Skip to main content
Announcements
Qlik Connect 2024! Seize endless possibilities! LEARN MORE
cancel
Showing results for 
Search instead for 
Did you mean: 
Not applicable

Users cannot access hub - Inactive?

I've set up a User Directory Connector to my Active Directory environment for my Qlik Sense installation. This is a new install on a single server, and I only have two end users accessing this at the moment. Both end users report that when they access the hub, they are prompted for their AD credentials, then they just see a completely blank screen. When I access QMC > User Directory Connectors, I can see that the UDC is syncing successfully. In reviewing User Access Allocations, I can see licenses are allocated to both users. The Users page lists both users as well, however, it shows Inactive is set to 'Yes' and Removed Externally is also set to 'Yes'.

Does Qlik disable inactive users causing this type of behavior? If so, how do I prevent this? How do I re-enable them so they can access Qlik again?

1 Solution

Accepted Solutions
Albert_Candelario

Hello all,

Kindly refer to - User can't log in or service not running any longe... - Qlik Community - 1716259

Cheers,

Albert

Please, remember to mark the thread as solved once getting the correct answer

View solution in original post

11 Replies
Not applicable
Author

It appears as though my Active Directory user directory connector was causing this issue. Every time it synced, all users that were not root admin would show a 'removed externally' state of 'Yes'. I disabled this connector and users have since been able to access the site without issue, and new users can still navigate to the site where Qlik creates their domain account as a User so I can allocate a license to them. That being said, I'm a small environment who will have very few Qlik users, so I don't see value in keeping the user directory connector - I'll just set up privileges manually.

Not applicable
Author

Exactly the same is happening to us. Incredibly frustrating that we cant use A.D

Will try deleting the A.D and see if it enables our user to be able to access the software. Will raise a support query on this also

Not applicable
Author

Ok. Deleting the A.D while not removing all users does not fix this issue

It might do if i ticked the box to delete all the users but i don't want to do that because it would cause my Licence Tokens to be quarantined for 7 days

Errrrgh

Not applicable
Author

I hope you find a good resolution to this. Please keep me posted if you get any new information on how to prevent this type of issue. It definitely is frustrating!

Not applicable
Author

Hi markbailey‌,

Just curious, did you get any clarity on how this connector behaves? I'm going to start on-boarding more and more users to Qlik Sense, so I see value in this for my organization in the not too distant future.

Tyler_Waterfall
Employee
Employee

Perhaps I am missing something, but in my experience, I found that after I created and synced the user directory connector the first time, I needed to uncheck the box under User Sync Settings "Fetch user data on first access, then keep in sync".

When the connector syncs again, the users not active (that already existed in the Sense repository after the initial sync) get set to "Innactive" if this box remains checked. Perhaps this has changed, but this is what I experienced.

Not applicable
Author

Hi tylerwaterfall‌,

Thanks for your input. In my troubleshooting I noticed the same abnormal behavior regardless if the 'User Sync Settings' box was checked or unchecked. However, I will pay special attention to this when I'm ready to start utilizing this feature again.

Not applicable
Author

I had the same issue and the options here did not help, ended up going to Qlik support on it. In our case the cause turned out to be the "Additional LDAP Filters" for active directory, the syntax that was used was not correct (I assume it may be an uncommon syntax). removing the filters allowed it to sync correctly.

Another symptom for us, was very little details were synced for the users, they only had their login name shown in the user screen, afterwards the full name and user groups were populated.

Not applicable
Author

I have found that my problem was the LDAP filter that probably was in the wrong format. I was passing the path to the OU where the users are , like this:

OU=SBSUsers, OU=Users,OU=MyBusiness,DC=MyDomain,DC=local

I removed the LDAP filter, Synced and all users (including some service accounts I wanted to filter) showed up in seconds!

What I should have, was a LDAP query to return users from a specific group, something like this:

Example 1: (memberOf=CN=QlikPowerUsers,CN=Users,DC=example,DC=com) returns all users and their attributes who are

members of the QlikPowerUsers group.

Example 2: (&(objectCategory=person)(objectClass=user)(cn=Joe*)) returns all users and their attributes whose name begins

with "Joe".

Example 3:

(|(memberOf=CN=QlikPowerUsers,CN=Users,DC=example,DC=com)(memberOf=CN=QlikReadOnlyUsers,CN=Users,DC=exa

mple,DC=com)) returns all users and their attributes who are members of either QlikPowerUsers OR QlikReadOnlyUsers groups.

More info about this on this very useful document:

Qlik Sense Best Practice: User Directory Connectors

Hope this also solved your problem!

Best Regards,

Carlos Silva