<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Changing IdP Autentication - Qlik Sense SaaS in Management &amp; Governance</title>
    <link>https://community.qlik.com/t5/Management-Governance/Changing-IdP-Autentication-Qlik-Sense-SaaS/m-p/2425803#M30046</link>
    <description>&lt;P&gt;Thanks Levi for the detailed breakdown and explanation.&amp;nbsp; This has been really useful.&amp;nbsp; Thanks, Rob&lt;/P&gt;</description>
    <pubDate>Fri, 01 Mar 2024 10:28:14 GMT</pubDate>
    <dc:creator>rob_insley</dc:creator>
    <dc:date>2024-03-01T10:28:14Z</dc:date>
    <item>
      <title>Changing IdP Autentication - Qlik Sense SaaS</title>
      <link>https://community.qlik.com/t5/Management-Governance/Changing-IdP-Autentication-Qlik-Sense-SaaS/m-p/2425227#M30044</link>
      <description>&lt;P&gt;My client wishes to change their current IdP Authentication in Qlik Sense SaaS.&amp;nbsp; &amp;nbsp;Current they login using their Network login but this is going to be changed to use an email address.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;EMail Address is a an existing Claim attribute so I am trying to understand what the process will be to change the iDP Authentication&amp;nbsp; and a whether existing users will somehow get automatically mapped when the new IdP is configured.&amp;nbsp; Having a single tenancy means we do not have a Qlik Sense SaaS Environment to try out the change so that we can fully identify the potential impacts.&lt;/P&gt;
&lt;P&gt;I understand it will be a 2 step process-&lt;/P&gt;
&lt;P&gt;Step 1 . Revert to Qlik Account Authentication and ensure we have the recovery account to be able to re-login.&lt;/P&gt;
&lt;P&gt;Step 2. Configure the new IdP Authentication&lt;/P&gt;
&lt;P&gt;So after configuring and&amp;nbsp; establishing the new iDP Authentication we need to understand the impact to understand if we will need to re-establish all Spaces permissions to the new users or whether the new users will inherit the existing permissions by automated mapping via email?&lt;/P&gt;
&lt;P&gt;HAs anyone done something similar?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 29 Feb 2024 10:34:45 GMT</pubDate>
      <guid>https://community.qlik.com/t5/Management-Governance/Changing-IdP-Autentication-Qlik-Sense-SaaS/m-p/2425227#M30044</guid>
      <dc:creator>rob_insley</dc:creator>
      <dc:date>2024-02-29T10:34:45Z</dc:date>
    </item>
    <item>
      <title>Re: Changing IdP Autentication - Qlik Sense SaaS</title>
      <link>https://community.qlik.com/t5/Management-Governance/Changing-IdP-Autentication-Qlik-Sense-SaaS/m-p/2425379#M30045</link>
      <description>&lt;P&gt;Let's start out with how a user is identified in Qlik Cloud. Let's take this user's record:&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-center" image-alt="Levi_Turner_0-1709216784120.png" style="width: 999px;"&gt;&lt;img src="https://community.qlik.com/t5/image/serverpage/image-id/160985i80F5D3686A9E30A8/image-size/large?v=v2&amp;amp;px=999" role="button" title="Levi_Turner_0-1709216784120.png" alt="Levi_Turner_0-1709216784120.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;In tabular format, the user is:&lt;/P&gt;
&lt;TABLE border="1" width="97.78357235984356%"&gt;
&lt;TBODY&gt;
&lt;TR&gt;
&lt;TD width="16.666666666666668%"&gt;User ID (created by Qlik)&lt;/TD&gt;
&lt;TD width="16.666666666666668%" height="25px"&gt;User Subject (from your IDP)&lt;/TD&gt;
&lt;TD width="33.333333333333336%" height="25px"&gt;User Email (from your IDP)&lt;/TD&gt;
&lt;TD width="33.333333333333336%" height="25px"&gt;User Name (from your IDP)&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD width="16.666666666666668%"&gt;65e093f29fac8999db04512e&lt;/TD&gt;
&lt;TD width="16.666666666666668%" height="25px"&gt;856bcab5-64db-4aa1-bce8-d90e98d322c2&lt;/TD&gt;
&lt;TD width="33.333333333333336%" height="25px"&gt;levi.turner@demo.dev&lt;/TD&gt;
&lt;TD width="33.333333333333336%" height="25px"&gt;Levi Turner&lt;/TD&gt;
&lt;/TR&gt;
&lt;/TBODY&gt;
&lt;/TABLE&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;User records in Qlik Cloud have dual primary keys:&amp;nbsp;&lt;STRONG&gt;subject&lt;/STRONG&gt; and&amp;nbsp;&lt;STRONG&gt;email&lt;/STRONG&gt;. This means, if your IDP changes the user's subject&amp;nbsp;&lt;STRONG&gt;or&lt;/STRONG&gt; the user's email, the user's Qlik Cloud identity will remain the same. If you change&amp;nbsp;&lt;STRONG&gt;both&lt;/STRONG&gt; the user's subject&amp;nbsp;&lt;STRONG&gt;and&lt;/STRONG&gt; email, Qlik Cloud will treat this as a new user. In my example user, I can change the email like so:&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-center" image-alt="Levi_Turner_1-1709217099300.png" style="width: 999px;"&gt;&lt;img src="https://community.qlik.com/t5/image/serverpage/image-id/160986i7DDEE7223014E26C/image-size/large?v=v2&amp;amp;px=999" role="button" title="Levi_Turner_1-1709217099300.png" alt="Levi_Turner_1-1709217099300.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;TABLE border="1" width="97.78357235984356%"&gt;
&lt;TBODY&gt;
&lt;TR&gt;
&lt;TD width="16.666666666666668%"&gt;User ID (created by Qlik)&lt;/TD&gt;
&lt;TD width="16.666666666666668%" height="25px"&gt;User Subject (from your IDP)&lt;/TD&gt;
&lt;TD width="33.333333333333336%" height="25px"&gt;User Email (from your IDP)&lt;/TD&gt;
&lt;TD width="33.333333333333336%" height="25px"&gt;User Name (from your IDP)&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD width="16.666666666666668%"&gt;65e093f29fac8999db04512e&lt;/TD&gt;
&lt;TD width="16.666666666666668%" height="25px"&gt;856bcab5-64db-4aa1-bce8-d90e98d322c2&lt;/TD&gt;
&lt;TD width="33.333333333333336%" height="25px"&gt;levi.turner2@demo.dev&lt;/TD&gt;
&lt;TD width="33.333333333333336%" height="25px"&gt;Levi Turner&lt;/TD&gt;
&lt;/TR&gt;
&lt;/TBODY&gt;
&lt;/TABLE&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Or I can change the subject like so:&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-center" image-alt="Levi_Turner_2-1709217177001.png" style="width: 999px;"&gt;&lt;img src="https://community.qlik.com/t5/image/serverpage/image-id/160987i4D5DF9DFE09270A3/image-size/large?v=v2&amp;amp;px=999" role="button" title="Levi_Turner_2-1709217177001.png" alt="Levi_Turner_2-1709217177001.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;TABLE border="1" width="97.78357235984356%"&gt;
&lt;TBODY&gt;
&lt;TR&gt;
&lt;TD width="16.666666666666668%"&gt;User ID (created by Qlik)&lt;/TD&gt;
&lt;TD width="16.666666666666668%" height="25px"&gt;User Subject (from your IDP)&lt;/TD&gt;
&lt;TD width="33.333333333333336%" height="25px"&gt;User Email (from your IDP)&lt;/TD&gt;
&lt;TD width="33.333333333333336%" height="25px"&gt;User Name (from your IDP)&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD width="16.666666666666668%"&gt;65e093f29fac8999db04512e&lt;/TD&gt;
&lt;TD width="16.666666666666668%" height="25px"&gt;BrandNewSubject&lt;/TD&gt;
&lt;TD width="33.333333333333336%" height="25px"&gt;levi.turner2@demo.dev&lt;/TD&gt;
&lt;TD width="33.333333333333336%" height="25px"&gt;Levi Turner&lt;/TD&gt;
&lt;/TR&gt;
&lt;/TBODY&gt;
&lt;/TABLE&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;If I change&amp;nbsp;&lt;STRONG&gt;both&lt;/STRONG&gt;, then I will have a new user:&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-center" image-alt="Levi_Turner_3-1709217921933.png" style="width: 999px;"&gt;&lt;img src="https://community.qlik.com/t5/image/serverpage/image-id/160990iA508FF5A2313BB60/image-size/large?v=v2&amp;amp;px=999" role="button" title="Levi_Turner_3-1709217921933.png" alt="Levi_Turner_3-1709217921933.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;TABLE border="1" width="97.78357235984356%"&gt;
&lt;TBODY&gt;
&lt;TR&gt;
&lt;TD width="16.666666666666668%" height="47px"&gt;User ID (created by Qlik)&lt;/TD&gt;
&lt;TD width="16.666666666666668%" height="47px"&gt;User Subject (from your IDP)&lt;/TD&gt;
&lt;TD width="33.333333333333336%" height="47px"&gt;User Email (from your IDP)&lt;/TD&gt;
&lt;TD width="33.333333333333336%" height="47px"&gt;User Name (from your IDP)&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD width="16.666666666666668%" height="25px"&gt;65e093f29fac8999db04512e&lt;/TD&gt;
&lt;TD width="16.666666666666668%" height="25px"&gt;BrandNewSubject&lt;/TD&gt;
&lt;TD width="33.333333333333336%" height="25px"&gt;levi.turner2@demo.dev&lt;/TD&gt;
&lt;TD width="33.333333333333336%" height="25px"&gt;Levi Turner&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD height="25px"&gt;65e0984ad099feece9adaead&lt;/TD&gt;
&lt;TD height="25px"&gt;856bcab5-64db-4aa1-bce8-d90e98d322c1&lt;/TD&gt;
&lt;TD height="25px"&gt;levi.turner@demo.dev&lt;/TD&gt;
&lt;TD height="25px"&gt;Levi Turner&lt;/TD&gt;
&lt;/TR&gt;
&lt;/TBODY&gt;
&lt;/TABLE&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;So back to your questions:&lt;/P&gt;
&lt;P&gt;&amp;gt;&amp;nbsp;So after configuring and establishing the new iDP Authentication we need to understand the impact to understand if we will need to re-establish all Spaces permissions to the new users or whether the new users will inherit the existing permissions by automated mapping via email?&lt;/P&gt;
&lt;P&gt;After configuring and establishing the new IDP, you should ensure&amp;nbsp;&lt;STRONG&gt;either&lt;/STRONG&gt; the user's subject&amp;nbsp;&lt;STRONG&gt;or&lt;/STRONG&gt; email is the same. This will ensure that the user is considered the same to Qlik Cloud. From there,&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;any permissions set by user name will automatically inherit. Ownership of apps, automations, sheets, data connections will all work seamlessly&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;But access by name isn't the only way to provide access, groups can be used.&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;any permissions set by&amp;nbsp;&lt;EM&gt;groups&lt;/EM&gt; will automatically inherit assuming that the new IDP also sends the same groups. If the old IDP sent 3 groups and the new IDP sends the same 3 groups, this will work. If the groups change names or aren't being sent, then this access will break&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;In this space:&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-center" image-alt="Levi_Turner_4-1709218214910.png" style="width: 999px;"&gt;&lt;img src="https://community.qlik.com/t5/image/serverpage/image-id/160991i29CEC0622CBC1F35/image-size/large?v=v2&amp;amp;px=999" role="button" title="Levi_Turner_4-1709218214910.png" alt="Levi_Turner_4-1709218214910.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;If I continue to send the group "Domain Admins", then an IDP change on Qlik Cloud will not be problematic. If the new IDP doesn't send "Domain Admins", then I would need either grant access to the space via the new group or by user name.&lt;/P&gt;</description>
      <pubDate>Thu, 29 Feb 2024 14:52:54 GMT</pubDate>
      <guid>https://community.qlik.com/t5/Management-Governance/Changing-IdP-Autentication-Qlik-Sense-SaaS/m-p/2425379#M30045</guid>
      <dc:creator>Levi_Turner</dc:creator>
      <dc:date>2024-02-29T14:52:54Z</dc:date>
    </item>
    <item>
      <title>Re: Changing IdP Autentication - Qlik Sense SaaS</title>
      <link>https://community.qlik.com/t5/Management-Governance/Changing-IdP-Autentication-Qlik-Sense-SaaS/m-p/2425803#M30046</link>
      <description>&lt;P&gt;Thanks Levi for the detailed breakdown and explanation.&amp;nbsp; This has been really useful.&amp;nbsp; Thanks, Rob&lt;/P&gt;</description>
      <pubDate>Fri, 01 Mar 2024 10:28:14 GMT</pubDate>
      <guid>https://community.qlik.com/t5/Management-Governance/Changing-IdP-Autentication-Qlik-Sense-SaaS/m-p/2425803#M30046</guid>
      <dc:creator>rob_insley</dc:creator>
      <dc:date>2024-03-01T10:28:14Z</dc:date>
    </item>
  </channel>
</rss>

