Well, once you installed FR2 you created a second location that the user must be authenticated to. In the ICA Connection configuraton you select security and then add or select the user group and the advanced to select the shadow permission. This is pretty much the same old way.
The next thing that must be set is in the Citrix Management console. The user will have to be included here as an administrator but only needs permissions applied to shadow. They also will need appropriate permissions to the shadow files, wshadow.cnt,wshadow.dll,wshadow.exe,wshadow.hlp,cshadow.exe and shadow.exe.