<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: QlikSense: SAML / FEDERATED SECURITY / SECURE TOKENS in Management &amp; Governance</title>
    <link>https://community.qlik.com/t5/Management-Governance/QlikSense-SAML-FEDERATED-SECURITY-SECURE-TOKENS/m-p/899848#M4163</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The problem appears with the userID field. All users in my user directory have as user id the name without the domain suffix. When I access through the virtual ADFS proxy with the userID@domainsuffix will not recognize it and tell me that I haven´t&amp;nbsp; access. In fact, automatically it generates a new user with the username @ domain suffix and adds it to the user list of Qlik. If I allocate the access to this new user, authentication works through the virtual proxy of ADFS, but consuming two licenses for the same user.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;In short, is it possible that my users have the user id @ domain suffix format to avoid this problem? What am I doing wrong?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Mon, 07 Mar 2016 14:58:06 GMT</pubDate>
    <dc:creator>javier_quintela</dc:creator>
    <dc:date>2016-03-07T14:58:06Z</dc:date>
    <item>
      <title>QlikSense: SAML / FEDERATED SECURITY / SECURE TOKENS</title>
      <link>https://community.qlik.com/t5/Management-Governance/QlikSense-SAML-FEDERATED-SECURITY-SECURE-TOKENS/m-p/899836#M4151</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;In White paper for QlikView:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;SAML / FEDERATED SECURITY / SECURE TOKENS There are a number of different security systems that can make use of secure tokens to sign users into a range of systems. There are several different standards and sets of terminology around this approach such as SAML (Security Assertion Markup Language) and federated security such Active Directory Federation Services. Although each is different the approach from a QlikView perspective is similar. Here is how it typically works… In this approach, due to the level of integration required, a custom login page can be created to use the security API in QlikView. Although this mechanism is relatively simple to use it does require some knowledge of programming and this configuration is not ‘out of the box’. There are examples on how to implement this approach available on the QlikView Community. 3 The advantage of this approach is again to conform to an organization’s standard way for securing services. It again does require that an organization has in place a security system that offers this kind of functionality but QlikView has an approach for integrating with a range of vendors’ solutions. QlikView Server 8. User received QlikView content CLOUD 1. User requests QlikView content Custom Login Page 2. User redirected to Login System 5. Request QlikView content with token 4. Redirect user to QlikView with token 3. Login Against Login System 6. Validate token Login System CUSTOMER SITE/INTERNET 7. Token is OK and provide username/groups QlikView and the Cloud | 13 With Active Directory Federation Services (ADFS) it is possible for users to seamlessly log in to a non-domain cloud server without being prompted to log in as their internal Windows credentials are used during the process of logging in. This gives an excellent user experience and ADFS is often implemented within organizations alongside their regular Active Directory which means there is no requirement for an additional SSO product or set of users.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Has anyone seen this for QlikSense?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 02 Jun 2015 19:18:03 GMT</pubDate>
      <guid>https://community.qlik.com/t5/Management-Governance/QlikSense-SAML-FEDERATED-SECURITY-SECURE-TOKENS/m-p/899836#M4151</guid>
      <dc:creator />
      <dc:date>2015-06-02T19:18:03Z</dc:date>
    </item>
    <item>
      <title>Re: QlikSense: SAML / FEDERATED SECURITY / SECURE TOKENS</title>
      <link>https://community.qlik.com/t5/Management-Governance/QlikSense-SAML-FEDERATED-SECURITY-SECURE-TOKENS/m-p/899837#M4152</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;If you are looking for how you can set up Qlik Sense SAML with ADFS, here are some videos I created that go through the process of configuring and implementing Sense SAML with ADFS.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A href="https://drive.google.com/folderview?id=0BxBEVQthCb29fjE0VmlHM2VxMVJtNnM5VFctMGNqa2JaMHJjWnh5bFRacThFMWJSS2FVems&amp;amp;usp=sharing" title="https://drive.google.com/folderview?id=0BxBEVQthCb29fjE0VmlHM2VxMVJtNnM5VFctMGNqa2JaMHJjWnh5bFRacThFMWJSS2FVems&amp;amp;usp=sharing"&gt;ADFS_SAML&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If you are interested in implementing security with Qlik Sense in a similar way to the way it is possible in QlikView, check out this video on the proxy API.&amp;nbsp; You can use ticketing if you want.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A href="https://drive.google.com/file/d/0BxBEVQthCb29cFVKemdFY0hNcXM/view?usp=sharing" title="https://drive.google.com/file/d/0BxBEVQthCb29cFVKemdFY0hNcXM/view?usp=sharing"&gt;QPS.mp4 - Google Drive&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hope this helps.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Jeff G&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 05 Aug 2015 22:22:17 GMT</pubDate>
      <guid>https://community.qlik.com/t5/Management-Governance/QlikSense-SAML-FEDERATED-SECURITY-SECURE-TOKENS/m-p/899837#M4152</guid>
      <dc:creator />
      <dc:date>2015-08-05T22:22:17Z</dc:date>
    </item>
    <item>
      <title>Re: QlikSense: SAML / FEDERATED SECURITY / SECURE TOKENS</title>
      <link>https://community.qlik.com/t5/Management-Governance/QlikSense-SAML-FEDERATED-SECURITY-SECURE-TOKENS/m-p/899838#M4153</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Jeff,&lt;/P&gt;&lt;P&gt;Thank you so much for the videos on SAML with adfs.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I built a prototype based on the videos and it is working well. I'm curious if you could describe any trouble spots when doing this on an existing adfs deployment. I'm sure there is a wide variety of deployment scenarios with this but just describe some common issues.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;It occurs to me that your videos use the certificates from the Qlik Sense server. In the case of an existing ADFS deployment do I have to use certificates from the ADFS server on Qlik?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks for whatever insight you can provide&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks Chris &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 10 Sep 2015 13:36:28 GMT</pubDate>
      <guid>https://community.qlik.com/t5/Management-Governance/QlikSense-SAML-FEDERATED-SECURITY-SECURE-TOKENS/m-p/899838#M4153</guid>
      <dc:creator>chriscammers</dc:creator>
      <dc:date>2015-09-10T13:36:28Z</dc:date>
    </item>
    <item>
      <title>Re: QlikSense: SAML / FEDERATED SECURITY / SECURE TOKENS</title>
      <link>https://community.qlik.com/t5/Management-Governance/QlikSense-SAML-FEDERATED-SECURITY-SECURE-TOKENS/m-p/899839#M4154</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Chris,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt; line-height: 1.5em;"&gt;I'm a big proponent of using certs from trusted authorities.&amp;nbsp; If you have a cert on ADFS, you may have to issue another for the Qlik server, but then the virtual proxy for SAML is using the updated server cert.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt; line-height: 1.5em;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt; line-height: 1.5em;"&gt;So short answer is you can use either, but if you want to use the certs you have for ADFS that are trusted (not self-signed) you can likely make a go of it.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt; line-height: 1.5em;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt; line-height: 1.5em;"&gt;jg&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 10 Sep 2015 15:41:10 GMT</pubDate>
      <guid>https://community.qlik.com/t5/Management-Governance/QlikSense-SAML-FEDERATED-SECURITY-SECURE-TOKENS/m-p/899839#M4154</guid>
      <dc:creator />
      <dc:date>2015-09-10T15:41:10Z</dc:date>
    </item>
    <item>
      <title>Re: QlikSense: SAML / FEDERATED SECURITY / SECURE TOKENS</title>
      <link>https://community.qlik.com/t5/Management-Governance/QlikSense-SAML-FEDERATED-SECURITY-SECURE-TOKENS/m-p/899840#M4155</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Jeff,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I am now at a client impelmenting ADFS with SAML on Qlik Sense and everything is looking good but I am getting 400 errors from sense.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;As I said in my earlier post the ADFS environment is fairly mature all I can tell right now is that the virtual proxy does not like the saml request from the adfs server. I'm curious which of the final power shell tasks were specifically needed to make Sense work as opposed to the ones you were doing to avoid errors with the self signed certs?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;One more thing in the Qlik Proxy security audit log I am seeing the following error&lt;/P&gt;&lt;P&gt;Command=Authenticate request;Result=-2147467259;ResultText=Error: The I/O operation has been aborted because of either a thread exit or an application request&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 24 Sep 2015 19:23:18 GMT</pubDate>
      <guid>https://community.qlik.com/t5/Management-Governance/QlikSense-SAML-FEDERATED-SECURITY-SECURE-TOKENS/m-p/899840#M4155</guid>
      <dc:creator>chriscammers</dc:creator>
      <dc:date>2015-09-24T19:23:18Z</dc:date>
    </item>
    <item>
      <title>Re: QlikSense: SAML / FEDERATED SECURITY / SECURE TOKENS</title>
      <link>https://community.qlik.com/t5/Management-Governance/QlikSense-SAML-FEDERATED-SECURITY-SECURE-TOKENS/m-p/899841#M4156</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;just came across this post as i am looking to do ADFS and this has been great information. I was just wondering, what options would be needed to remove the need for the users to enter their username and password? So its streamless once they access the url for the hub&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 05 Nov 2015 14:31:40 GMT</pubDate>
      <guid>https://community.qlik.com/t5/Management-Governance/QlikSense-SAML-FEDERATED-SECURITY-SECURE-TOKENS/m-p/899841#M4156</guid>
      <dc:creator />
      <dc:date>2015-11-05T14:31:40Z</dc:date>
    </item>
    <item>
      <title>Re: QlikSense: SAML / FEDERATED SECURITY / SECURE TOKENS</title>
      <link>https://community.qlik.com/t5/Management-Governance/QlikSense-SAML-FEDERATED-SECURITY-SECURE-TOKENS/m-p/899842#M4157</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Jessey,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Are you talking about replacing windows authentication popup when entering Qlik Sense?&amp;nbsp; If not, how do you envision users authenticating (identity verification) before forwarding on to Qlik Sense.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;There are lots of ways to make the auth process seamless, but at some point a user credential needs to be passed to Qlik Sense to identify the user who will access the solution.&amp;nbsp; That can happen in code, but requires the credential to come from somewhere.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;jg&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 05 Nov 2015 15:27:58 GMT</pubDate>
      <guid>https://community.qlik.com/t5/Management-Governance/QlikSense-SAML-FEDERATED-SECURITY-SECURE-TOKENS/m-p/899842#M4157</guid>
      <dc:creator />
      <dc:date>2015-11-05T15:27:58Z</dc:date>
    </item>
    <item>
      <title>Re: QlikSense: SAML / FEDERATED SECURITY / SECURE TOKENS</title>
      <link>https://community.qlik.com/t5/Management-Governance/QlikSense-SAML-FEDERATED-SECURITY-SECURE-TOKENS/m-p/899843#M4158</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Jeff,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P style="font-size: 13px; font-family: 'Helvetica Neue', Helvetica, Arial, 'Lucida Grande', sans-serif; color: #3d3d3d;"&gt;I am now at a client implementing ADFS with SAML on Qlik Sense and everything is looking good but I am getting 400 errors from sense. &lt;SPAN style="line-height: 1.5em;"&gt;My ADFS environment is fairly mature all I can tell right now is that the virtual proxy does not like the saml request from the adfs server. I use the certificates of the ADFS enviroment to sign and decrypt, not the certificate of my QlikSense site.&lt;/SPAN&gt;&lt;/P&gt;&lt;P style="font-size: 13px; font-family: 'Helvetica Neue', Helvetica, Arial, 'Lucida Grande', sans-serif; color: #3d3d3d;"&gt;&lt;/P&gt;&lt;P style="font-size: 13px; font-family: 'Helvetica Neue', Helvetica, Arial, 'Lucida Grande', sans-serif; color: #3d3d3d;"&gt;Here is my virtual proxy configuration:&lt;/P&gt;&lt;P style="font-size: 13px; font-family: 'Helvetica Neue', Helvetica, Arial, 'Lucida Grande', sans-serif; color: #3d3d3d;"&gt;&lt;IMG alt="sshot-1.jpg" class="jive-image image-1" src="https://community.qlik.com/legacyfs/online/116112_sshot-1.jpg" style="height: 573px; width: 620px;" /&gt;&lt;/P&gt;&lt;P style="font-size: 13px; font-family: 'Helvetica Neue', Helvetica, Arial, 'Lucida Grande', sans-serif; color: #3d3d3d;"&gt;Can you help me?&lt;/P&gt;&lt;P style="font-size: 13px; font-family: 'Helvetica Neue', Helvetica, Arial, 'Lucida Grande', sans-serif; color: #3d3d3d;"&gt;&lt;/P&gt;&lt;P style="font-size: 13px; font-family: 'Helvetica Neue', Helvetica, Arial, 'Lucida Grande', sans-serif; color: #3d3d3d;"&gt;Thanks.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 26 Feb 2016 10:00:17 GMT</pubDate>
      <guid>https://community.qlik.com/t5/Management-Governance/QlikSense-SAML-FEDERATED-SECURITY-SECURE-TOKENS/m-p/899843#M4158</guid>
      <dc:creator>javier_quintela</dc:creator>
      <dc:date>2016-02-26T10:00:17Z</dc:date>
    </item>
    <item>
      <title>Re: QlikSense: SAML / FEDERATED SECURITY / SECURE TOKENS</title>
      <link>https://community.qlik.com/t5/Management-Governance/QlikSense-SAML-FEDERATED-SECURITY-SECURE-TOKENS/m-p/899844#M4159</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P style="font-size: 13px; font-family: 'Helvetica Neue', Helvetica, Arial, 'Lucida Grande', sans-serif; color: #3d3d3d;"&gt;Jeff,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P style="font-size: 13px; font-family: 'Helvetica Neue', Helvetica, Arial, 'Lucida Grande', sans-serif; color: #3d3d3d;"&gt;I am now at a client implementing ADFS with SAML on Qlik Sense and everything is looking good but I am getting 400 errors from sense. &lt;SPAN style="font-weight: inherit; font-style: inherit; font-family: inherit;"&gt;My ADFS environment is fairly mature all I can tell right now is that the virtual proxy does not like the saml request from the adfs server. I use the certificates of the ADFS enviroment to sign and decrypt, not the certificate of my QlikSense site.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P style="font-size: 13px; font-family: 'Helvetica Neue', Helvetica, Arial, 'Lucida Grande', sans-serif; color: #3d3d3d;"&gt;Here is my virtual proxy configuration:&lt;/P&gt;&lt;P style="font-size: 13px; font-family: 'Helvetica Neue', Helvetica, Arial, 'Lucida Grande', sans-serif; color: #3d3d3d;"&gt;&lt;A _jive_internal="true" href="https://community.qlik.com/servlet/JiveServlet/showImage/2-983868-116112/sshot-1.jpg" style="font-weight: inherit; font-style: inherit; font-family: inherit; color: #3778c7;"&gt;&lt;IMG alt="sshot-1.jpg" class="jive-image image-1" height="765" src="https://community.qlik.com/legacyfs/online/116267_sshot-1.jpg" style="border: 0px; font-weight: inherit; font-style: inherit; font-family: inherit;" width="828" /&gt;&lt;/A&gt;&lt;/P&gt;&lt;P style="font-size: 13px; font-family: 'Helvetica Neue', Helvetica, Arial, 'Lucida Grande', sans-serif; color: #3d3d3d;"&gt;Can you help me?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P style="font-size: 13px; font-family: 'Helvetica Neue', Helvetica, Arial, 'Lucida Grande', sans-serif; color: #3d3d3d;"&gt;Thanks.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 29 Feb 2016 09:24:26 GMT</pubDate>
      <guid>https://community.qlik.com/t5/Management-Governance/QlikSense-SAML-FEDERATED-SECURITY-SECURE-TOKENS/m-p/899844#M4159</guid>
      <dc:creator>javier_quintela</dc:creator>
      <dc:date>2016-02-29T09:24:26Z</dc:date>
    </item>
    <item>
      <title>Re: QlikSense: SAML / FEDERATED SECURITY / SECURE TOKENS</title>
      <link>https://community.qlik.com/t5/Management-Governance/QlikSense-SAML-FEDERATED-SECURITY-SECURE-TOKENS/m-p/899845#M4160</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;If you are running into 400 errors it's likely 1 of 3 things.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;1. The roledescriptor elements have not been removed from the federation metadata file before uploading to Qlik Sense.&lt;/P&gt;&lt;P&gt;2. Because you are using lower than Qlik Sense 2.0.7 or 2.2 and endpoint is set to use SHA256 signing encryption it's failing.&lt;/P&gt;&lt;P&gt;3. You are attempting Identity Provider initiated flow instead of service provider initiated flow.&amp;nbsp; Qlik sense supports SP initiated flow only.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;jg&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 03 Mar 2016 12:40:12 GMT</pubDate>
      <guid>https://community.qlik.com/t5/Management-Governance/QlikSense-SAML-FEDERATED-SECURITY-SECURE-TOKENS/m-p/899845#M4160</guid>
      <dc:creator />
      <dc:date>2016-03-03T12:40:12Z</dc:date>
    </item>
    <item>
      <title>Re: QlikSense: SAML / FEDERATED SECURITY / SECURE TOKENS</title>
      <link>https://community.qlik.com/t5/Management-Governance/QlikSense-SAML-FEDERATED-SECURITY-SECURE-TOKENS/m-p/899846#M4161</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thank you very much Jeff, it was a version problem as well you said. I upgraded to version 2.2.3.0 and 400 errors no longer appear!!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt; line-height: 1.5em;"&gt;Now, the problem is that when accessing the URL through Virtual Proxy of ADFS and enter credentials, I am redirected to the hub URL but it tells me:&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt; line-height: 1.5em;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt; line-height: 1.5em;"&gt;"You can not access Qlik Sense because you has not access permission"&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt; line-height: 1.5em;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt; line-height: 1.5em;"&gt;Proxy Logs say this: Access to app '__hub' denied, result code 'NoAvailableAccessType'&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt; line-height: 1.5em;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt; line-height: 1.5em;"&gt;However, if I access to the url of the hub without going through Virtual Proxy of ADFS I access correctly.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt; line-height: 1.5em;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt; line-height: 1.5em;"&gt;Any ideas?&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt; line-height: 1.5em;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt; line-height: 1.5em;"&gt;Thanks&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 04 Mar 2016 07:19:20 GMT</pubDate>
      <guid>https://community.qlik.com/t5/Management-Governance/QlikSense-SAML-FEDERATED-SECURITY-SECURE-TOKENS/m-p/899846#M4161</guid>
      <dc:creator>javier_quintela</dc:creator>
      <dc:date>2016-03-04T07:19:20Z</dc:date>
    </item>
    <item>
      <title>Re: QlikSense: SAML / FEDERATED SECURITY / SECURE TOKENS</title>
      <link>https://community.qlik.com/t5/Management-Governance/QlikSense-SAML-FEDERATED-SECURITY-SECURE-TOKENS/m-p/899847#M4162</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;‌hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;now your issue is you haven't provisioned a token for the user logging in to have access.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;check out the license and tokens video in this series here:&lt;/P&gt;&lt;P&gt;&lt;A href="https://m.youtube.com/playlist?list=PLW1uf5CQ_gSpUIEWu0-0TzzEaNVQo346i" title="https://m.youtube.com/playlist?list=PLW1uf5CQ_gSpUIEWu0-0TzzEaNVQo346i"&gt;https://m.youtube.com/playlist?list=PLW1uf5CQ_gSpUIEWu0-0TzzEaNVQo346i&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Cheers,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;jeff g&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 04 Mar 2016 12:00:46 GMT</pubDate>
      <guid>https://community.qlik.com/t5/Management-Governance/QlikSense-SAML-FEDERATED-SECURITY-SECURE-TOKENS/m-p/899847#M4162</guid>
      <dc:creator />
      <dc:date>2016-03-04T12:00:46Z</dc:date>
    </item>
    <item>
      <title>Re: QlikSense: SAML / FEDERATED SECURITY / SECURE TOKENS</title>
      <link>https://community.qlik.com/t5/Management-Governance/QlikSense-SAML-FEDERATED-SECURITY-SECURE-TOKENS/m-p/899848#M4163</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The problem appears with the userID field. All users in my user directory have as user id the name without the domain suffix. When I access through the virtual ADFS proxy with the userID@domainsuffix will not recognize it and tell me that I haven´t&amp;nbsp; access. In fact, automatically it generates a new user with the username @ domain suffix and adds it to the user list of Qlik. If I allocate the access to this new user, authentication works through the virtual proxy of ADFS, but consuming two licenses for the same user.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;In short, is it possible that my users have the user id @ domain suffix format to avoid this problem? What am I doing wrong?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 07 Mar 2016 14:58:06 GMT</pubDate>
      <guid>https://community.qlik.com/t5/Management-Governance/QlikSense-SAML-FEDERATED-SECURITY-SECURE-TOKENS/m-p/899848#M4163</guid>
      <dc:creator>javier_quintela</dc:creator>
      <dc:date>2016-03-07T14:58:06Z</dc:date>
    </item>
    <item>
      <title>Re: QlikSense: SAML / FEDERATED SECURITY / SECURE TOKENS</title>
      <link>https://community.qlik.com/t5/Management-Governance/QlikSense-SAML-FEDERATED-SECURITY-SECURE-TOKENS/m-p/899849#M4164</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN lang="en"&gt;I know what the problem was: My SAML attribute for User ID was not upn, windows account name was!!!&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN lang="en"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN lang="en"&gt;Regards&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 23 Mar 2016 11:36:03 GMT</pubDate>
      <guid>https://community.qlik.com/t5/Management-Governance/QlikSense-SAML-FEDERATED-SECURITY-SECURE-TOKENS/m-p/899849#M4164</guid>
      <dc:creator>javier_quintela</dc:creator>
      <dc:date>2016-03-23T11:36:03Z</dc:date>
    </item>
  </channel>
</rss>

