Skip to main content
Announcements
Have questions about Qlik Connect? Join us live on April 10th, at 11 AM ET: SIGN UP NOW
cancel
Showing results for 
Search instead for 
Did you mean: 
Not applicable

Access Point Windows Authentication> User can not login

I have an end user who is unable to log into AccessPoint using IE or Fire. Access Point screen just sits their 'Logged in as...' no documents show up. All other users are able to log in just fine.

We use Windows Authentication to auto log on users. I do have section access setup but this is on the document level. The user is not even making it this far to see the documents

He is able to access other intarnet sites on our domain (SharePoint) and able to access Exchange and our internal CRM tool. I have attempted to access QV IP/port rather than server name but this made no difference. I have tried taking his machine off the domain and putting it back on but this way no difference either.

I can log onto another machine with his account and QV authenticates the end user just fine. Something is unique about his individual machine. I have looked at DC, QV and his individual machine and no errors show up. Does QV leave anything (file, cookie, etc?) on the client machine when it connects? Anything else I can check?

Thanks for any suggestions. Let me know if you have any other questions.

7 Replies
pover
Luminary Alumni
Luminary Alumni

I've had this problem in at least one machine in every QlikView project since the past year. The problem seems to be a combination of the version of the operating system and the version of Internet Explorer. Try disabling the Protected Mode in Internet Explorer, but the only 100% sure solution is that the user connects to the server through QlikView Developer.

Regards.

Not applicable
Author

Jacob,

Try to set the user authentication mode to Prompt for user name and password in Internet options. We had this problem with one of our client and it worked when we used this method.

Not applicable
Author

Thanks for the responses.

Still not sure what is happening. I tried accessing QV via Firefox and IE. Tried put IE into compatibly mode.

I was able to get Firefox and IE to prompt for credentials. It not matter if I typed. The screen just sat at 'Logged in as...'

Tried adding QV as a 'Trusted Site.' Reinstalled IE.

Bjorn_Wedbratt
Former Employee
Former Employee

I would start by trying in stand-alone QV on the failing machine and do a direct Open In Server. The reason is that authentication will be done in a slightly different way compared to AP.

If this works, my next step would be to check if you have a Local User Account on the machine named exactly the same as the domain account and with the exact same password. If you do it might be that the NTLM challenge is built for the wrong account. I assume you're using QVWS as a web server so pay attention it does not support Kerberos, only NTLM (as opposed to IIS). If you do run IIS I would create a simple test asp-page, protect it with IWA and try accessing it from the client.

Another thing to look for is the security settings for the zone in Internet Explorer.
Go to Tools->Internet Options->Security and select Local intranet.
First check that the URL is in this zone (by pressing the Sites-buttonm then the Advanced button). If not, add it.
If you customized the security level for this zone I suggest you press "Reset all zones to default level"

If still no joy I suggest running Fiddler to trace the traffic or as a last resort Wireshark (but then you're down to TCP-level communication and it might not be easy to fully analyze the output).

Not applicable
Author

Bjorn thanks for your through response.

I tried the IE security zones in my initial troubleshooting all to no avail. This occurs in Firefox to. I do not believe IE is to blame as much as I want to blame it.

It should be noted the user can access the IIS 'default' page.

The user was able to login into QV in the past. One day it worked. The next day it did not. I did not attempt to change any server side settings simply because I can login into another machine with the user credentials and the user can access QV just fine. This led me to believe it is unique with this users machine.

I have given the end user three options.

  1. Re image machine
  2. Use System Restore to before the issue happened
  3. Remove local user account on local machine. Login as user on domain. Let Windows rebuilt profile.


I am awaiting the end users response. I do not like any of the options but I know 1 will work for sure. 2 and 3 have a chance.

I will let you know which of these options worked.

Thanks.

Not applicable
Author

...

Good find on the end user on this one. The end user runs Spybot on his machine as part of his routine.

Spybot reported he had a proxy setup on IE. We do not use a proxy...

After the end user turned this off, he was able access QV. This proxy must applied to Fire and IE.

So lesson learned. Check proxy settings.

Thanks for all the help on this issue.

Bjorn_Wedbratt
Former Employee
Former Employee

Great that you found the root-cause. Some products "hook" into IE/FF etc by altering the proxy settings (Fiddler does it for example to be able to sniff the traffic between the browser and the network) so this is always a good thing to check.

Thanks for posting the solution to your problem as it might help others reminding the proxy settings 🙂

Regards,
Bjorn