<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Configure User Directory to Azure LDAP in Management &amp; Governance</title>
    <link>https://community.qlik.com/t5/Management-Governance/Configure-User-Directory-to-Azure-LDAP/m-p/1190522#M7416</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P style="font-size: 13px; font-family: 'Helvetica Neue', Helvetica, Arial, 'Lucida Grande', sans-serif; color: #3d3d3d;"&gt;&lt;A class="jive-link-external-small" href="https://docs.microsoft.com/en-us/azure/active-directory/active-directory-saas-qliksense-enterprise-tutorial" rel="nofollow" style="font-weight: inherit; font-style: inherit; font-family: inherit; color: #3778c7;" target="_blank"&gt;Tutorial: Azure Active Directory integration with Qlik Sense Enterprise | Microsoft Docs&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P style="font-size: 13px; font-family: 'Helvetica Neue', Helvetica, Arial, 'Lucida Grande', sans-serif; color: #3d3d3d;"&gt;It shall be better with this one. Slash were removed from the previous link I provided I don't know why&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Wed, 08 Feb 2017 15:08:55 GMT</pubDate>
    <dc:creator>joan_marty</dc:creator>
    <dc:date>2017-02-08T15:08:55Z</dc:date>
    <item>
      <title>Configure User Directory to Azure LDAP</title>
      <link>https://community.qlik.com/t5/Management-Governance/Configure-User-Directory-to-Azure-LDAP/m-p/1190518#M7412</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;We've set up Qlik Sense on a server, and are experimenting with trying to configure it to connect to Azure Active Directory. We followed all of the instructions in the Azure article "Configure Secure LDAP for an Azure AD Domain Services Managed Domain" (&lt;A href="https://azure.microsoft.com/en-us/documentation/articles/active-directory-ds-admin-guide-configure-secure-ldap/" title="https://azure.microsoft.com/en-us/documentation/articles/active-directory-ds-admin-guide-configure-secure-ldap/"&gt;Configure Secure LDAP (LDAPS) in Azure AD Domain Services | Microsoft Azure&lt;/A&gt;). We've got an AD setup on Azure, and we created a wildcard certificate with a Certificate Authority (GoDaddy). So with a domain for the company of 'example.com', the wildcard cert is '*.example.com'. We exported this certificate from the Qlik Sense server per the instructions in the Azure article, loaded it into the Domain Services configuration panel on Azure, and received an IP address for LDAPS. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;We then configured DNS A record so that the subdomain ('ldap.example.com') points to this IP address. When we run a scan on the IP and the DNS alias at MXtoolbox.com we get a valid scan showing the IP address is there, with only port 443 open (https).&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Now over to Sense:&amp;nbsp; in the QMC -&amp;gt; User Directory Connector, we can't manage to figure out how to connect to the LDAP server. Do we need to set up a virtual proxy to bind the certificate? &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Typical log entries:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;TABLE&gt;&lt;TBODY&gt;&lt;TR&gt;&lt;TD&gt;41&lt;/TD&gt;&lt;TD&gt;20160922T064554.973-0700&lt;/TD&gt;&lt;TD&gt;INFO&lt;/TD&gt;&lt;TD&gt;demoqlik&lt;/TD&gt;&lt;TD&gt;UserManagement.Repository.Repository.Users.Factories.UserDirectoryFactory&lt;/TD&gt;&lt;TD&gt;107&lt;/TD&gt;&lt;TD&gt;09c1532a-ef60-429b-a182-e9c6cc279af1&lt;/TD&gt;&lt;TD&gt;NT AUTHORITY\SYSTEM&lt;/TD&gt;&lt;TD&gt;Looking up RootDSE: LDAP://ldap.example.com:443/RootDSE&lt;/TD&gt;&lt;TD&gt;&lt;/TD&gt;&lt;TD&gt;&lt;/TD&gt;&lt;TD&gt;&lt;/TD&gt;&lt;TD&gt;09c1532a-ef60-429b-a182-e9c6cc279af1&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;42&lt;/TD&gt;&lt;TD&gt;20160922T064555.038-0700&lt;/TD&gt;&lt;TD&gt;ERROR&lt;/TD&gt;&lt;TD&gt;&lt;SPAN style="font-size: 13.3333px;"&gt;demoqlik&lt;/SPAN&gt;&lt;/TD&gt;&lt;TD&gt;UserManagement.Repository.Repository.Users.Factories.UserDirectoryFactory&lt;/TD&gt;&lt;TD&gt;107&lt;/TD&gt;&lt;TD&gt;c7e246ce-b5a1-411e-a895-6673bda08f91&lt;/TD&gt;&lt;TD&gt;NT AUTHORITY\SYSTEM&lt;/TD&gt;&lt;TD&gt;Fetching directoryentry LDAP://ldap.&lt;SPAN style="font-size: 13.3333px;"&gt;example.com&lt;/SPAN&gt;:443/RootDSE failed: The directory service is unavailable.↵↓&lt;/TD&gt;&lt;TD&gt;&lt;/TD&gt;&lt;TD&gt;&lt;/TD&gt;&lt;TD&gt;&lt;/TD&gt;&lt;TD&gt;c7e246ce-b5a1-411e-a895-6673bda08f91&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;43&lt;/TD&gt;&lt;TD&gt;20160922T064555.038-0700&lt;/TD&gt;&lt;TD&gt;ERROR&lt;/TD&gt;&lt;TD&gt;&lt;SPAN style="font-size: 13.3333px;"&gt;demoqlik&lt;/SPAN&gt;&lt;/TD&gt;&lt;TD&gt;UserManagement.Repository.Repository.Users.Factories.UserDirectoryFactory&lt;/TD&gt;&lt;TD&gt;107&lt;/TD&gt;&lt;TD&gt;ac0c1648-b9d9-4174-8020-8cc654beaf1d&lt;/TD&gt;&lt;TD&gt;NT AUTHORITY\SYSTEM&lt;/TD&gt;&lt;TD&gt;Exception while initializing ldap://ldap.&lt;SPAN style="font-size: 13.3333px;"&gt;example.com&lt;/SPAN&gt;:443: Setting up connection to LDAP root node failed. Check log file.&lt;/TD&gt;&lt;TD&gt;&lt;/TD&gt;&lt;TD&gt;&lt;/TD&gt;&lt;TD&gt;&lt;/TD&gt;&lt;TD&gt;ac0c1648-b9d9-4174-8020-8cc654beaf1d&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;44&lt;/TD&gt;&lt;TD&gt;20160922T064555.038-0700&lt;/TD&gt;&lt;TD&gt;WARN&lt;/TD&gt;&lt;TD&gt;&lt;SPAN style="font-size: 13.3333px;"&gt;demoqlik&lt;/SPAN&gt;&lt;/TD&gt;&lt;TD&gt;UserManagement.Repository.Repository.Users.Factories.UserDirectoryFactory&lt;/TD&gt;&lt;TD&gt;107&lt;/TD&gt;&lt;TD&gt;414351f5-62d9-4f41-bd8c-bffd56948887&lt;/TD&gt;&lt;TD&gt;NT AUTHORITY\SYSTEM&lt;/TD&gt;&lt;TD&gt;Setup of ActiveDirectory UDC not successful: Setting up connection to LDAP root node failed. Check log file.&lt;/TD&gt;&lt;TD&gt;&lt;/TD&gt;&lt;TD&gt;&lt;/TD&gt;&lt;TD&gt;&lt;/TD&gt;&lt;TD&gt;414351f5-62d9-4f41-bd8c-bffd56948887&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;45&lt;/TD&gt;&lt;TD&gt;20160922T064555.038-0700&lt;/TD&gt;&lt;TD&gt;WARN&lt;/TD&gt;&lt;TD&gt;&lt;SPAN style="font-size: 13.3333px;"&gt;demoqlik&lt;/SPAN&gt;&lt;/TD&gt;&lt;TD&gt;UserManagement.Repository.Repository.Users.Factories.UserDirectoryFactory&lt;/TD&gt;&lt;TD&gt;33&lt;/TD&gt;&lt;TD&gt;ffc751e2-16d6-4fb0-bd5d-dbf01404171c&lt;/TD&gt;&lt;TD&gt;NT AUTHORITY\SYSTEM&lt;/TD&gt;&lt;TD&gt;Setting up UDC of type Repository.UserDirectoryConnectors.LDAP.ActiveDirectory unsuccessful&lt;/TD&gt;&lt;TD&gt;Setting up connection to LDAP root node failed. Check log file.&lt;/TD&gt;&lt;TD&gt;↵↓Server stack trace: ↵↓&amp;nbsp;&amp;nbsp; at Repository.UserDirectoryConnectors.LDAP.LDAPRoot.FindEntry(String path, GenericLDAP ldap)↵↓&amp;nbsp;&amp;nbsp; at Repository.UserDirectoryConnectors.LDAP.ActiveDirectory.FindRoot()↵↓&amp;nbsp;&amp;nbsp; at Repository.UserDirectoryConnectors.LDAP.GenericLDAP.Setup(Logger logger)↵↓&amp;nbsp;&amp;nbsp; at System.Runtime.Remoting.Messaging.StackBuilderSink._PrivateProcessMessage(IntPtr md, Object[] args, Object server, Object[]&amp;amp; outArgs)↵↓&amp;nbsp;&amp;nbsp; at System.Runtime.Remoting.Messaging.StackBuilderSink.AsyncProcessMessage(IMessage msg, IMessageSink replySink)↵↓↵↓Exception rethrown at [0]: ↵↓&amp;nbsp;&amp;nbsp; at System.Runtime.Remoting.Proxies.RealProxy.EndInvokeHelper(Message reqMsg, Boolean bProxyCase)↵↓&amp;nbsp;&amp;nbsp; at System.Func`1.EndInvoke(IAsyncResult result)↵↓&amp;nbsp;&amp;nbsp; at Repository.Users.SafeUserDirectoryConnector.CallWithTimeout&lt;T&gt;(Func`1 func, TimeSpan timeout)↵↓&amp;nbsp;&amp;nbsp; at Repository.Users.SafeUserDirectoryConnector.Setup(Logger logger)↵↓&amp;nbsp;&amp;nbsp; at Repository.Users.Factories.UserDirectoryFactory.TrySetupUserDirectory(UserDirectory userDirectory)&lt;/T&gt;&lt;/TD&gt;&lt;TD&gt;&lt;/TD&gt;&lt;TD&gt;ffc751e2-16d6-4fb0-bd5d-dbf01404171c&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Confused, would appreciate any assistance or ideas. Thank you!&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 22 Sep 2016 15:27:05 GMT</pubDate>
      <guid>https://community.qlik.com/t5/Management-Governance/Configure-User-Directory-to-Azure-LDAP/m-p/1190518#M7412</guid>
      <dc:creator>azimuthbrett</dc:creator>
      <dc:date>2016-09-22T15:27:05Z</dc:date>
    </item>
    <item>
      <title>Re: Configure User Directory to Azure LDAP</title>
      <link>https://community.qlik.com/t5/Management-Governance/Configure-User-Directory-to-Azure-LDAP/m-p/1190519#M7413</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello Brett, I'm adding one of our experts &lt;A href="https://community.qlik.com/qlik-users/227715"&gt;ext_kea&lt;/A&gt;‌ Kate Healy to this thread so she can assist. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Best, Sara &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 22 Sep 2016 16:21:24 GMT</pubDate>
      <guid>https://community.qlik.com/t5/Management-Governance/Configure-User-Directory-to-Azure-LDAP/m-p/1190519#M7413</guid>
      <dc:creator>Anonymous</dc:creator>
      <dc:date>2016-09-22T16:21:24Z</dc:date>
    </item>
    <item>
      <title>Re: Configure User Directory to Azure LDAP</title>
      <link>https://community.qlik.com/t5/Management-Governance/Configure-User-Directory-to-Azure-LDAP/m-p/1190520#M7414</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi, I'm also running this kind of activity at the moment, trying to integrate AZURE AD with Qlik Sense to get SSO and other things linked to this.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I'm still in progress but I can already give you this link which shows how to delcare Qlik Sense Server in Azure&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-external-small" href="https://azure.microsoft.comen-usdocumentationarticlesactive-directory-saas-qliksense-enterprise-tutorial" rel="nofollow" target="_blank"&gt;https://azure.microsoft.comen-usdocumentationarticlesactive-directory-saas-qliksense-enterprise-tutorial&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Maybe it can help you a bit&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 23 Sep 2016 08:32:51 GMT</pubDate>
      <guid>https://community.qlik.com/t5/Management-Governance/Configure-User-Directory-to-Azure-LDAP/m-p/1190520#M7414</guid>
      <dc:creator>joan_marty</dc:creator>
      <dc:date>2016-09-23T08:32:51Z</dc:date>
    </item>
    <item>
      <title>Re: Configure User Directory to Azure LDAP</title>
      <link>https://community.qlik.com/t5/Management-Governance/Configure-User-Directory-to-Azure-LDAP/m-p/1190521#M7415</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks Joan. Looks like the URL you posted has some missing backslashes...I was getting an error page. For anyone else that attempts, this one should work:&lt;/P&gt;&lt;P&gt;&lt;A href="https://docs.microsoft.com/en-us/azure/active-directory/active-directory-saas-qliksense-enterprise-tutorial" title="https://docs.microsoft.com/en-us/azure/active-directory/active-directory-saas-qliksense-enterprise-tutorial"&gt;https://docs.microsoft.com/en-us/azure/active-directory/active-directory-saas-qliksense-enterprise-tutorial&lt;/A&gt;‌&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If it doesn't I found the doc by going to azure.microsoft.com and searching "Qlik Sense".&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;It's been several months since we attempted setting this up so I can't recall all of the details. I can say that we went through every step in that same tutorial. The problem (as I recall) is that it sets you up to access Sense from the Azure portal - i.e. users are logged into Azure and have a Sense app they can click on to get to the dashboards. Not what we wanted.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;What we wanted was to enable SSO. So a user with valid AD credentials managed via a cloud-based AD setup on Azure would provide their company credentials when logging into sense (e.g. on a company domain such as &lt;/SPAN&gt;&lt;A class="jive-link-external-small" href="https://dashboards.example.com" rel="nofollow" target="_blank"&gt;https://dashboards.example.com&lt;/A&gt;&lt;SPAN&gt;). We wanted Sense to be able to authenticate the user directly by reference to the remote AD. We were never able to figure it out.&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 08 Feb 2017 13:19:21 GMT</pubDate>
      <guid>https://community.qlik.com/t5/Management-Governance/Configure-User-Directory-to-Azure-LDAP/m-p/1190521#M7415</guid>
      <dc:creator>azimuthbrett</dc:creator>
      <dc:date>2017-02-08T13:19:21Z</dc:date>
    </item>
    <item>
      <title>Re: Configure User Directory to Azure LDAP</title>
      <link>https://community.qlik.com/t5/Management-Governance/Configure-User-Directory-to-Azure-LDAP/m-p/1190522#M7416</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P style="font-size: 13px; font-family: 'Helvetica Neue', Helvetica, Arial, 'Lucida Grande', sans-serif; color: #3d3d3d;"&gt;&lt;A class="jive-link-external-small" href="https://docs.microsoft.com/en-us/azure/active-directory/active-directory-saas-qliksense-enterprise-tutorial" rel="nofollow" style="font-weight: inherit; font-style: inherit; font-family: inherit; color: #3778c7;" target="_blank"&gt;Tutorial: Azure Active Directory integration with Qlik Sense Enterprise | Microsoft Docs&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P style="font-size: 13px; font-family: 'Helvetica Neue', Helvetica, Arial, 'Lucida Grande', sans-serif; color: #3d3d3d;"&gt;It shall be better with this one. Slash were removed from the previous link I provided I don't know why&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 08 Feb 2017 15:08:55 GMT</pubDate>
      <guid>https://community.qlik.com/t5/Management-Governance/Configure-User-Directory-to-Azure-LDAP/m-p/1190522#M7416</guid>
      <dc:creator>joan_marty</dc:creator>
      <dc:date>2017-02-08T15:08:55Z</dc:date>
    </item>
    <item>
      <title>Re: Configure User Directory to Azure LDAP</title>
      <link>https://community.qlik.com/t5/Management-Governance/Configure-User-Directory-to-Azure-LDAP/m-p/1190523#M7417</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Effectively in such case wanting to propagate SSO, the only option we found internally is to synchronize Azure AD with a local AD in the domain.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;We did not found yet any other possibility to do differently.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Joan Marty&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Le 8 févr. 2017 à 17:10, Brett Odom &amp;lt;qcwebmaster@qlikview.com&amp;lt;mailto:qcwebmaster@qlikview.com&amp;gt;&amp;gt; a écrit :&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;        &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 08 Feb 2017 16:58:57 GMT</pubDate>
      <guid>https://community.qlik.com/t5/Management-Governance/Configure-User-Directory-to-Azure-LDAP/m-p/1190523#M7417</guid>
      <dc:creator>joan_marty</dc:creator>
      <dc:date>2017-02-08T16:58:57Z</dc:date>
    </item>
    <item>
      <title>Re: Configure User Directory to Azure LDAP</title>
      <link>https://community.qlik.com/t5/Management-Governance/Configure-User-Directory-to-Azure-LDAP/m-p/1190524#M7418</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Finally : &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P style="font-size: 13px; font-family: 'Helvetica Neue', Helvetica, Arial, 'Lucida Grande', sans-serif; color: #3d3d3d;"&gt;if anyone wants to create an Azure AD UDC : here attached is the "Generic LDAP UDC configuration".&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P style="font-size: 13px; font-family: 'Helvetica Neue', Helvetica, Arial, 'Lucida Grande', sans-serif; color: #3d3d3d;"&gt;So, you just have to change the User-Directory-Attribute "User identification" to "Person" and that's it&lt;/P&gt;&lt;P style="font-size: 13px; font-family: 'Helvetica Neue', Helvetica, Arial, 'Lucida Grande', sans-serif; color: #3d3d3d;"&gt;&lt;/P&gt;&lt;P style="font-size: 13px; font-family: 'Helvetica Neue', Helvetica, Arial, 'Lucida Grande', sans-serif; color: #3d3d3d;"&gt;&lt;IMG alt="Resolution Ldap Azure.png" class="jive-image image-1" src="/legacyfs/online/200854_Resolution Ldap Azure.png" style="height: 591px; width: 620px;" /&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 26 Apr 2018 09:09:31 GMT</pubDate>
      <guid>https://community.qlik.com/t5/Management-Governance/Configure-User-Directory-to-Azure-LDAP/m-p/1190524#M7418</guid>
      <dc:creator>thomaslg_wq</dc:creator>
      <dc:date>2018-04-26T09:09:31Z</dc:date>
    </item>
  </channel>
</rss>

