud.
OKTA has response a proper "access_denied" return according OAuth2 protocol - https://www.oauth.com/oauth2-servers/authorization/the-authorization-response/