<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Out of box SSO using AD not working.  Prerequisites? in Management &amp; Governance</title>
    <link>https://community.qlik.com/t5/Management-Governance/Out-of-box-SSO-using-AD-not-working-Prerequisites/m-p/9958#M193</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;BLOCKQUOTE&gt;&lt;TABLE border="1"&gt;&lt;TBODY&gt;&lt;TR&gt;&lt;TD&gt;
&lt;P&gt;My gut is that Qlik isn't able to use the domain AD.&amp;nbsp; Does the Qlik Sense server account need to be a domain account (with some special AD rights)?&amp;nbsp; Does there need to be some other service running on the server to use the AD I'm not aware of?&lt;/P&gt;



&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;&lt;/BLOCKQUOTE&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;From the Qlik Support side, we will always recommend using a domain account when the server is on the domain. This makes permissions to remote resources a much easier adventure.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If this is not possible (right now or long-term), then you can do the following:&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;QMC &amp;gt; User Directory Connectors&lt;/LI&gt;&lt;LI&gt;Create New &amp;gt; Active Directory&lt;/LI&gt;&lt;LI&gt;Expand the &lt;STRONG&gt;Connection&lt;/STRONG&gt; section on the right hand side&lt;UL&gt;&lt;LI&gt;The &lt;STRONG&gt;Path&lt;/STRONG&gt; likely has already been picked up&lt;/LI&gt;&lt;LI&gt;Enter in a valid set of domain credentials for the &lt;STRONG&gt;User Name&lt;/STRONG&gt; and &lt;STRONG&gt;Password&lt;/STRONG&gt; fields&lt;/LI&gt;&lt;/UL&gt;&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;&lt;IMG alt="8eSZ5UZ.png" class="jive-image image-1" src="https://i.imgur.com/8eSZ5UZ.png" style="height: 189px; width: 620px;" /&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;This will allow you to leverage domain credentials to have the trust needed to make a query to the domain controller(s).&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The only aspect to take note of here is that be sure that these credentials are updated whenever they are updated on AD. For example, if you use your credentials then you likely have a 30/60/90 day password expiration policy where you need to change you password. Once doing this for yourself, the UDC will need updating as well.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hope that helps.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Mon, 14 May 2018 13:59:31 GMT</pubDate>
    <dc:creator>Levi_Turner</dc:creator>
    <dc:date>2018-05-14T13:59:31Z</dc:date>
    <item>
      <title>Out of box SSO using AD not working.  Prerequisites?</title>
      <link>https://community.qlik.com/t5/Management-Governance/Out-of-box-SSO-using-AD-not-working-Prerequisites/m-p/9956#M191</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Installed QS Server using a server-local service account with admin rights on an Azure VM that is connected to our domain.&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt;"&gt;If I try to log on to the Hub or QMC via a client on the domain I'm asked to authenticate with ID and password; a domain ID doesn't work, only a server local account does.&amp;nbsp; Ditto if I do try to log on to the Hub or QMC on the server.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt;"&gt;Via the Operations Monitor, Log Detail view I see the Proxy Service threw the error: Authenticate Request (ReceiveRequestAsync) failed.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;My gut is that Qlik isn't able to use the domain AD.&amp;nbsp; Does the Qlik Sense server account need to be a domain account (with some special AD rights)?&amp;nbsp; Does there need to be some other service running on the server to use the AD I'm not aware of?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Any suggestions would be appreciated &lt;IMG src="https://community.qlik.com/legacyfs/online/emoticons/happy.png" /&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 09 May 2018 14:00:58 GMT</pubDate>
      <guid>https://community.qlik.com/t5/Management-Governance/Out-of-box-SSO-using-AD-not-working-Prerequisites/m-p/9956#M191</guid>
      <dc:creator>davetrentwipro</dc:creator>
      <dc:date>2018-05-09T14:00:58Z</dc:date>
    </item>
    <item>
      <title>Re: Out of box SSO using AD not working.  Prerequisites?</title>
      <link>https://community.qlik.com/t5/Management-Governance/Out-of-box-SSO-using-AD-not-working-Prerequisites/m-p/9957#M192</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi David,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;have you checked:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A href="https://help.qlik.com/en-US/sense/April2018/Subsystems/PlanningQlikSenseDeployments/Content/Deployment/AWS-and-Azure-security.htm" title="https://help.qlik.com/en-US/sense/April2018/Subsystems/PlanningQlikSenseDeployments/Content/Deployment/AWS-and-Azure-security.htm"&gt;https://help.qlik.com/en-US/sense/April2018/Subsystems/PlanningQlikSenseDeployments/Content/Deployment/AWS-and-Azure-sec…&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;best regards&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Andy&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 09 May 2018 15:24:28 GMT</pubDate>
      <guid>https://community.qlik.com/t5/Management-Governance/Out-of-box-SSO-using-AD-not-working-Prerequisites/m-p/9957#M192</guid>
      <dc:creator>awhitfield</dc:creator>
      <dc:date>2018-05-09T15:24:28Z</dc:date>
    </item>
    <item>
      <title>Re: Out of box SSO using AD not working.  Prerequisites?</title>
      <link>https://community.qlik.com/t5/Management-Governance/Out-of-box-SSO-using-AD-not-working-Prerequisites/m-p/9958#M193</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;BLOCKQUOTE&gt;&lt;TABLE border="1"&gt;&lt;TBODY&gt;&lt;TR&gt;&lt;TD&gt;
&lt;P&gt;My gut is that Qlik isn't able to use the domain AD.&amp;nbsp; Does the Qlik Sense server account need to be a domain account (with some special AD rights)?&amp;nbsp; Does there need to be some other service running on the server to use the AD I'm not aware of?&lt;/P&gt;



&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;&lt;/BLOCKQUOTE&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;From the Qlik Support side, we will always recommend using a domain account when the server is on the domain. This makes permissions to remote resources a much easier adventure.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If this is not possible (right now or long-term), then you can do the following:&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;QMC &amp;gt; User Directory Connectors&lt;/LI&gt;&lt;LI&gt;Create New &amp;gt; Active Directory&lt;/LI&gt;&lt;LI&gt;Expand the &lt;STRONG&gt;Connection&lt;/STRONG&gt; section on the right hand side&lt;UL&gt;&lt;LI&gt;The &lt;STRONG&gt;Path&lt;/STRONG&gt; likely has already been picked up&lt;/LI&gt;&lt;LI&gt;Enter in a valid set of domain credentials for the &lt;STRONG&gt;User Name&lt;/STRONG&gt; and &lt;STRONG&gt;Password&lt;/STRONG&gt; fields&lt;/LI&gt;&lt;/UL&gt;&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;&lt;IMG alt="8eSZ5UZ.png" class="jive-image image-1" src="https://i.imgur.com/8eSZ5UZ.png" style="height: 189px; width: 620px;" /&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;This will allow you to leverage domain credentials to have the trust needed to make a query to the domain controller(s).&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The only aspect to take note of here is that be sure that these credentials are updated whenever they are updated on AD. For example, if you use your credentials then you likely have a 30/60/90 day password expiration policy where you need to change you password. Once doing this for yourself, the UDC will need updating as well.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hope that helps.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 14 May 2018 13:59:31 GMT</pubDate>
      <guid>https://community.qlik.com/t5/Management-Governance/Out-of-box-SSO-using-AD-not-working-Prerequisites/m-p/9958#M193</guid>
      <dc:creator>Levi_Turner</dc:creator>
      <dc:date>2018-05-14T13:59:31Z</dc:date>
    </item>
    <item>
      <title>Re: Out of box SSO using AD not working.  Prerequisites?</title>
      <link>https://community.qlik.com/t5/Management-Governance/Out-of-box-SSO-using-AD-not-working-Prerequisites/m-p/9959#M194</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks much Levi!&lt;/P&gt;&lt;P&gt;Created a UDC against the AD.&amp;nbsp; Query ran successfully as per the logs: am waiting for "asynchronous" response from the AD.&amp;nbsp; (Did uncheck the box "existing users" box.)&lt;/P&gt;&lt;P&gt;I entered the following filter so as not to bring down the whole AD &lt;IMG src="https://community.qlik.com/legacyfs/online/emoticons/shocked.png" /&gt;&lt;/P&gt;&lt;P&gt;( &amp;amp;(objectCategory=person)(objectClass=user)(cn=Jay*) )&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;Quick question: Does the user identified by the UDC need to have User object update rights (e.g. Root Admin) as a QS user in order to allow a write of the retrieved users?&amp;nbsp; Am curious as I don't see an owner attribute for UDC.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 14 May 2018 14:12:45 GMT</pubDate>
      <guid>https://community.qlik.com/t5/Management-Governance/Out-of-box-SSO-using-AD-not-working-Prerequisites/m-p/9959#M194</guid>
      <dc:creator>davetrentwipro</dc:creator>
      <dc:date>2018-05-14T14:12:45Z</dc:date>
    </item>
    <item>
      <title>Re: Out of box SSO using AD not working.  Prerequisites?</title>
      <link>https://community.qlik.com/t5/Management-Governance/Out-of-box-SSO-using-AD-not-working-Prerequisites/m-p/9960#M195</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I am not 100% sure that filter will be successful. I would expect something like this: (&amp;amp;(objectCategory=person)(objectClass=user)(memberof=CN=Example Group,OU=DL,OU=Groups,DC=company,DC=com))&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;There's an article in our KB in the Support Portal titled Qlik Sense: How to create a filter in Directory Connector (and test it), which can be used to test LDAP filters outside of Sense since Qlik just sends the query to AD.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Technet documentation on the matter: &lt;A href="http://social.technet.microsoft.com/wiki/contents/articles/5392.active-directory-ldap-syntax-filters.aspx" title="http://social.technet.microsoft.com/wiki/contents/articles/5392.active-directory-ldap-syntax-filters.aspx"&gt;http://social.technet.microsoft.com/wiki/contents/articles/5392.active-directory-ldap-syntax-filters.aspx&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;BLOCKQUOTE&gt;&lt;TABLE border="1"&gt;&lt;TBODY&gt;&lt;TR&gt;&lt;TD&gt;
&lt;P&gt;Quick question: Does the user identified by the UDC need to have User object update rights (e.g. Root Admin) as a QS user in order to allow a write of the retrieved users? Am curious as I don't see an owner attribute for UDC.&lt;/P&gt;
&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;&lt;/BLOCKQUOTE&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;No, they do not. The account that does the changes is the sa_repository account which has sufficient rights inside of Qlik Sense to do what it needs to do.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 14 May 2018 21:43:41 GMT</pubDate>
      <guid>https://community.qlik.com/t5/Management-Governance/Out-of-box-SSO-using-AD-not-working-Prerequisites/m-p/9960#M195</guid>
      <dc:creator>Levi_Turner</dc:creator>
      <dc:date>2018-05-14T21:43:41Z</dc:date>
    </item>
    <item>
      <title>Re: Out of box SSO using AD not working.  Prerequisites?</title>
      <link>https://community.qlik.com/t5/Management-Governance/Out-of-box-SSO-using-AD-not-working-Prerequisites/m-p/9961#M196</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks again Levi (and Andy)!&lt;/P&gt;&lt;P&gt;I used the Support document &lt;STRONG&gt;&lt;EM&gt;How To Validate LDAP User Directory Connection&lt;/EM&gt;&lt;/STRONG&gt; to confirm what the QS Server logs were showing me: neither the service account (local to server) or my domain account (no special privileges) had rights to access the company LDAP.&amp;nbsp; We have a special rights account that didn't throw errors and also worked with the Softerra LDAP Browser.&lt;/P&gt;&lt;P&gt;I used that in conjunction with the article you suggested and associated links to learn a bit more about LDAP filters and had tried (&amp;amp;(objectClass=user)(cn=Jaya*)) with success.&amp;nbsp; Admitted will need different, more targeted filters going forward -- step 1 was to make it work.&lt;/P&gt;&lt;P&gt;Still need to confirm one of the users fetched can authenticate but am optimistic -- assume it worked unless I repost &lt;IMG src="https://community.qlik.com/legacyfs/online/emoticons/happy.png" /&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 15 May 2018 18:10:40 GMT</pubDate>
      <guid>https://community.qlik.com/t5/Management-Governance/Out-of-box-SSO-using-AD-not-working-Prerequisites/m-p/9961#M196</guid>
      <dc:creator>davetrentwipro</dc:creator>
      <dc:date>2018-05-15T18:10:40Z</dc:date>
    </item>
  </channel>
</rss>

