<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>article Switching from ADFS to AzureAD for AzureAD Groups in Qlik Cloud in Official Support Articles</title>
    <link>https://community.qlik.com/t5/Official-Support-Articles/Switching-from-ADFS-to-AzureAD-for-AzureAD-Groups-in-Qlik-Cloud/ta-p/1774559</link>
    <description>&lt;P&gt;&lt;FONT color="#000000"&gt;If you're a Qlik Enterprise SaaS early adopter, you managed to configure Azure Active Directory as the identity provider for your tenant using the ADFS option in the settings menu. While this enabled users to authenticate from Azure AD, it didn't solve a key problem with this workaround; native Azure group name resolution.&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&lt;FONT color="#000000"&gt;The new Azure AD identity provider settings in QCS include proper group name resolution. But you might be hesitant to switch the configuration from ADFS because you're worried about the impact on existing access control set up in your tenant. Will Space permissions work after the switch? Will users retain all their personal content? Will the switch create duplicate users? This blog resolves these concerns by showing you how to make the switch from ADFS to Azure AD smoothly.&lt;/FONT&gt;&lt;/P&gt;
&lt;H3 id="good-news-the-app-registration-in-azure-ad-remains-valid"&gt;&lt;STRONG&gt;&lt;FONT color="#339966"&gt;Good news: The app registration in Azure AD remains valid&lt;/FONT&gt;&lt;/STRONG&gt;&lt;/H3&gt;
&lt;P&gt;&lt;FONT color="#000000"&gt;There's no need to reinvent the wheel and create a new app registration in Azure to support the switch. However, there is a significant tweak to make if you want to take advantage of Qlik's capabilities to resolve group names from Azure. Here are the steps to prepare the existing app registration for reuse in QCS.&lt;/FONT&gt;&lt;/P&gt;
&lt;H4&gt;&lt;FONT color="#339966"&gt;&lt;STRONG&gt;Create a new client secret&lt;/STRONG&gt;&lt;/FONT&gt;&lt;/H4&gt;
&lt;P&gt;&lt;FONT color="#000000"&gt;In all likelihood, you misplaced - or should have lost - the client secret you created when you set up the app registration the first time. It's easy enough to generate a new secret for the app in the certificates and secrets section of the config. Create a new client secret and make a copy of it for use when you update QCS.&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&lt;FONT color="#000000"&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-left" image-alt="certs-and-secrets" style="width: 999px;"&gt;&lt;img src="https://community.qlik.com/t5/image/serverpage/image-id/47042i0B8B89A59028A011/image-size/large?v=v2&amp;amp;px=999" role="button" title="certs-and-secrets" alt="certs-and-secrets" /&gt;&lt;/span&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;H3&gt;&amp;nbsp;&lt;/H3&gt;
&lt;H3&gt;&amp;nbsp;&lt;/H3&gt;
&lt;H3&gt;&amp;nbsp;&lt;/H3&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;H4&gt;&amp;nbsp;&lt;/H4&gt;
&lt;H4&gt;&amp;nbsp;&lt;/H4&gt;
&lt;H4 id="remove-groups-optional-claim-from-token-configuration"&gt;&lt;STRONG&gt;&lt;FONT color="#339966"&gt;Remove groups optional claim from Token configuration&lt;/FONT&gt;&lt;/STRONG&gt;&lt;/H4&gt;
&lt;P&gt;&lt;FONT color="#000000"&gt;Say what now? Remove the groups claim? Yes, that's right, you don't need the groups claim anymore to obtain a user's groups because the Azure AD setting in QCS contacts the Microsoft Graph API to collect this information, resolving the group names for Azure AD native groups and groups synchronized through AD-Connect.&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&lt;FONT color="#000000"&gt;&lt;IMG src="https://raw.githubusercontent.com/goldbergjeffrey/mydocs/main/images/configure-azuread-idp-with-qcs/ad-config/remove-groups-claim.png" border="0" /&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;H4&gt;&amp;nbsp;&lt;/H4&gt;
&lt;H4 id="add-groupmember-read-all-api-permissions"&gt;&lt;STRONG&gt;&lt;FONT color="#339966"&gt;Add GroupMember.Read.All API permissions&lt;/FONT&gt;&lt;/STRONG&gt;&lt;/H4&gt;
&lt;P&gt;&lt;FONT color="#000000"&gt;The reason the optional groups claim is not needed is there is an API permission allowing sharing the groups the user is a member of. When the permission &lt;CODE&gt;GroupMember.Read.All&lt;/CODE&gt; is added to the app registration, Qlik makes a request to the MS Graph on behalf of the user to obtain the group names for which they are a member.&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&lt;FONT color="#000000"&gt;&lt;IMG src="https://raw.githubusercontent.com/goldbergjeffrey/mydocs/main/images/configure-azuread-idp-with-qcs/ad-config/api-permission-list.png" border="0" /&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&lt;FONT color="#000000"&gt;&lt;IMG src="https://raw.githubusercontent.com/goldbergjeffrey/mydocs/main/images/configure-azuread-idp-with-qcs/ad-config/ms-graph.png" border="0" /&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&lt;FONT color="#000000"&gt;&lt;IMG src="https://raw.githubusercontent.com/goldbergjeffrey/mydocs/main/images/configure-azuread-idp-with-qcs/ad-config/ms-graph-enabled-permissions.png" border="0" /&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&lt;FONT color="#000000"&gt;&lt;IMG src="https://raw.githubusercontent.com/goldbergjeffrey/mydocs/main/images/configure-azuread-idp-with-qcs/ad-config/groupmember-read-all.png" border="0" /&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;BLOCKQUOTE&gt;
&lt;P&gt;&lt;FONT color="#000000"&gt;Before you continue! Make sure to grant admin consent for the new GroupMember.Read.All permission. If you miss this step, expect http 401 errors because of the request to Microsoft Graph.&lt;/FONT&gt;&lt;/P&gt;
&lt;/BLOCKQUOTE&gt;
&lt;P&gt;&lt;FONT color="#000000"&gt;&lt;IMG src="https://raw.githubusercontent.com/goldbergjeffrey/mydocs/main/images/configure-azuread-idp-with-qcs/ad-config/grant-consent.png" border="0" /&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;H3&gt;&amp;nbsp;&lt;/H3&gt;
&lt;H3 id="create-a-new-interactive-identity-provider-configuration-in-qcs"&gt;&lt;STRONG&gt;&lt;FONT color="#339966"&gt;Create a new interactive identity provider configuration in QCS&lt;/FONT&gt;&lt;/STRONG&gt;&lt;/H3&gt;
&lt;P&gt;&lt;FONT color="#000000"&gt;While Qlik Enterprise SaaS allows for only one active interactive identity provider in a tenant, you can set up more to make it easier to switch from one to another.&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&lt;FONT color="#000000"&gt;For converting from an ADFS configuration to an Azure AD setup it's straightforward but there are a couple of tweaks you want to pay attention to ensuring a smooth transition. Here are the steps:&lt;/FONT&gt;&lt;/P&gt;
&lt;H4 id="copy-idp-settings-from-the-existing-adfs-configuration"&gt;&lt;STRONG&gt;&lt;FONT color="#339966"&gt;Copy IdP settings from the existing ADFS configuration&lt;/FONT&gt;&lt;/STRONG&gt;&lt;/H4&gt;
&lt;P&gt;&lt;FONT color="#000000"&gt;Take some screenshots of the ADFS set up, and record the discovery URL and Client ID to notepad so you can reuse them in the new configuration.&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&lt;FONT color="#000000"&gt;&lt;IMG src="https://raw.githubusercontent.com/goldbergjeffrey/mydocs/main/images/change-from-adfs-to-azuread-with-no-user-impact/application-credentials.png" border="0" /&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&lt;FONT color="#000000"&gt;&lt;IMG src="https://raw.githubusercontent.com/goldbergjeffrey/mydocs/main/images/change-from-adfs-to-azuread-with-no-user-impact/claims-mapping.png" border="0" /&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;H4 id="create-the-azure-ad-configuraiton"&gt;&lt;STRONG&gt;&lt;FONT color="#339966"&gt;Create the Azure AD configuration&lt;/FONT&gt;&lt;/STRONG&gt;&lt;/H4&gt;
&lt;P&gt;&lt;FONT color="#000000"&gt;Create a new interactive identity provider selecting Azure AD from the provider list.&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&lt;FONT color="#000000"&gt;&lt;IMG src="https://raw.githubusercontent.com/goldbergjeffrey/mydocs/main/images/change-from-adfs-to-azuread-with-no-user-impact/idp-type.png" border="0" /&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&lt;FONT color="#000000"&gt;&lt;IMG src="https://raw.githubusercontent.com/goldbergjeffrey/mydocs/main/images/change-from-adfs-to-azuread-with-no-user-impact/provider-list.png" border="0" /&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&lt;FONT color="#000000"&gt;Add the discovery URL for the app registration and input the Client ID and the new client secret created earlier in the corresponding text boxes.&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&lt;FONT color="#000000"&gt;Fill out the claims mapping values from your ADFS settings screenshot.&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&lt;FONT color="#000000"&gt;Lastly, to make sure the mapping works properly expand Advanced options and slide the email verified override switch to on.&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&lt;FONT color="#000000"&gt;&lt;IMG src="https://raw.githubusercontent.com/goldbergjeffrey/mydocs/main/images/change-from-adfs-to-azuread-with-no-user-impact/email_verified-switch.png" border="0" /&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&lt;FONT color="#000000"&gt;Create the configuration and save it.&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&lt;FONT color="#000000"&gt;After you authenticate to the new identity provider, the validation screen appears. With the new email verified claim switch turned on, the email shows up signifying the mapping process succeeded. Click through and activate the IdP.&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&lt;FONT color="#000000"&gt;&lt;IMG src="https://raw.githubusercontent.com/goldbergjeffrey/mydocs/main/images/change-from-adfs-to-azuread-with-no-user-impact/validation-screen.png" border="0" /&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;BLOCKQUOTE&gt;
&lt;P&gt;&lt;FONT color="#000000"&gt;Log out completely. This may require you to log out twice, once as the new validated user, and once as the user you logged in as to create the new configuration.&lt;/FONT&gt;&lt;/P&gt;
&lt;/BLOCKQUOTE&gt;
&lt;P&gt;&lt;FONT color="#000000"&gt;Log in through Azure and go to a space to add members and view friendly group names.&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&lt;FONT color="#000000"&gt;&lt;IMG src="https://raw.githubusercontent.com/goldbergjeffrey/mydocs/main/images/change-from-adfs-to-azuread-with-no-user-impact/group-list.png" border="0" /&gt;&lt;/FONT&gt;&lt;/P&gt;</description>
    <pubDate>Tue, 10 May 2022 19:01:03 GMT</pubDate>
    <dc:creator>Jeffrey_Goldberg</dc:creator>
    <dc:date>2022-05-10T19:01:03Z</dc:date>
    <item>
      <title>Switching from ADFS to AzureAD for AzureAD Groups in Qlik Cloud</title>
      <link>https://community.qlik.com/t5/Official-Support-Articles/Switching-from-ADFS-to-AzureAD-for-AzureAD-Groups-in-Qlik-Cloud/ta-p/1774559</link>
      <description>&lt;P&gt;&lt;FONT color="#000000"&gt;If you're a Qlik Enterprise SaaS early adopter, you managed to configure Azure Active Directory as the identity provider for your tenant using the ADFS option in the settings menu. While this enabled users to authenticate from Azure AD, it didn't solve a key problem with this workaround; native Azure group name resolution.&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&lt;FONT color="#000000"&gt;The new Azure AD identity provider settings in QCS include proper group name resolution. But you might be hesitant to switch the configuration from ADFS because you're worried about the impact on existing access control set up in your tenant. Will Space permissions work after the switch? Will users retain all their personal content? Will the switch create duplicate users? This blog resolves these concerns by showing you how to make the switch from ADFS to Azure AD smoothly.&lt;/FONT&gt;&lt;/P&gt;
&lt;H3 id="good-news-the-app-registration-in-azure-ad-remains-valid"&gt;&lt;STRONG&gt;&lt;FONT color="#339966"&gt;Good news: The app registration in Azure AD remains valid&lt;/FONT&gt;&lt;/STRONG&gt;&lt;/H3&gt;
&lt;P&gt;&lt;FONT color="#000000"&gt;There's no need to reinvent the wheel and create a new app registration in Azure to support the switch. However, there is a significant tweak to make if you want to take advantage of Qlik's capabilities to resolve group names from Azure. Here are the steps to prepare the existing app registration for reuse in QCS.&lt;/FONT&gt;&lt;/P&gt;
&lt;H4&gt;&lt;FONT color="#339966"&gt;&lt;STRONG&gt;Create a new client secret&lt;/STRONG&gt;&lt;/FONT&gt;&lt;/H4&gt;
&lt;P&gt;&lt;FONT color="#000000"&gt;In all likelihood, you misplaced - or should have lost - the client secret you created when you set up the app registration the first time. It's easy enough to generate a new secret for the app in the certificates and secrets section of the config. Create a new client secret and make a copy of it for use when you update QCS.&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&lt;FONT color="#000000"&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-left" image-alt="certs-and-secrets" style="width: 999px;"&gt;&lt;img src="https://community.qlik.com/t5/image/serverpage/image-id/47042i0B8B89A59028A011/image-size/large?v=v2&amp;amp;px=999" role="button" title="certs-and-secrets" alt="certs-and-secrets" /&gt;&lt;/span&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;H3&gt;&amp;nbsp;&lt;/H3&gt;
&lt;H3&gt;&amp;nbsp;&lt;/H3&gt;
&lt;H3&gt;&amp;nbsp;&lt;/H3&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;H4&gt;&amp;nbsp;&lt;/H4&gt;
&lt;H4&gt;&amp;nbsp;&lt;/H4&gt;
&lt;H4 id="remove-groups-optional-claim-from-token-configuration"&gt;&lt;STRONG&gt;&lt;FONT color="#339966"&gt;Remove groups optional claim from Token configuration&lt;/FONT&gt;&lt;/STRONG&gt;&lt;/H4&gt;
&lt;P&gt;&lt;FONT color="#000000"&gt;Say what now? Remove the groups claim? Yes, that's right, you don't need the groups claim anymore to obtain a user's groups because the Azure AD setting in QCS contacts the Microsoft Graph API to collect this information, resolving the group names for Azure AD native groups and groups synchronized through AD-Connect.&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&lt;FONT color="#000000"&gt;&lt;IMG src="https://raw.githubusercontent.com/goldbergjeffrey/mydocs/main/images/configure-azuread-idp-with-qcs/ad-config/remove-groups-claim.png" border="0" /&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;H4&gt;&amp;nbsp;&lt;/H4&gt;
&lt;H4 id="add-groupmember-read-all-api-permissions"&gt;&lt;STRONG&gt;&lt;FONT color="#339966"&gt;Add GroupMember.Read.All API permissions&lt;/FONT&gt;&lt;/STRONG&gt;&lt;/H4&gt;
&lt;P&gt;&lt;FONT color="#000000"&gt;The reason the optional groups claim is not needed is there is an API permission allowing sharing the groups the user is a member of. When the permission &lt;CODE&gt;GroupMember.Read.All&lt;/CODE&gt; is added to the app registration, Qlik makes a request to the MS Graph on behalf of the user to obtain the group names for which they are a member.&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&lt;FONT color="#000000"&gt;&lt;IMG src="https://raw.githubusercontent.com/goldbergjeffrey/mydocs/main/images/configure-azuread-idp-with-qcs/ad-config/api-permission-list.png" border="0" /&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&lt;FONT color="#000000"&gt;&lt;IMG src="https://raw.githubusercontent.com/goldbergjeffrey/mydocs/main/images/configure-azuread-idp-with-qcs/ad-config/ms-graph.png" border="0" /&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&lt;FONT color="#000000"&gt;&lt;IMG src="https://raw.githubusercontent.com/goldbergjeffrey/mydocs/main/images/configure-azuread-idp-with-qcs/ad-config/ms-graph-enabled-permissions.png" border="0" /&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&lt;FONT color="#000000"&gt;&lt;IMG src="https://raw.githubusercontent.com/goldbergjeffrey/mydocs/main/images/configure-azuread-idp-with-qcs/ad-config/groupmember-read-all.png" border="0" /&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;BLOCKQUOTE&gt;
&lt;P&gt;&lt;FONT color="#000000"&gt;Before you continue! Make sure to grant admin consent for the new GroupMember.Read.All permission. If you miss this step, expect http 401 errors because of the request to Microsoft Graph.&lt;/FONT&gt;&lt;/P&gt;
&lt;/BLOCKQUOTE&gt;
&lt;P&gt;&lt;FONT color="#000000"&gt;&lt;IMG src="https://raw.githubusercontent.com/goldbergjeffrey/mydocs/main/images/configure-azuread-idp-with-qcs/ad-config/grant-consent.png" border="0" /&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;H3&gt;&amp;nbsp;&lt;/H3&gt;
&lt;H3 id="create-a-new-interactive-identity-provider-configuration-in-qcs"&gt;&lt;STRONG&gt;&lt;FONT color="#339966"&gt;Create a new interactive identity provider configuration in QCS&lt;/FONT&gt;&lt;/STRONG&gt;&lt;/H3&gt;
&lt;P&gt;&lt;FONT color="#000000"&gt;While Qlik Enterprise SaaS allows for only one active interactive identity provider in a tenant, you can set up more to make it easier to switch from one to another.&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&lt;FONT color="#000000"&gt;For converting from an ADFS configuration to an Azure AD setup it's straightforward but there are a couple of tweaks you want to pay attention to ensuring a smooth transition. Here are the steps:&lt;/FONT&gt;&lt;/P&gt;
&lt;H4 id="copy-idp-settings-from-the-existing-adfs-configuration"&gt;&lt;STRONG&gt;&lt;FONT color="#339966"&gt;Copy IdP settings from the existing ADFS configuration&lt;/FONT&gt;&lt;/STRONG&gt;&lt;/H4&gt;
&lt;P&gt;&lt;FONT color="#000000"&gt;Take some screenshots of the ADFS set up, and record the discovery URL and Client ID to notepad so you can reuse them in the new configuration.&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&lt;FONT color="#000000"&gt;&lt;IMG src="https://raw.githubusercontent.com/goldbergjeffrey/mydocs/main/images/change-from-adfs-to-azuread-with-no-user-impact/application-credentials.png" border="0" /&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&lt;FONT color="#000000"&gt;&lt;IMG src="https://raw.githubusercontent.com/goldbergjeffrey/mydocs/main/images/change-from-adfs-to-azuread-with-no-user-impact/claims-mapping.png" border="0" /&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;H4 id="create-the-azure-ad-configuraiton"&gt;&lt;STRONG&gt;&lt;FONT color="#339966"&gt;Create the Azure AD configuration&lt;/FONT&gt;&lt;/STRONG&gt;&lt;/H4&gt;
&lt;P&gt;&lt;FONT color="#000000"&gt;Create a new interactive identity provider selecting Azure AD from the provider list.&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&lt;FONT color="#000000"&gt;&lt;IMG src="https://raw.githubusercontent.com/goldbergjeffrey/mydocs/main/images/change-from-adfs-to-azuread-with-no-user-impact/idp-type.png" border="0" /&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&lt;FONT color="#000000"&gt;&lt;IMG src="https://raw.githubusercontent.com/goldbergjeffrey/mydocs/main/images/change-from-adfs-to-azuread-with-no-user-impact/provider-list.png" border="0" /&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&lt;FONT color="#000000"&gt;Add the discovery URL for the app registration and input the Client ID and the new client secret created earlier in the corresponding text boxes.&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&lt;FONT color="#000000"&gt;Fill out the claims mapping values from your ADFS settings screenshot.&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&lt;FONT color="#000000"&gt;Lastly, to make sure the mapping works properly expand Advanced options and slide the email verified override switch to on.&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&lt;FONT color="#000000"&gt;&lt;IMG src="https://raw.githubusercontent.com/goldbergjeffrey/mydocs/main/images/change-from-adfs-to-azuread-with-no-user-impact/email_verified-switch.png" border="0" /&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&lt;FONT color="#000000"&gt;Create the configuration and save it.&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&lt;FONT color="#000000"&gt;After you authenticate to the new identity provider, the validation screen appears. With the new email verified claim switch turned on, the email shows up signifying the mapping process succeeded. Click through and activate the IdP.&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&lt;FONT color="#000000"&gt;&lt;IMG src="https://raw.githubusercontent.com/goldbergjeffrey/mydocs/main/images/change-from-adfs-to-azuread-with-no-user-impact/validation-screen.png" border="0" /&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;BLOCKQUOTE&gt;
&lt;P&gt;&lt;FONT color="#000000"&gt;Log out completely. This may require you to log out twice, once as the new validated user, and once as the user you logged in as to create the new configuration.&lt;/FONT&gt;&lt;/P&gt;
&lt;/BLOCKQUOTE&gt;
&lt;P&gt;&lt;FONT color="#000000"&gt;Log in through Azure and go to a space to add members and view friendly group names.&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&lt;FONT color="#000000"&gt;&lt;IMG src="https://raw.githubusercontent.com/goldbergjeffrey/mydocs/main/images/change-from-adfs-to-azuread-with-no-user-impact/group-list.png" border="0" /&gt;&lt;/FONT&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 10 May 2022 19:01:03 GMT</pubDate>
      <guid>https://community.qlik.com/t5/Official-Support-Articles/Switching-from-ADFS-to-AzureAD-for-AzureAD-Groups-in-Qlik-Cloud/ta-p/1774559</guid>
      <dc:creator>Jeffrey_Goldberg</dc:creator>
      <dc:date>2022-05-10T19:01:03Z</dc:date>
    </item>
  </channel>
</rss>

