<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: SAML attribute in section access in Management &amp; Governance</title>
    <link>https://community.qlik.com/t5/Management-Governance/SAML-attribute-in-section-access/m-p/1996638#M31469</link>
    <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.qlik.com/t5/user/viewprofilepage/user-id/188507"&gt;@fjuken&lt;/a&gt;&amp;nbsp;can you try with the "SAML attribute" set to groups NOT group&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Tue, 25 Oct 2022 13:52:25 GMT</pubDate>
    <dc:creator>Eugene_Sleator</dc:creator>
    <dc:date>2022-10-25T13:52:25Z</dc:date>
    <item>
      <title>SAML attribute in section access</title>
      <link>https://community.qlik.com/t5/Management-Governance/SAML-attribute-in-section-access/m-p/1952495#M31466</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;
&lt;P&gt;Configured Integration from Qlik Sense onPrem towards Azure AD.&lt;BR /&gt;Access to QMC and Hub works fine using security rules , but when I access a app i get 'access denied'.&lt;BR /&gt;Based on documentation it should be possible to reUse the SAML 'group' attribute in access script, right?&lt;/P&gt;
&lt;P&gt;Please advice!&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="fjuken_0-1657129415888.png" style="width: 400px;"&gt;&lt;img src="https://community.qlik.com/t5/image/serverpage/image-id/83462i76C2D7C6833E0425/image-size/medium?v=v2&amp;amp;px=400" role="button" title="fjuken_0-1657129415888.png" alt="fjuken_0-1657129415888.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="fjuken_1-1657129522061.png" style="width: 400px;"&gt;&lt;img src="https://community.qlik.com/t5/image/serverpage/image-id/83463i1E9369168966E507/image-size/medium?v=v2&amp;amp;px=400" role="button" title="fjuken_1-1657129522061.png" alt="fjuken_1-1657129522061.png" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 29 Jan 2025 16:38:32 GMT</pubDate>
      <guid>https://community.qlik.com/t5/Management-Governance/SAML-attribute-in-section-access/m-p/1952495#M31466</guid>
      <dc:creator>fjuken</dc:creator>
      <dc:date>2025-01-29T16:38:32Z</dc:date>
    </item>
    <item>
      <title>Re: SAML attribute in section access</title>
      <link>https://community.qlik.com/t5/Management-Governance/SAML-attribute-in-section-access/m-p/1986954#M31467</link>
      <description>&lt;P&gt;HI &lt;a href="https://community.qlik.com/t5/user/viewprofilepage/user-id/188507"&gt;@fjuken&lt;/a&gt; in order for this to work you need to include the Group attribute in the Virtual Proxy. Please refer to these Qlik articles for an explanation;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://support.qlik.com/articles/000084086" target="_self"&gt;Qlik Sense: Section Access not working with SAML attributes&lt;/A&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://community.qlik.com/t5/Design/User-Environment-What-Session-Attributes-in-Qlik-Sense/ba-p/1476590" target="_self"&gt;User-Environment-What-Session-Attributes-in-Qlik-Sense&lt;/A&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://community.qlik.com/t5/App-Development/Section-Access-User-Attributes/td-p/1268286" target="_self"&gt;Section-Access-User-Attributes&lt;/A&gt;&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;Hope this helps&lt;BR /&gt;&lt;BR /&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 25 Oct 2022 13:52:58 GMT</pubDate>
      <guid>https://community.qlik.com/t5/Management-Governance/SAML-attribute-in-section-access/m-p/1986954#M31467</guid>
      <dc:creator>Eugene_Sleator</dc:creator>
      <dc:date>2022-10-25T13:52:58Z</dc:date>
    </item>
    <item>
      <title>Re: SAML attribute in section access</title>
      <link>https://community.qlik.com/t5/Management-Governance/SAML-attribute-in-section-access/m-p/1987134#M31468</link>
      <description>&lt;P&gt;Thanks for reply,&amp;nbsp;&lt;a href="https://community.qlik.com/t5/user/viewprofilepage/user-id/134172"&gt;@Eugene_Sleator&lt;/a&gt;&amp;nbsp;!&lt;/P&gt;
&lt;P&gt;We've configured following on the virtual Proxy (we're sending group objects from AzureAD as attribute 'group')&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="fjuken_0-1664458142133.png" style="width: 400px;"&gt;&lt;img src="https://community.qlik.com/t5/image/serverpage/image-id/90230i042FE3F11DADCAB8/image-size/medium?v=v2&amp;amp;px=400" role="button" title="fjuken_0-1664458142133.png" alt="fjuken_0-1664458142133.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;Using this proxy for access to QMC and HUB works as expected, but when we try to access apps we get 'Access Denied'&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="fjuken_1-1664458326382.png" style="width: 400px;"&gt;&lt;img src="https://community.qlik.com/t5/image/serverpage/image-id/90231i92851809439DE237/image-size/medium?v=v2&amp;amp;px=400" role="button" title="fjuken_1-1664458326382.png" alt="fjuken_1-1664458326382.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;We tried different combinations of adding this to the access script, as you see an example of in the post, both linking to group attribute and the username of the SAML authenticated user ++ but we're not able to get access to the app using SAML authentication..&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Br,&lt;/P&gt;
&lt;P&gt;Håvard Fjukstad.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 29 Sep 2022 13:37:35 GMT</pubDate>
      <guid>https://community.qlik.com/t5/Management-Governance/SAML-attribute-in-section-access/m-p/1987134#M31468</guid>
      <dc:creator>fjuken</dc:creator>
      <dc:date>2022-09-29T13:37:35Z</dc:date>
    </item>
    <item>
      <title>Re: SAML attribute in section access</title>
      <link>https://community.qlik.com/t5/Management-Governance/SAML-attribute-in-section-access/m-p/1996638#M31469</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.qlik.com/t5/user/viewprofilepage/user-id/188507"&gt;@fjuken&lt;/a&gt;&amp;nbsp;can you try with the "SAML attribute" set to groups NOT group&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 25 Oct 2022 13:52:25 GMT</pubDate>
      <guid>https://community.qlik.com/t5/Management-Governance/SAML-attribute-in-section-access/m-p/1996638#M31469</guid>
      <dc:creator>Eugene_Sleator</dc:creator>
      <dc:date>2022-10-25T13:52:25Z</dc:date>
    </item>
    <item>
      <title>Re: SAML attribute in section access</title>
      <link>https://community.qlik.com/t5/Management-Governance/SAML-attribute-in-section-access/m-p/1998177#M31470</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.qlik.com/t5/user/viewprofilepage/user-id/134172"&gt;@Eugene_Sleator&lt;/a&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Seems like our issue is related to casing.&lt;BR /&gt;After adding this to the access script we managed to login and access app.&lt;/P&gt;
&lt;P&gt;_sa:&lt;BR /&gt;LOAD Upper(ACCESS) AS ACCESS,&lt;BR /&gt;Upper(USERID) AS USERID,&lt;BR /&gt;Upper(GROUP) AS GROUP,&lt;BR /&gt;Upper(%SAKEY) AS %SAKEY&lt;BR /&gt;Inline [&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;
&lt;P&gt;Br,&lt;BR /&gt;Håvard Fjukstad.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 28 Oct 2022 15:43:46 GMT</pubDate>
      <guid>https://community.qlik.com/t5/Management-Governance/SAML-attribute-in-section-access/m-p/1998177#M31470</guid>
      <dc:creator>fjuken</dc:creator>
      <dc:date>2022-10-28T15:43:46Z</dc:date>
    </item>
  </channel>
</rss>

