<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Trusted Domain Users and UDC in Management &amp; Governance</title>
    <link>https://community.qlik.com/t5/Management-Governance/Trusted-Domain-Users-and-UDC/m-p/1423689#M11170</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I have users in two domains that need access to Qlik Sense. I am syncing one root AD group in domain A with my UDC. All users are members of this group through group nesting. Everything works fine within domain A.&lt;/P&gt;&lt;P&gt;I can even add domain B users to a nested group in domain A and they will be created in Sense.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;However, none of the domain B users' group membership is brought in with it.&lt;/P&gt;&lt;P&gt;We are using custom properties mapped to an AD group to assign permissions in Sense so the users from domain B have no permissions.&amp;nbsp; &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Domain B users are direct members of group1 in Domain A that is a member (nested) of group2 that is synced with a Sense UDC. &lt;/P&gt;&lt;P&gt;We have a two-way transitive trust between the domains. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;My question is, how do I get the UDC (AD/LDAP) to resolve the group membership of users in an external domain?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Mon, 18 Dec 2017 21:33:59 GMT</pubDate>
    <dc:creator>lucienorrin</dc:creator>
    <dc:date>2017-12-18T21:33:59Z</dc:date>
    <item>
      <title>Trusted Domain Users and UDC</title>
      <link>https://community.qlik.com/t5/Management-Governance/Trusted-Domain-Users-and-UDC/m-p/1423689#M11170</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I have users in two domains that need access to Qlik Sense. I am syncing one root AD group in domain A with my UDC. All users are members of this group through group nesting. Everything works fine within domain A.&lt;/P&gt;&lt;P&gt;I can even add domain B users to a nested group in domain A and they will be created in Sense.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;However, none of the domain B users' group membership is brought in with it.&lt;/P&gt;&lt;P&gt;We are using custom properties mapped to an AD group to assign permissions in Sense so the users from domain B have no permissions.&amp;nbsp; &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Domain B users are direct members of group1 in Domain A that is a member (nested) of group2 that is synced with a Sense UDC. &lt;/P&gt;&lt;P&gt;We have a two-way transitive trust between the domains. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;My question is, how do I get the UDC (AD/LDAP) to resolve the group membership of users in an external domain?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 18 Dec 2017 21:33:59 GMT</pubDate>
      <guid>https://community.qlik.com/t5/Management-Governance/Trusted-Domain-Users-and-UDC/m-p/1423689#M11170</guid>
      <dc:creator>lucienorrin</dc:creator>
      <dc:date>2017-12-18T21:33:59Z</dc:date>
    </item>
    <item>
      <title>Re: Trusted Domain Users and UDC</title>
      <link>https://community.qlik.com/t5/Management-Governance/Trusted-Domain-Users-and-UDC/m-p/1423690#M11171</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Ok, so it turns out the users from domain B are not synced. It just so happens the users tried to access the hub and were created automatically in Sense.&lt;/P&gt;&lt;P&gt;The user account is still not associated (in Sense) with the groups in domain A they are members of.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Is this a limitation of LDAP?&lt;/P&gt;&lt;P&gt;It looks like external users are represented as ForeignSecurityPrincipals (SIDs) when using LDAP. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I would like to add this is ridiculously easy using powershell...&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;EM&gt;Get-ADGroupMember -Identity &amp;lt;Group&amp;gt; -Recursive | select name&lt;/EM&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 20 Dec 2017 15:00:47 GMT</pubDate>
      <guid>https://community.qlik.com/t5/Management-Governance/Trusted-Domain-Users-and-UDC/m-p/1423690#M11171</guid>
      <dc:creator>lucienorrin</dc:creator>
      <dc:date>2017-12-20T15:00:47Z</dc:date>
    </item>
    <item>
      <title>Re: Trusted Domain Users and UDC</title>
      <link>https://community.qlik.com/t5/Management-Governance/Trusted-Domain-Users-and-UDC/m-p/1750253#M16762</link>
      <description>&lt;P&gt;Hello Lucienorrin,&lt;/P&gt;&lt;P&gt;I have the same problem and I don't found the solution. Did you resolve it ?&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;</description>
      <pubDate>Wed, 07 Oct 2020 09:03:56 GMT</pubDate>
      <guid>https://community.qlik.com/t5/Management-Governance/Trusted-Domain-Users-and-UDC/m-p/1750253#M16762</guid>
      <dc:creator>paulcalvet</dc:creator>
      <dc:date>2020-10-07T09:03:56Z</dc:date>
    </item>
  </channel>
</rss>

