Skip to main content
Announcements
Qlik Connect 2024! Seize endless possibilities! LEARN MORE
cancel
Showing results for 
Search instead for 
Did you mean: 
Not applicable

QVS installed in the different domain

Hi,

If I installed the QVS on the different domain from the Users, how can I let the server identify the users.

For example:

QVS in A domain, Users in B domain.

What should I do? Config Active directory?

Thanks.

6 Replies
Bjorn_Wedbratt
Former Employee
Former Employee

Hi,
If you have domains you already have AD in place. If the two domains are joined to the same forest with two-way trusts, there shouldn't be any problems for the users in Domain B to access resources in Domain A. Just give the users correct NTFS permissions on file-level (qvw-files) on the QVS.

Regards,
Bjorn

Not applicable
Author

How to give the users correct NTFS permissions on file-level (qvw-files) on the QVS?

Not applicable
Author

In QEMC do the below settings

System -> Setup -> Directory Service Connectors -> DSC@ServerName -> Active Directory

select General Tab on right side.

enter the Path of both the AD group
example
LDAP://domainA.com

I hope this may be helpful to you

-

Yoga

Emmanuelle__Bustos
Partner - Specialist
Partner - Specialist

Hi yogananthan

In my case we have two doamins A and B and the QVS is installed in a Doamin A and the users in domain B can be assigned via LDAP and when they open the accesspoint they are prompted for credentials but cant be signed in.

I have aded them into Users Group in Windows and even permission over the Document's folder (qvw's) but the issue remains. I solved the issue adding first all the Domain B uses to the Administrator Group, as we know is not the best practice give such permission to all users, so i prove removing them from administrators group and adding them to the Powers users and this works too.

My question is If this is the best practice or what should i do for improve this??

Not applicable
Author

Hi Emanuel,

As I understand the application is security enabled(Section Access implemented). If Yes, comment the NTDOMAINSID check and reload the application manualy then run the job through QEMC.

From my experience to view the applications the users no need to be part of either Administrators and any other local(server) user group.

Regards,

Yoga

Emmanuelle__Bustos
Partner - Specialist
Partner - Specialist

yogananthan

We dont use Section access in fact only the demos are in the accesspoint and as i said if the Domain's B users are part of No one or Users Group they cant access (signing failed) just when i add them into power users or administartors Group they can access.