<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>idea Re: Modify claims in Identity Mapping - Status changed to: Open - Collecting Feedback in Suggest an Idea</title>
    <link>https://community.qlik.com/t5/Suggest-an-Idea/Modify-claims-in-Identity-Mapping/idc-p/1723463#M2677</link>
    <description>&lt;P&gt;&lt;a href="https://community.qlik.com/t5/user/viewprofilepage/user-id/35422"&gt;@ergustafsson&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;&lt;P&gt;Thank you for the feedback. There are two parts to your request so let's take them in turn.&lt;/P&gt;&lt;P&gt;RE: Multi-cloud&lt;/P&gt;&lt;P&gt;The multi-cloud challenge with the user stripped in Qlik Sense SaaS upon first synchro with Windows is less about IdP not able to deal with mappings properly, and just that in the synchro the user information is different. We're looking into different transport methods for moving workloads to the cloud that could bring personal content over and offer some remapping of users from the old system to the new. This is going to find it's way into the world in the cli first because it's much more easily scriptable what with all the mappings (users, streams to spaces, etc) involved in making the transport seamless.&lt;/P&gt;&lt;P&gt;For now, you have to go and set the new owner and the new space manually after the first synchro, but then should work after that.&lt;/P&gt;&lt;P&gt;RE: More customization of IdP claims&lt;/P&gt;&lt;P&gt;Acknowledged and understood. I've been trying to find a way to deal with it on the IdP side because you rightly point out the lack of standards. Microsoft does not make it easy and being the big fish doesn't help us much. So we're looking into the effort to enhance customization of claims mapping.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;jg&lt;/P&gt;</description>
    <pubDate>Tue, 30 Jun 2020 11:08:54 GMT</pubDate>
    <dc:creator>Jeffrey_Goldberg</dc:creator>
    <dc:date>2020-06-30T11:08:54Z</dc:date>
    <item>
      <title>Modify claims in Identity Mapping</title>
      <link>https://community.qlik.com/t5/Suggest-an-Idea/Modify-claims-in-Identity-Mapping/idi-p/1723386</link>
      <description>&lt;P&gt;Using Qlik SaaS solutions (QSEoCS) we intend to connect with multi cloud with our QSEoW setup. Generally things are working, but due to Open ID Connect being a specification and not a standard, some idp providers like Azure AD does not provide all claims that allows such an identity mapping to work.&lt;/P&gt;&lt;P&gt;The consequence is that all apps being deployed to a cloud solution gets published without an owner. This makes the "self-service" not a viable solution when using multi cloud.&lt;/P&gt;&lt;P&gt;In this particular case, the OIDC claim email_verified is missing. The on-prem SAML authentication that connects to this, seems to generally work.&lt;/P&gt;&lt;P&gt;The idea here is to be able to modify, to hardcode, to change or to alter how the identity mapping is enforced between the cloud and the on-prem solution, irrelevant of the idp provider. From the end-user point of view, everything is set up correctly (userid the same, name the same etc), but due to all different IDP providers interpreting OIDC differently, we need to be able to affect the setup in how Qlik handles the identities.&lt;/P&gt;</description>
      <pubDate>Wed, 25 Nov 2020 08:56:29 GMT</pubDate>
      <guid>https://community.qlik.com/t5/Suggest-an-Idea/Modify-claims-in-Identity-Mapping/idi-p/1723386</guid>
      <dc:creator>ergustafsson</dc:creator>
      <dc:date>2020-11-25T08:56:29Z</dc:date>
    </item>
    <item>
      <title>Re: Modify claims in Identity Mapping - Status changed to: Open - Collecting Feedback</title>
      <link>https://community.qlik.com/t5/Suggest-an-Idea/Modify-claims-in-Identity-Mapping/idc-p/1723463#M2677</link>
      <description>&lt;P&gt;&lt;a href="https://community.qlik.com/t5/user/viewprofilepage/user-id/35422"&gt;@ergustafsson&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;&lt;P&gt;Thank you for the feedback. There are two parts to your request so let's take them in turn.&lt;/P&gt;&lt;P&gt;RE: Multi-cloud&lt;/P&gt;&lt;P&gt;The multi-cloud challenge with the user stripped in Qlik Sense SaaS upon first synchro with Windows is less about IdP not able to deal with mappings properly, and just that in the synchro the user information is different. We're looking into different transport methods for moving workloads to the cloud that could bring personal content over and offer some remapping of users from the old system to the new. This is going to find it's way into the world in the cli first because it's much more easily scriptable what with all the mappings (users, streams to spaces, etc) involved in making the transport seamless.&lt;/P&gt;&lt;P&gt;For now, you have to go and set the new owner and the new space manually after the first synchro, but then should work after that.&lt;/P&gt;&lt;P&gt;RE: More customization of IdP claims&lt;/P&gt;&lt;P&gt;Acknowledged and understood. I've been trying to find a way to deal with it on the IdP side because you rightly point out the lack of standards. Microsoft does not make it easy and being the big fish doesn't help us much. So we're looking into the effort to enhance customization of claims mapping.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;jg&lt;/P&gt;</description>
      <pubDate>Tue, 30 Jun 2020 11:08:54 GMT</pubDate>
      <guid>https://community.qlik.com/t5/Suggest-an-Idea/Modify-claims-in-Identity-Mapping/idc-p/1723463#M2677</guid>
      <dc:creator>Jeffrey_Goldberg</dc:creator>
      <dc:date>2020-06-30T11:08:54Z</dc:date>
    </item>
    <item>
      <title>Re: Modify claims in Identity Mapping</title>
      <link>https://community.qlik.com/t5/Suggest-an-Idea/Modify-claims-in-Identity-Mapping/idc-p/1723470#M2680</link>
      <description>&lt;P&gt;Thanks for the feedback&amp;nbsp;&lt;a href="https://community.qlik.com/t5/user/viewprofilepage/user-id/45015"&gt;@Jeffrey_Goldberg&lt;/a&gt;&amp;nbsp; .&amp;nbsp;&lt;/P&gt;&lt;P&gt;I mean the second "idea" - '&lt;SPAN&gt;customization&amp;nbsp; of IdP claims' is essentially due to the multi cloud doesn't transport the workload as you mention (which is the first one). But I guess it is two separate things, yes. It's really that we have to manually set the owner that causes a pain for a sysadmin, and even though it is Microsofts "fault", we still have the problem. We do have quite a bunch of PS scripts for QSEoW so if there is a way with the new qlik-cli, I'm all open for that.&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 30 Jun 2020 11:20:49 GMT</pubDate>
      <guid>https://community.qlik.com/t5/Suggest-an-Idea/Modify-claims-in-Identity-Mapping/idc-p/1723470#M2680</guid>
      <dc:creator>ergustafsson</dc:creator>
      <dc:date>2020-06-30T11:20:49Z</dc:date>
    </item>
    <item>
      <title>Re: Modify claims in Identity Mapping</title>
      <link>https://community.qlik.com/t5/Suggest-an-Idea/Modify-claims-in-Identity-Mapping/idc-p/1723483#M2683</link>
      <description>&lt;P&gt;Yes, the cli will have user commands in an upcoming release along with some access to qrs for app migration and multi-cloud scenarios.&lt;/P&gt;&lt;P&gt;In theory, you can connect to qrs today using the cli by creating a context using a jwt and a jwt vproxy. then use the qlik raw command to issue requests directly to qrs. Like I said, eventually some helper commands to qrs will be available.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;jg&lt;/P&gt;</description>
      <pubDate>Tue, 30 Jun 2020 11:50:29 GMT</pubDate>
      <guid>https://community.qlik.com/t5/Suggest-an-Idea/Modify-claims-in-Identity-Mapping/idc-p/1723483#M2683</guid>
      <dc:creator>Jeffrey_Goldberg</dc:creator>
      <dc:date>2020-06-30T11:50:29Z</dc:date>
    </item>
    <item>
      <title>Re: Modify claims in Identity Mapping</title>
      <link>https://community.qlik.com/t5/Suggest-an-Idea/Modify-claims-in-Identity-Mapping/idc-p/1723532#M2687</link>
      <description>&lt;P&gt;same here... the lack of email is a major problem, as we're unable to share apps visualizations by email! also profile picture wont work&lt;/P&gt;</description>
      <pubDate>Tue, 30 Jun 2020 13:33:02 GMT</pubDate>
      <guid>https://community.qlik.com/t5/Suggest-an-Idea/Modify-claims-in-Identity-Mapping/idc-p/1723532#M2687</guid>
      <dc:creator>sfbi</dc:creator>
      <dc:date>2020-06-30T13:33:02Z</dc:date>
    </item>
    <item>
      <title>Re: Modify claims in Identity Mapping - Status changed to: Open - On Roadmap</title>
      <link>https://community.qlik.com/t5/Suggest-an-Idea/Modify-claims-in-Identity-Mapping/idc-p/1745882#M3526</link>
      <description />
      <pubDate>Tue, 22 Sep 2020 08:39:32 GMT</pubDate>
      <guid>https://community.qlik.com/t5/Suggest-an-Idea/Modify-claims-in-Identity-Mapping/idc-p/1745882#M3526</guid>
      <dc:creator>Ian_Crosland</dc:creator>
      <dc:date>2020-09-22T08:39:32Z</dc:date>
    </item>
    <item>
      <title>Re: Modify claims in Identity Mapping</title>
      <link>https://community.qlik.com/t5/Suggest-an-Idea/Modify-claims-in-Identity-Mapping/idc-p/1773958#M4733</link>
      <description>&lt;P&gt;This appears to be fixed already:&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="erikadvectas_0-1610528660417.png" style="width: 400px;"&gt;&lt;img src="https://community.qlik.com/t5/image/serverpage/image-id/46878i4750AF5FEA50D279/image-size/medium?v=v2&amp;amp;px=400" role="button" title="erikadvectas_0-1610528660417.png" alt="erikadvectas_0-1610528660417.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 13 Jan 2021 09:04:28 GMT</pubDate>
      <guid>https://community.qlik.com/t5/Suggest-an-Idea/Modify-claims-in-Identity-Mapping/idc-p/1773958#M4733</guid>
      <dc:creator>ergustafsson</dc:creator>
      <dc:date>2021-01-13T09:04:28Z</dc:date>
    </item>
    <item>
      <title>Re: Modify claims in Identity Mapping</title>
      <link>https://community.qlik.com/t5/Suggest-an-Idea/Modify-claims-in-Identity-Mapping/idc-p/1786272#M5324</link>
      <description>&lt;P&gt;&lt;SPAN class="style-scope yt-formatted-string"&gt;Hi Team,&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN class="style-scope yt-formatted-string"&gt;What to do when User ID and Idp Subject contains multiple characters like (auth0jhabajkfkfkfkfkanknL) instead of Domain\username&lt;/SPAN&gt;&amp;nbsp;.&lt;SPAN class="style-scope yt-formatted-string"&gt;Would be grateful if you can suggest on this.&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 25 Feb 2021 15:40:36 GMT</pubDate>
      <guid>https://community.qlik.com/t5/Suggest-an-Idea/Modify-claims-in-Identity-Mapping/idc-p/1786272#M5324</guid>
      <dc:creator>pavi</dc:creator>
      <dc:date>2021-02-25T15:40:36Z</dc:date>
    </item>
    <item>
      <title>From now on, please track this idea from the Ideation por...</title>
      <link>https://community.qlik.com/t5/Suggest-an-Idea/Modify-claims-in-Identity-Mapping/idc-p/2100655#M13906</link>
      <description>&lt;P&gt;From now on, please track this idea from the Ideation portal.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;&lt;A title="Link to new idea" href="https://ideation.qlik.com/app/#/case/275017" target="_blank" rel="noopener"&gt;Link to new idea&lt;/A&gt;&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;Meghann&lt;/P&gt;&lt;P data-unlink="true"&gt;&lt;EM&gt;NOTE: Upon clicking this link 2 tabs may open - please feel free to close the one with a login page. If you &lt;STRONG&gt;only&lt;/STRONG&gt; see 1 tab with the login page, please try clicking this link first: &lt;STRONG&gt;&lt;A title="Authenticate me!" href="#" target="_blank" rel="noopener"&gt;Authenticate me!&lt;/A&gt;&lt;/STRONG&gt;&amp;nbsp;t&lt;/EM&gt;&lt;EM&gt;hen try the link above again. Ensure pop-up blocker is off.&lt;/EM&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 02 Aug 2023 15:45:52 GMT</pubDate>
      <guid>https://community.qlik.com/t5/Suggest-an-Idea/Modify-claims-in-Identity-Mapping/idc-p/2100655#M13906</guid>
      <dc:creator>Meghann_MacDonald</dc:creator>
      <dc:date>2023-08-02T15:45:52Z</dc:date>
    </item>
    <item>
      <title>Re: Modify claims in Identity Mapping - Status changed to: Closed - Archived</title>
      <link>https://community.qlik.com/t5/Suggest-an-Idea/Modify-claims-in-Identity-Mapping/idc-p/2100656#M13907</link>
      <description />
      <pubDate>Wed, 02 Aug 2023 15:45:54 GMT</pubDate>
      <guid>https://community.qlik.com/t5/Suggest-an-Idea/Modify-claims-in-Identity-Mapping/idc-p/2100656#M13907</guid>
      <dc:creator>Ideation</dc:creator>
      <dc:date>2023-08-02T15:45:54Z</dc:date>
    </item>
    <item>
      <title>Re: Modify claims in Identity Mapping - Status changed to: Delivered</title>
      <link>https://community.qlik.com/t5/Suggest-an-Idea/Modify-claims-in-Identity-Mapping/idc-p/2123973#M16991</link>
      <description />
      <pubDate>Fri, 29 Sep 2023 14:47:03 GMT</pubDate>
      <guid>https://community.qlik.com/t5/Suggest-an-Idea/Modify-claims-in-Identity-Mapping/idc-p/2123973#M16991</guid>
      <dc:creator>Meghann_MacDonald</dc:creator>
      <dc:date>2023-09-29T14:47:03Z</dc:date>
    </item>
  </channel>
</rss>

