Unlock a world of possibilities! Login now and discover the exclusive benefits awaiting you.
I've set up a User Directory Connector to my Active Directory environment for my Qlik Sense installation. This is a new install on a single server, and I only have two end users accessing this at the moment. Both end users report that when they access the hub, they are prompted for their AD credentials, then they just see a completely blank screen. When I access QMC > User Directory Connectors, I can see that the UDC is syncing successfully. In reviewing User Access Allocations, I can see licenses are allocated to both users. The Users page lists both users as well, however, it shows Inactive is set to 'Yes' and Removed Externally is also set to 'Yes'.
Does Qlik disable inactive users causing this type of behavior? If so, how do I prevent this? How do I re-enable them so they can access Qlik again?
Hello all,
Kindly refer to - User can't log in or service not running any longe... - Qlik Community - 1716259
Cheers,
Albert
It appears as though my Active Directory user directory connector was causing this issue. Every time it synced, all users that were not root admin would show a 'removed externally' state of 'Yes'. I disabled this connector and users have since been able to access the site without issue, and new users can still navigate to the site where Qlik creates their domain account as a User so I can allocate a license to them. That being said, I'm a small environment who will have very few Qlik users, so I don't see value in keeping the user directory connector - I'll just set up privileges manually.
Exactly the same is happening to us. Incredibly frustrating that we cant use A.D
Will try deleting the A.D and see if it enables our user to be able to access the software. Will raise a support query on this also
Ok. Deleting the A.D while not removing all users does not fix this issue
It might do if i ticked the box to delete all the users but i don't want to do that because it would cause my Licence Tokens to be quarantined for 7 days
Errrrgh
I hope you find a good resolution to this. Please keep me posted if you get any new information on how to prevent this type of issue. It definitely is frustrating!
Hi markbailey,
Just curious, did you get any clarity on how this connector behaves? I'm going to start on-boarding more and more users to Qlik Sense, so I see value in this for my organization in the not too distant future.
Perhaps I am missing something, but in my experience, I found that after I created and synced the user directory connector the first time, I needed to uncheck the box under User Sync Settings "Fetch user data on first access, then keep in sync".
When the connector syncs again, the users not active (that already existed in the Sense repository after the initial sync) get set to "Innactive" if this box remains checked. Perhaps this has changed, but this is what I experienced.
Hi tylerwaterfall,
Thanks for your input. In my troubleshooting I noticed the same abnormal behavior regardless if the 'User Sync Settings' box was checked or unchecked. However, I will pay special attention to this when I'm ready to start utilizing this feature again.
I had the same issue and the options here did not help, ended up going to Qlik support on it. In our case the cause turned out to be the "Additional LDAP Filters" for active directory, the syntax that was used was not correct (I assume it may be an uncommon syntax). removing the filters allowed it to sync correctly.
Another symptom for us, was very little details were synced for the users, they only had their login name shown in the user screen, afterwards the full name and user groups were populated.
I have found that my problem was the LDAP filter that probably was in the wrong format. I was passing the path to the OU where the users are , like this:
OU=SBSUsers, OU=Users,OU=MyBusiness,DC=MyDomain,DC=local
I removed the LDAP filter, Synced and all users (including some service accounts I wanted to filter) showed up in seconds!
What I should have, was a LDAP query to return users from a specific group, something like this:
Example 1: (memberOf=CN=QlikPowerUsers,CN=Users,DC=example,DC=com) returns all users and their attributes who are
members of the QlikPowerUsers group.
Example 2: (&(objectCategory=person)(objectClass=user)(cn=Joe*)) returns all users and their attributes whose name begins
with "Joe".
Example 3:
(|(memberOf=CN=QlikPowerUsers,CN=Users,DC=example,DC=com)(memberOf=CN=QlikReadOnlyUsers,CN=Users,DC=exa
mple,DC=com)) returns all users and their attributes who are members of either QlikPowerUsers OR QlikReadOnlyUsers groups.
More info about this on this very useful document:
Qlik Sense Best Practice: User Directory Connectors
Hope this also solved your problem!
Best Regards,
Carlos Silva