<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>article Guidance on how to conclude if the issue is Security Rule Related in Official Support Articles</title>
    <link>https://community.qlik.com/t5/Official-Support-Articles/Guidance-on-how-to-conclude-if-the-issue-is-Security-Rule/ta-p/1716546</link>
    <description>&lt;P class="qlik-migrated-tkb-headings"&gt;&lt;div class="video-embed-center video-embed"&gt;&lt;iframe class="embedly-embed" src="https://cdn.embedly.com/widgets/media.html?src=https%3A%2F%2Fwww.youtube.com%2Fembed%2F7qXV1uWf9DM%3Ffeature%3Doembed&amp;amp;display_name=YouTube&amp;amp;url=https%3A%2F%2Fwww.youtube.com%2Fwatch%3Fv%3D7qXV1uWf9DM&amp;amp;image=https%3A%2F%2Fi.ytimg.com%2Fvi%2F7qXV1uWf9DM%2Fhqdefault.jpg&amp;amp;type=text%2Fhtml&amp;amp;schema=youtube" width="200" height="112" scrolling="no" title="Qlik Fix: How to check if issue is security rule related" frameborder="0" allow="autoplay; fullscreen; encrypted-media; picture-in-picture;" allowfullscreen="true"&gt;&lt;/iframe&gt;&lt;/div&gt;&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt;Qlik Sense allows for flexible assignment of user access rights by utilizing Security Rule.&lt;BR /&gt;&lt;BR /&gt;This article is meant to help in identifying if a Security Rule is causing an issue. For information on how Security Rules operate, please see the official Qlik Sense Help site for your respective version &amp;gt; Designing access control &amp;gt;&amp;nbsp;&lt;I&gt;&lt;A href="https://help.qlik.com/en-US/sense-admin/September2019/Subsystems/DeployAdministerQSE/Content/Sense_DeployAdminister/QSEoW/Administer_QSEoW/Managing_QSEoW/security-rules-evaluation.htm" target="_blank" rel="noopener"&gt;Security rules evaluation&lt;/A&gt;&lt;/I&gt;&lt;BR /&gt;&lt;BR /&gt;Each time a user requests access to a resource,&amp;nbsp;Qlik Sense&amp;nbsp;evaluates the request against the security rules in the&amp;nbsp;Qlik Sense&amp;nbsp;system. If at least one rule evaluates to True then&amp;nbsp;Qlik Sense&amp;nbsp;will provide the user with access according to the conditions and actions described in the security rule. If no rules evaluate to True&amp;nbsp;then the user will be denied access. The fact that&amp;nbsp;Qlik Sense&amp;nbsp;security rules are property-based makes&amp;nbsp;Qlik Sense&amp;nbsp;very scalable as you can build rules based on properties that apply to groups of users.&lt;BR /&gt;&lt;BR /&gt;As of such, it is possible that multiple custom security rules are in place that are overriding each other, or multiple "Roles" are assigned to a User in the "Users" tab and their rights are conflicting.&lt;BR /&gt;&lt;BR /&gt;This article provide guidance on how to conclude if the issue is caused by Security Rules or by something else.&lt;BR /&gt;&lt;BR /&gt;Also see related article &lt;A href="https://community.qlik.com/t5/Support-Knowledge-Base/How-to-Use-the-Audit-function-to-verify-app-access-for-users-and/ta-p/1716865" target="_blank" rel="noopener"&gt;Qlik Sense How to: Use the Audit function to see what access user has to apps in the hub, and what rules that are in affect&lt;/A&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;STRONG&gt;Environment:&lt;/STRONG&gt;&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;Qlik Sense Enterprise all versions&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;For&amp;nbsp;Qlik Sense February 2019 (13.9.2), please first refer to&amp;nbsp;&lt;A href="https://support.qlik.com/articles/Basic/Super-Admin-Security-Rule" target="_blank" rel="noopener"&gt;Super Admin Security Rule not working&lt;/A&gt;&lt;/P&gt;
&lt;P class="qlik-migrated-tkb-headings"&gt;Resolution:&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt;When a user reported an issue, create a super admin role, assign it to that user and see if the issue will be resolved.&lt;BR /&gt;&lt;BR /&gt;1. Go to QMC &amp;gt; &lt;SPAN&gt;Security Rules&lt;/SPAN&gt;&lt;BR /&gt;2. Click &lt;SPAN&gt;Create &lt;/SPAN&gt;new button&lt;BR /&gt;3. Enter &lt;SPAN&gt;&lt;STRONG&gt;T-SuperAdmin&lt;/STRONG&gt;&lt;/SPAN&gt; in Name&lt;BR /&gt;4. Enter&lt;SPAN&gt;&amp;nbsp;&lt;STRONG&gt;SuperAdmin for Troubleshooting Purpose&lt;/STRONG&gt;&lt;/SPAN&gt;&amp;nbsp;in &lt;SPAN&gt;Description&lt;/SPAN&gt;&lt;BR /&gt;5. Enter &lt;STRONG&gt;*&lt;/STRONG&gt; in Resource filter&lt;BR /&gt;6. Tick "&lt;SPAN&gt;Create&lt;/SPAN&gt;", "&lt;SPAN&gt;Read&lt;/SPAN&gt;", "&lt;SPAN&gt;Update&lt;/SPAN&gt;", "&lt;SPAN&gt;Delete&lt;/SPAN&gt;", "&lt;SPAN&gt;Export&lt;/SPAN&gt;", "&lt;SPAN&gt;Publish&lt;/SPAN&gt;","&lt;SPAN&gt;Change owner&lt;/SPAN&gt;", "&lt;SPAN&gt;Change role&lt;/SPAN&gt;", "&lt;SPAN&gt;Export data&lt;/SPAN&gt;", "&lt;FONT face="Courier New, Courier, monospace"&gt;Access offline&lt;/FONT&gt;", "&lt;FONT face="Courier New, Courier, monospace"&gt;Duplicate&lt;/FONT&gt;" in &lt;SPAN&gt;Action&lt;/SPAN&gt;&lt;BR /&gt;7. Enter&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;STRONG&gt;&lt;SPAN&gt;((user.roles="T-SuperAdmin"))&lt;/SPAN&gt;&amp;nbsp;&lt;/STRONG&gt;in &lt;SPAN&gt;Conditions&lt;/SPAN&gt;&lt;BR /&gt;8. Select&lt;STRONG&gt; &lt;SPAN&gt;Both in hub and QMC&lt;/SPAN&gt;&lt;/STRONG&gt; in &lt;SPAN&gt;Context&lt;/SPAN&gt;&lt;BR /&gt;9. Press &lt;SPAN&gt;Apply &lt;/SPAN&gt;button&lt;BR /&gt;10. Go to QMC &amp;gt; &lt;SPAN&gt;Users&lt;/SPAN&gt;&lt;BR /&gt;11. Select the user who has the issue and click &lt;SPAN&gt;Edit &lt;/SPAN&gt;button&lt;BR /&gt;12. Click &lt;SPAN&gt;Add role&lt;/SPAN&gt; button and select&lt;SPAN&gt;&amp;nbsp;&lt;STRONG&gt;T-SuperAdmin&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;BR /&gt;13. If any existing role or custom properties applied, please remove it&amp;nbsp;&lt;BR /&gt;14. Press &lt;SPAN&gt;Apply &lt;/SPAN&gt;button&lt;BR /&gt;15. Ask the user who reported to do the test and see if the issue will be resolved for that user&lt;BR /&gt;Note: Please also ask the user to close all of the existing browsers before start the test.&lt;/P&gt;
&lt;H4&gt;If the issue resolved:&lt;/H4&gt;
&lt;DIV&gt;Security Rule related. Please review existing security rules&lt;/DIV&gt;
&lt;DIV&gt;&amp;nbsp;&lt;/DIV&gt;
&lt;H4&gt;If the issue is not resolved:&lt;/H4&gt;
&lt;DIV&gt;&amp;nbsp;Not Security Related&lt;/DIV&gt;</description>
    <pubDate>Thu, 11 Feb 2021 09:30:10 GMT</pubDate>
    <dc:creator>Yoichi_Hirotake</dc:creator>
    <dc:date>2021-02-11T09:30:10Z</dc:date>
    <item>
      <title>Guidance on how to conclude if the issue is Security Rule Related</title>
      <link>https://community.qlik.com/t5/Official-Support-Articles/Guidance-on-how-to-conclude-if-the-issue-is-Security-Rule/ta-p/1716546</link>
      <description>&lt;P class="qlik-migrated-tkb-headings"&gt;&lt;div class="video-embed-center video-embed"&gt;&lt;iframe class="embedly-embed" src="https://cdn.embedly.com/widgets/media.html?src=https%3A%2F%2Fwww.youtube.com%2Fembed%2F7qXV1uWf9DM%3Ffeature%3Doembed&amp;amp;display_name=YouTube&amp;amp;url=https%3A%2F%2Fwww.youtube.com%2Fwatch%3Fv%3D7qXV1uWf9DM&amp;amp;image=https%3A%2F%2Fi.ytimg.com%2Fvi%2F7qXV1uWf9DM%2Fhqdefault.jpg&amp;amp;type=text%2Fhtml&amp;amp;schema=youtube" width="200" height="112" scrolling="no" title="Qlik Fix: How to check if issue is security rule related" frameborder="0" allow="autoplay; fullscreen; encrypted-media; picture-in-picture;" allowfullscreen="true"&gt;&lt;/iframe&gt;&lt;/div&gt;&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt;Qlik Sense allows for flexible assignment of user access rights by utilizing Security Rule.&lt;BR /&gt;&lt;BR /&gt;This article is meant to help in identifying if a Security Rule is causing an issue. For information on how Security Rules operate, please see the official Qlik Sense Help site for your respective version &amp;gt; Designing access control &amp;gt;&amp;nbsp;&lt;I&gt;&lt;A href="https://help.qlik.com/en-US/sense-admin/September2019/Subsystems/DeployAdministerQSE/Content/Sense_DeployAdminister/QSEoW/Administer_QSEoW/Managing_QSEoW/security-rules-evaluation.htm" target="_blank" rel="noopener"&gt;Security rules evaluation&lt;/A&gt;&lt;/I&gt;&lt;BR /&gt;&lt;BR /&gt;Each time a user requests access to a resource,&amp;nbsp;Qlik Sense&amp;nbsp;evaluates the request against the security rules in the&amp;nbsp;Qlik Sense&amp;nbsp;system. If at least one rule evaluates to True then&amp;nbsp;Qlik Sense&amp;nbsp;will provide the user with access according to the conditions and actions described in the security rule. If no rules evaluate to True&amp;nbsp;then the user will be denied access. The fact that&amp;nbsp;Qlik Sense&amp;nbsp;security rules are property-based makes&amp;nbsp;Qlik Sense&amp;nbsp;very scalable as you can build rules based on properties that apply to groups of users.&lt;BR /&gt;&lt;BR /&gt;As of such, it is possible that multiple custom security rules are in place that are overriding each other, or multiple "Roles" are assigned to a User in the "Users" tab and their rights are conflicting.&lt;BR /&gt;&lt;BR /&gt;This article provide guidance on how to conclude if the issue is caused by Security Rules or by something else.&lt;BR /&gt;&lt;BR /&gt;Also see related article &lt;A href="https://community.qlik.com/t5/Support-Knowledge-Base/How-to-Use-the-Audit-function-to-verify-app-access-for-users-and/ta-p/1716865" target="_blank" rel="noopener"&gt;Qlik Sense How to: Use the Audit function to see what access user has to apps in the hub, and what rules that are in affect&lt;/A&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;STRONG&gt;Environment:&lt;/STRONG&gt;&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;Qlik Sense Enterprise all versions&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;For&amp;nbsp;Qlik Sense February 2019 (13.9.2), please first refer to&amp;nbsp;&lt;A href="https://support.qlik.com/articles/Basic/Super-Admin-Security-Rule" target="_blank" rel="noopener"&gt;Super Admin Security Rule not working&lt;/A&gt;&lt;/P&gt;
&lt;P class="qlik-migrated-tkb-headings"&gt;Resolution:&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt;When a user reported an issue, create a super admin role, assign it to that user and see if the issue will be resolved.&lt;BR /&gt;&lt;BR /&gt;1. Go to QMC &amp;gt; &lt;SPAN&gt;Security Rules&lt;/SPAN&gt;&lt;BR /&gt;2. Click &lt;SPAN&gt;Create &lt;/SPAN&gt;new button&lt;BR /&gt;3. Enter &lt;SPAN&gt;&lt;STRONG&gt;T-SuperAdmin&lt;/STRONG&gt;&lt;/SPAN&gt; in Name&lt;BR /&gt;4. Enter&lt;SPAN&gt;&amp;nbsp;&lt;STRONG&gt;SuperAdmin for Troubleshooting Purpose&lt;/STRONG&gt;&lt;/SPAN&gt;&amp;nbsp;in &lt;SPAN&gt;Description&lt;/SPAN&gt;&lt;BR /&gt;5. Enter &lt;STRONG&gt;*&lt;/STRONG&gt; in Resource filter&lt;BR /&gt;6. Tick "&lt;SPAN&gt;Create&lt;/SPAN&gt;", "&lt;SPAN&gt;Read&lt;/SPAN&gt;", "&lt;SPAN&gt;Update&lt;/SPAN&gt;", "&lt;SPAN&gt;Delete&lt;/SPAN&gt;", "&lt;SPAN&gt;Export&lt;/SPAN&gt;", "&lt;SPAN&gt;Publish&lt;/SPAN&gt;","&lt;SPAN&gt;Change owner&lt;/SPAN&gt;", "&lt;SPAN&gt;Change role&lt;/SPAN&gt;", "&lt;SPAN&gt;Export data&lt;/SPAN&gt;", "&lt;FONT face="Courier New, Courier, monospace"&gt;Access offline&lt;/FONT&gt;", "&lt;FONT face="Courier New, Courier, monospace"&gt;Duplicate&lt;/FONT&gt;" in &lt;SPAN&gt;Action&lt;/SPAN&gt;&lt;BR /&gt;7. Enter&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;STRONG&gt;&lt;SPAN&gt;((user.roles="T-SuperAdmin"))&lt;/SPAN&gt;&amp;nbsp;&lt;/STRONG&gt;in &lt;SPAN&gt;Conditions&lt;/SPAN&gt;&lt;BR /&gt;8. Select&lt;STRONG&gt; &lt;SPAN&gt;Both in hub and QMC&lt;/SPAN&gt;&lt;/STRONG&gt; in &lt;SPAN&gt;Context&lt;/SPAN&gt;&lt;BR /&gt;9. Press &lt;SPAN&gt;Apply &lt;/SPAN&gt;button&lt;BR /&gt;10. Go to QMC &amp;gt; &lt;SPAN&gt;Users&lt;/SPAN&gt;&lt;BR /&gt;11. Select the user who has the issue and click &lt;SPAN&gt;Edit &lt;/SPAN&gt;button&lt;BR /&gt;12. Click &lt;SPAN&gt;Add role&lt;/SPAN&gt; button and select&lt;SPAN&gt;&amp;nbsp;&lt;STRONG&gt;T-SuperAdmin&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;BR /&gt;13. If any existing role or custom properties applied, please remove it&amp;nbsp;&lt;BR /&gt;14. Press &lt;SPAN&gt;Apply &lt;/SPAN&gt;button&lt;BR /&gt;15. Ask the user who reported to do the test and see if the issue will be resolved for that user&lt;BR /&gt;Note: Please also ask the user to close all of the existing browsers before start the test.&lt;/P&gt;
&lt;H4&gt;If the issue resolved:&lt;/H4&gt;
&lt;DIV&gt;Security Rule related. Please review existing security rules&lt;/DIV&gt;
&lt;DIV&gt;&amp;nbsp;&lt;/DIV&gt;
&lt;H4&gt;If the issue is not resolved:&lt;/H4&gt;
&lt;DIV&gt;&amp;nbsp;Not Security Related&lt;/DIV&gt;</description>
      <pubDate>Thu, 11 Feb 2021 09:30:10 GMT</pubDate>
      <guid>https://community.qlik.com/t5/Official-Support-Articles/Guidance-on-how-to-conclude-if-the-issue-is-Security-Rule/ta-p/1716546</guid>
      <dc:creator>Yoichi_Hirotake</dc:creator>
      <dc:date>2021-02-11T09:30:10Z</dc:date>
    </item>
  </channel>
</rss>

