<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Qlik Sense Windows Auth0/SAML Licence Allocation in Management &amp; Governance</title>
    <link>https://community.qlik.com/t5/Management-Governance/Qlik-Sense-Windows-Auth0-SAML-Licence-Allocation/m-p/1767767#M17062</link>
    <description>&lt;P&gt;Hi everyone,&lt;/P&gt;&lt;P&gt;Looked in all corners of the internet for an answer on this one and I can't find a thing!&lt;/P&gt;&lt;P&gt;I'm using Auth0 IDP to authenticate with Qlik Sense via SAML. I'm successfully able to authenticate and log users into Qlik.&amp;nbsp; I've created some rules in Auth0 to pass some business Groups like "Finance", "Marketing" etc. I pass this into Qlik Sense using user.environment.Groups I can then pass this into Qlik where I've built some Custom Properties to automatically assign Stream and Data Connection access. Works perfectly.&amp;nbsp;&lt;/P&gt;&lt;P&gt;I understand that these session variables (user.enviornment.Groups) are not persisted in Qlik Sense.&amp;nbsp;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Now my issue..&lt;/P&gt;&lt;P&gt;In Auth0 I created a Role concept, which can either be "Professional" or "Analyzer" depending on the access the user should be assigned, once again I pass this from Auth0 into Qlik, and have a variable user.enviornment.Role. I tired to use my variable to assign either Analyzer or Professional user licence, so that way whatever is mapped in Auth0 just permits access. However.... it doesn't work? I am certain that the Role is making it into Qlik Sense, I decoded the SAML response, and also tried to apply it to streams to ensure it is getting there, definitely is.&amp;nbsp;&lt;/P&gt;&lt;P&gt;So I don't know why this isn't working, I suspect it may be something to do with session variables not being persisted in Qlik Sense? I've read there are a number of other people running SAML auth method, so I'd really like to hear from someone else how they achieved this?&lt;/P&gt;&lt;P&gt;I think I can probably decode the SAML and hit the licence REST API on the fly to assign a licence, but surely there is an easier way to this that I am not considering?&lt;/P&gt;&lt;P&gt;If I can get this last component to work the system should be perfect for my requirements.&amp;nbsp;&lt;/P&gt;&lt;P&gt;Many thanks,&lt;/P&gt;&lt;P&gt;Thomas&lt;/P&gt;</description>
    <pubDate>Fri, 11 Dec 2020 00:18:54 GMT</pubDate>
    <dc:creator>thomas_evans</dc:creator>
    <dc:date>2020-12-11T00:18:54Z</dc:date>
    <item>
      <title>Qlik Sense Windows Auth0/SAML Licence Allocation</title>
      <link>https://community.qlik.com/t5/Management-Governance/Qlik-Sense-Windows-Auth0-SAML-Licence-Allocation/m-p/1767767#M17062</link>
      <description>&lt;P&gt;Hi everyone,&lt;/P&gt;&lt;P&gt;Looked in all corners of the internet for an answer on this one and I can't find a thing!&lt;/P&gt;&lt;P&gt;I'm using Auth0 IDP to authenticate with Qlik Sense via SAML. I'm successfully able to authenticate and log users into Qlik.&amp;nbsp; I've created some rules in Auth0 to pass some business Groups like "Finance", "Marketing" etc. I pass this into Qlik Sense using user.environment.Groups I can then pass this into Qlik where I've built some Custom Properties to automatically assign Stream and Data Connection access. Works perfectly.&amp;nbsp;&lt;/P&gt;&lt;P&gt;I understand that these session variables (user.enviornment.Groups) are not persisted in Qlik Sense.&amp;nbsp;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Now my issue..&lt;/P&gt;&lt;P&gt;In Auth0 I created a Role concept, which can either be "Professional" or "Analyzer" depending on the access the user should be assigned, once again I pass this from Auth0 into Qlik, and have a variable user.enviornment.Role. I tired to use my variable to assign either Analyzer or Professional user licence, so that way whatever is mapped in Auth0 just permits access. However.... it doesn't work? I am certain that the Role is making it into Qlik Sense, I decoded the SAML response, and also tried to apply it to streams to ensure it is getting there, definitely is.&amp;nbsp;&lt;/P&gt;&lt;P&gt;So I don't know why this isn't working, I suspect it may be something to do with session variables not being persisted in Qlik Sense? I've read there are a number of other people running SAML auth method, so I'd really like to hear from someone else how they achieved this?&lt;/P&gt;&lt;P&gt;I think I can probably decode the SAML and hit the licence REST API on the fly to assign a licence, but surely there is an easier way to this that I am not considering?&lt;/P&gt;&lt;P&gt;If I can get this last component to work the system should be perfect for my requirements.&amp;nbsp;&lt;/P&gt;&lt;P&gt;Many thanks,&lt;/P&gt;&lt;P&gt;Thomas&lt;/P&gt;</description>
      <pubDate>Fri, 11 Dec 2020 00:18:54 GMT</pubDate>
      <guid>https://community.qlik.com/t5/Management-Governance/Qlik-Sense-Windows-Auth0-SAML-Licence-Allocation/m-p/1767767#M17062</guid>
      <dc:creator>thomas_evans</dc:creator>
      <dc:date>2020-12-11T00:18:54Z</dc:date>
    </item>
    <item>
      <title>Re: Qlik Sense Windows Auth0/SAML Licence Allocation</title>
      <link>https://community.qlik.com/t5/Management-Governance/Qlik-Sense-Windows-Auth0-SAML-Licence-Allocation/m-p/1904969#M21537</link>
      <description>&lt;P&gt;hi&amp;nbsp;&lt;a href="https://community.qlik.com/t5/user/viewprofilepage/user-id/29497"&gt;@thomas_evans&lt;/a&gt;&amp;nbsp; - did you ever get this working? We are looking for a similar solution&lt;/P&gt;</description>
      <pubDate>Mon, 14 Mar 2022 20:08:53 GMT</pubDate>
      <guid>https://community.qlik.com/t5/Management-Governance/Qlik-Sense-Windows-Auth0-SAML-Licence-Allocation/m-p/1904969#M21537</guid>
      <dc:creator>Senor_Dai</dc:creator>
      <dc:date>2022-03-14T20:08:53Z</dc:date>
    </item>
    <item>
      <title>Re: Qlik Sense Windows Auth0/SAML Licence Allocation</title>
      <link>https://community.qlik.com/t5/Management-Governance/Qlik-Sense-Windows-Auth0-SAML-Licence-Allocation/m-p/1905000#M21539</link>
      <description>&lt;P&gt;Hi,&amp;nbsp;&lt;/P&gt;
&lt;P&gt;No, I never managed to get it working, session variables couldn't be referenced. In the end I automatically assigned analyzer licenses, and then manually assigned professional licenses where required. Not as elegant as I would have liked, but does the trick.&lt;/P&gt;</description>
      <pubDate>Mon, 14 Mar 2022 22:00:32 GMT</pubDate>
      <guid>https://community.qlik.com/t5/Management-Governance/Qlik-Sense-Windows-Auth0-SAML-Licence-Allocation/m-p/1905000#M21539</guid>
      <dc:creator>thomas_evans</dc:creator>
      <dc:date>2022-03-14T22:00:32Z</dc:date>
    </item>
  </channel>
</rss>

