<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>article Sync Active Directory users from multiple domains with Advanced LDAP - Qlik Sense Enterprise on Windows in Official Support Articles</title>
    <link>https://community.qlik.com/t5/Official-Support-Articles/Sync-Active-Directory-users-from-multiple-domains-with-Advanced/ta-p/1799273</link>
    <description>&lt;P&gt;Historically, in order to load users member from multiple Active Directory Domains was not possible with a single User Directory Connector. It was required to create one User Directory Connector per domain making the Active Directory administration more complex for the IT Team.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Starting from Qlik Sense September 2020, it is now possible to achieve this with Advanced LDAP.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Starting on Qlik Sense February 2021, multiple domain names are synchronized instead of allowing for duplicate users with the real domain name to populate when they login. (Look for&amp;nbsp;&lt;SPAN&gt;&lt;A href="https://community.qlik.com/t5/Release-Notes/Qlik-Sense-Enterprise-on-Windows-February-2021-IR-to-Patch-17/ta-p/1836015#toc-hId--522551508" target="_blank" rel="noopener"&gt;QB-2187&lt;/A&gt;)&lt;/SPAN&gt;&lt;/P&gt;
&lt;H4&gt;Environment&lt;/H4&gt;
&lt;UL&gt;
&lt;LI&gt;&lt;LI-PRODUCT title="Qlik Sense Enterprise on Windows" id="qlikSenseEnterpriseWindows"&gt;&lt;/LI-PRODUCT&gt;,&amp;nbsp;September 2020 and higher&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;div class="video-embed-center video-embed"&gt;&lt;iframe class="embedly-embed" src="https://cdn.embedly.com/widgets/media.html?src=https%3A%2F%2Fwww.youtube.com%2Fembed%2FSGm1eJKqFGo%3Ffeature%3Doembed&amp;amp;display_name=YouTube&amp;amp;url=https%3A%2F%2Fwww.youtube.com%2Fwatch%3Fv%3DSGm1eJKqFGo&amp;amp;image=https%3A%2F%2Fi.ytimg.com%2Fvi%2FSGm1eJKqFGo%2Fhqdefault.jpg&amp;amp;type=text%2Fhtml&amp;amp;schema=youtube" width="600" height="337" scrolling="no" title="Qlik Fix: Sync Active Directory users from multiple domains with Advanced LDAP" frameborder="0" allow="autoplay; fullscreen; encrypted-media; picture-in-picture;" allowfullscreen="true"&gt;&lt;/iframe&gt;&lt;/div&gt;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://community.qlik.com/t5/Qlik-Fix/Qlik-Fix-Sync-Active-Directory-users-from-multiple-domains-with/ta-p/1799891" target="_blank" rel="noopener"&gt;Click Here Video Transcript&lt;/A&gt;&lt;/P&gt;
&lt;H4&gt;Requirement(s):&lt;/H4&gt;
&lt;UL&gt;
&lt;LI&gt;Make sure there f&lt;SPAN&gt;ull trust between the different Active Directory Domains in the same forest.&lt;/SPAN&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;H4&gt;&lt;SPAN&gt;Steps:&lt;/SPAN&gt;&lt;/H4&gt;
&lt;OL&gt;
&lt;LI&gt;&lt;SPAN&gt;In one of the domain, create an Active Directory Universal Security group and add the list of users from multiple domains you want to sync into Qlik Sense.&lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;SPAN&gt;Then go to QMC -&amp;gt; User Directory Connector and create an Advanced LDAP Connection&lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI&gt;Provide a name and user directory name&lt;/LI&gt;
&lt;LI&gt;Uncheck the box “Sync user data for existing users” so that we can import new users into Qlik Sense&lt;/LI&gt;
&lt;LI&gt;In the host section, you will need to point to the Global Catalog port which is 3268 for LDAP and 3269 for LDAPS by default so that the sync can capture user through the entire forest.&lt;/LI&gt;
&lt;LI&gt;Add a username and password to connect to the Global Catalog.&lt;/LI&gt;
&lt;LI&gt;The base DN here is important as it needs to refer to the forest name in order to navigate through the child domains.&lt;/LI&gt;
&lt;LI&gt;You can then add an LDAP filter to load the user member of the group you created earlier. Make sure that the rootAdmin accounts used to manage Qlik Sense are not excluded by the new LDAP filter. More information under&amp;nbsp;&lt;A href="https://community.qlik.com/t5/Knowledge-Base/How-to-avoid-the-RootAdmin-s-from-becoming-inactive/ta-p/1715558" target="_blank" rel="noopener"&gt;How to avoid the RootAdmin(s) from becoming inactive &lt;/A&gt;&amp;nbsp;&lt;/LI&gt;
&lt;LI&gt;And finally you will need to change in the Directory entry attributes the &lt;STRONG&gt;User identifier&lt;/STRONG&gt;&amp;nbsp;from “&lt;FONT face="courier new,courier"&gt;inetOrgPerson&lt;/FONT&gt;” to “&lt;FONT face="courier new,courier"&gt;person&lt;/FONT&gt;”. This is specific to Active Directory.&amp;nbsp;&lt;/LI&gt;
&lt;/OL&gt;
&lt;P&gt;It is now time to run the synchronization and check that your users are imported.&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Bastien_Laugiero_0-1618374041352.png" style="width: 459px;"&gt;&lt;img src="https://community.qlik.com/t5/image/serverpage/image-id/52952i77EF35867CC033C3/image-dimensions/459x367?v=v2" width="459" height="367" role="button" title="Bastien_Laugiero_0-1618374041352.png" alt="Bastien_Laugiero_0-1618374041352.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P style="font-style: italic;"&gt;The information in this article is provided as-is and to be used at own discretion. Depending on tool(s) used, customization(s), and/or other factors ongoing support on the solution above may not be provided by Qlik Support.&lt;/P&gt;
&lt;P style="font-style: italic;"&gt;&amp;nbsp;&lt;/P&gt;
&lt;H3&gt;Related Content&amp;nbsp;&lt;/H3&gt;
&lt;UL&gt;
&lt;LI&gt;&lt;A href="https://community.qlik.com/t5/Knowledge-Base/Qlik-Sense-on-Windows-Configuring-and-testing-LDAP-filters-for/ta-p/1713947" target="_blank" rel="noopener"&gt;Qlik Sense on Windows: Configuring and testing LDAP filters for User Directory Connector&lt;/A&gt;&amp;nbsp;&lt;/LI&gt;
&lt;LI&gt;&lt;A style="font-family: inherit; background-color: #ffffff;" href="https://help.qlik.com/en-US/sense-admin/Subsystems/DeployAdministerQSE/Content/Sense_DeployAdminister/QSEoW/Administer_QSEoW/Managing_QSEoW/user-directory-connectors-advanced-LDAP-properties.htm" target="_blank" rel="noopener"&gt;User directory connectors Advanced LDAP properties - Qlik Sense for administrators&lt;/A&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;A style="font-family: inherit; background-color: #ffffff;" href="https://community.qlik.com/t5/Knowledge-Base/Qlik-Sense-Example-of-a-LDAP-filter-to-sync-users-in-a-group/ta-p/1713735" target="_blank" rel="noopener"&gt;Qlik Sense : Example of a LDAP filter to sync users in a group&lt;/A&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Thu, 02 Jun 2022 10:27:33 GMT</pubDate>
    <dc:creator>Bastien_Laugiero</dc:creator>
    <dc:date>2022-06-02T10:27:33Z</dc:date>
    <item>
      <title>Sync Active Directory users from multiple domains with Advanced LDAP - Qlik Sense Enterprise on Windows</title>
      <link>https://community.qlik.com/t5/Official-Support-Articles/Sync-Active-Directory-users-from-multiple-domains-with-Advanced/ta-p/1799273</link>
      <description>&lt;P&gt;Historically, in order to load users member from multiple Active Directory Domains was not possible with a single User Directory Connector. It was required to create one User Directory Connector per domain making the Active Directory administration more complex for the IT Team.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Starting from Qlik Sense September 2020, it is now possible to achieve this with Advanced LDAP.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Starting on Qlik Sense February 2021, multiple domain names are synchronized instead of allowing for duplicate users with the real domain name to populate when they login. (Look for&amp;nbsp;&lt;SPAN&gt;&lt;A href="https://community.qlik.com/t5/Release-Notes/Qlik-Sense-Enterprise-on-Windows-February-2021-IR-to-Patch-17/ta-p/1836015#toc-hId--522551508" target="_blank" rel="noopener"&gt;QB-2187&lt;/A&gt;)&lt;/SPAN&gt;&lt;/P&gt;
&lt;H4&gt;Environment&lt;/H4&gt;
&lt;UL&gt;
&lt;LI&gt;&lt;LI-PRODUCT title="Qlik Sense Enterprise on Windows" id="qlikSenseEnterpriseWindows"&gt;&lt;/LI-PRODUCT&gt;,&amp;nbsp;September 2020 and higher&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;div class="video-embed-center video-embed"&gt;&lt;iframe class="embedly-embed" src="https://cdn.embedly.com/widgets/media.html?src=https%3A%2F%2Fwww.youtube.com%2Fembed%2FSGm1eJKqFGo%3Ffeature%3Doembed&amp;amp;display_name=YouTube&amp;amp;url=https%3A%2F%2Fwww.youtube.com%2Fwatch%3Fv%3DSGm1eJKqFGo&amp;amp;image=https%3A%2F%2Fi.ytimg.com%2Fvi%2FSGm1eJKqFGo%2Fhqdefault.jpg&amp;amp;type=text%2Fhtml&amp;amp;schema=youtube" width="600" height="337" scrolling="no" title="Qlik Fix: Sync Active Directory users from multiple domains with Advanced LDAP" frameborder="0" allow="autoplay; fullscreen; encrypted-media; picture-in-picture;" allowfullscreen="true"&gt;&lt;/iframe&gt;&lt;/div&gt;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://community.qlik.com/t5/Qlik-Fix/Qlik-Fix-Sync-Active-Directory-users-from-multiple-domains-with/ta-p/1799891" target="_blank" rel="noopener"&gt;Click Here Video Transcript&lt;/A&gt;&lt;/P&gt;
&lt;H4&gt;Requirement(s):&lt;/H4&gt;
&lt;UL&gt;
&lt;LI&gt;Make sure there f&lt;SPAN&gt;ull trust between the different Active Directory Domains in the same forest.&lt;/SPAN&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;H4&gt;&lt;SPAN&gt;Steps:&lt;/SPAN&gt;&lt;/H4&gt;
&lt;OL&gt;
&lt;LI&gt;&lt;SPAN&gt;In one of the domain, create an Active Directory Universal Security group and add the list of users from multiple domains you want to sync into Qlik Sense.&lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;SPAN&gt;Then go to QMC -&amp;gt; User Directory Connector and create an Advanced LDAP Connection&lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI&gt;Provide a name and user directory name&lt;/LI&gt;
&lt;LI&gt;Uncheck the box “Sync user data for existing users” so that we can import new users into Qlik Sense&lt;/LI&gt;
&lt;LI&gt;In the host section, you will need to point to the Global Catalog port which is 3268 for LDAP and 3269 for LDAPS by default so that the sync can capture user through the entire forest.&lt;/LI&gt;
&lt;LI&gt;Add a username and password to connect to the Global Catalog.&lt;/LI&gt;
&lt;LI&gt;The base DN here is important as it needs to refer to the forest name in order to navigate through the child domains.&lt;/LI&gt;
&lt;LI&gt;You can then add an LDAP filter to load the user member of the group you created earlier. Make sure that the rootAdmin accounts used to manage Qlik Sense are not excluded by the new LDAP filter. More information under&amp;nbsp;&lt;A href="https://community.qlik.com/t5/Knowledge-Base/How-to-avoid-the-RootAdmin-s-from-becoming-inactive/ta-p/1715558" target="_blank" rel="noopener"&gt;How to avoid the RootAdmin(s) from becoming inactive &lt;/A&gt;&amp;nbsp;&lt;/LI&gt;
&lt;LI&gt;And finally you will need to change in the Directory entry attributes the &lt;STRONG&gt;User identifier&lt;/STRONG&gt;&amp;nbsp;from “&lt;FONT face="courier new,courier"&gt;inetOrgPerson&lt;/FONT&gt;” to “&lt;FONT face="courier new,courier"&gt;person&lt;/FONT&gt;”. This is specific to Active Directory.&amp;nbsp;&lt;/LI&gt;
&lt;/OL&gt;
&lt;P&gt;It is now time to run the synchronization and check that your users are imported.&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Bastien_Laugiero_0-1618374041352.png" style="width: 459px;"&gt;&lt;img src="https://community.qlik.com/t5/image/serverpage/image-id/52952i77EF35867CC033C3/image-dimensions/459x367?v=v2" width="459" height="367" role="button" title="Bastien_Laugiero_0-1618374041352.png" alt="Bastien_Laugiero_0-1618374041352.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P style="font-style: italic;"&gt;The information in this article is provided as-is and to be used at own discretion. Depending on tool(s) used, customization(s), and/or other factors ongoing support on the solution above may not be provided by Qlik Support.&lt;/P&gt;
&lt;P style="font-style: italic;"&gt;&amp;nbsp;&lt;/P&gt;
&lt;H3&gt;Related Content&amp;nbsp;&lt;/H3&gt;
&lt;UL&gt;
&lt;LI&gt;&lt;A href="https://community.qlik.com/t5/Knowledge-Base/Qlik-Sense-on-Windows-Configuring-and-testing-LDAP-filters-for/ta-p/1713947" target="_blank" rel="noopener"&gt;Qlik Sense on Windows: Configuring and testing LDAP filters for User Directory Connector&lt;/A&gt;&amp;nbsp;&lt;/LI&gt;
&lt;LI&gt;&lt;A style="font-family: inherit; background-color: #ffffff;" href="https://help.qlik.com/en-US/sense-admin/Subsystems/DeployAdministerQSE/Content/Sense_DeployAdminister/QSEoW/Administer_QSEoW/Managing_QSEoW/user-directory-connectors-advanced-LDAP-properties.htm" target="_blank" rel="noopener"&gt;User directory connectors Advanced LDAP properties - Qlik Sense for administrators&lt;/A&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;A style="font-family: inherit; background-color: #ffffff;" href="https://community.qlik.com/t5/Knowledge-Base/Qlik-Sense-Example-of-a-LDAP-filter-to-sync-users-in-a-group/ta-p/1713735" target="_blank" rel="noopener"&gt;Qlik Sense : Example of a LDAP filter to sync users in a group&lt;/A&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 02 Jun 2022 10:27:33 GMT</pubDate>
      <guid>https://community.qlik.com/t5/Official-Support-Articles/Sync-Active-Directory-users-from-multiple-domains-with-Advanced/ta-p/1799273</guid>
      <dc:creator>Bastien_Laugiero</dc:creator>
      <dc:date>2022-06-02T10:27:33Z</dc:date>
    </item>
    <item>
      <title>Re: Sync Active Directory users from multiple domains with Advanced LDAP - Qlik Sense Enterprise on Windows</title>
      <link>https://community.qlik.com/t5/Official-Support-Articles/Sync-Active-Directory-users-from-multiple-domains-with-Advanced/tac-p/1849282#M4589</link>
      <description>&lt;P&gt;Hello&amp;nbsp;&lt;a href="https://community.qlik.com/t5/user/viewprofilepage/user-id/2019"&gt;@Bastien_Laugiero&lt;/a&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;thank you very much for this great article.&lt;/P&gt;
&lt;P&gt;I'm trying to use this advanced Ldap connector in my customer environement, and i always get the same error in the log file :&lt;/P&gt;
&lt;DIV&gt;Exception when fetching data from 'MyDomain' of type Repository.UserDirectoryConnectors.LDAP.AdvancedLDAP &lt;STRONG&gt;The size limit was exceeded&lt;/STRONG&gt;↵↓Couldn't retrieve users from directory: 'MyDomain' of type Repository.UserDirectoryConnectors.LDAP.AdvancedLDAP&lt;/DIV&gt;
&lt;DIV&gt;&amp;nbsp;&lt;/DIV&gt;
&lt;DIV&gt;even with an ldap filter that send very few users, it is the same. What size are we talking about here ?&lt;/DIV&gt;
&lt;DIV&gt;Have a goo dat.&lt;/DIV&gt;
&lt;DIV&gt;&amp;nbsp;&lt;/DIV&gt;
&lt;DIV&gt;Johann&lt;/DIV&gt;</description>
      <pubDate>Wed, 20 Oct 2021 09:16:59 GMT</pubDate>
      <guid>https://community.qlik.com/t5/Official-Support-Articles/Sync-Active-Directory-users-from-multiple-domains-with-Advanced/tac-p/1849282#M4589</guid>
      <dc:creator>jchoucq</dc:creator>
      <dc:date>2021-10-20T09:16:59Z</dc:date>
    </item>
    <item>
      <title>Re: Sync Active Directory users from multiple domains with Advanced LDAP - Qlik Sense Enterprise on Windows</title>
      <link>https://community.qlik.com/t5/Official-Support-Articles/Sync-Active-Directory-users-from-multiple-domains-with-Advanced/tac-p/1849394#M4592</link>
      <description>&lt;P&gt;Hello&amp;nbsp;&lt;a href="https://community.qlik.com/t5/user/viewprofilepage/user-id/14334"&gt;@jchoucq&lt;/a&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;This is dependent on the source.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;On the Qlik end you can set advanced UDC settings, see&amp;nbsp;&lt;A href="https://help.qlik.com/en-US/sense-admin/August2021/Subsystems/DeployAdministerQSE/Content/Sense_DeployAdminister/QSEoW/Administer_QSEoW/Managing_QSEoW/user-directory-connectors-advanced-LDAP-properties.htm#anchor-4" target="_self"&gt;Advanced UDC Settings&lt;/A&gt;&amp;nbsp;for details.&lt;/P&gt;</description>
      <pubDate>Wed, 20 Oct 2021 11:54:10 GMT</pubDate>
      <guid>https://community.qlik.com/t5/Official-Support-Articles/Sync-Active-Directory-users-from-multiple-domains-with-Advanced/tac-p/1849394#M4592</guid>
      <dc:creator>Sonja_Bauernfeind</dc:creator>
      <dc:date>2021-10-20T11:54:10Z</dc:date>
    </item>
    <item>
      <title>Re: Sync Active Directory users from multiple domains with Advanced LDAP - Qlik Sense Enterprise on Windows</title>
      <link>https://community.qlik.com/t5/Official-Support-Articles/Sync-Active-Directory-users-from-multiple-domains-with-Advanced/tac-p/1849418#M4597</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.qlik.com/t5/user/viewprofilepage/user-id/28597"&gt;@Sonja_Bauernfeind&lt;/a&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;thanks for your answer. Yes, we tried, among other things, to change&amp;nbsp;&lt;SPAN&gt;Page size (2000, or 4000 ...)&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;We are connecting to an active directory global catalog, and the experts with me do not understand either this limit size error message &lt;span class="lia-unicode-emoji" title=":disappointed_face:"&gt;😞&lt;/span&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 20 Oct 2021 12:20:29 GMT</pubDate>
      <guid>https://community.qlik.com/t5/Official-Support-Articles/Sync-Active-Directory-users-from-multiple-domains-with-Advanced/tac-p/1849418#M4597</guid>
      <dc:creator>jchoucq</dc:creator>
      <dc:date>2021-10-20T12:20:29Z</dc:date>
    </item>
    <item>
      <title>Re: Sync Active Directory users from multiple domains with Advanced LDAP - Qlik Sense Enterprise on Windows</title>
      <link>https://community.qlik.com/t5/Official-Support-Articles/Sync-Active-Directory-users-from-multiple-domains-with-Advanced/tac-p/1849435#M4598</link>
      <description>&lt;P&gt;&lt;STRIKE&gt;Let me see if I can get an SME to give this a look&lt;/STRIKE&gt;, This is what we have on that issue for you: &lt;A href="https://community.qlik.com/t5/Knowledge/How-to-configire-Maxpagesize-in-LDAP-server-to-avoid-a-quot-The/ta-p/1835014" target="_self"&gt;How to configire Maxpagesize in LDAP server to avoid a "The size limit was exceeded" or a "QVX_UNEXPECTED_END_OF_DATA" error message&lt;/A&gt;&amp;nbsp; - but if that does not help, I'd recommend posting the question over in the relevant forums where you can make use of our active community and our agents. Think this one is the right one:&amp;nbsp;&amp;nbsp;&lt;A href="https://community.qlik.com/t5/Deployment-Management/bd-p/qlik-sense-deployment" target="_blank" rel="noopener"&gt;Deployment and Management&lt;/A&gt;.&lt;/P&gt;</description>
      <pubDate>Wed, 20 Oct 2021 12:41:27 GMT</pubDate>
      <guid>https://community.qlik.com/t5/Official-Support-Articles/Sync-Active-Directory-users-from-multiple-domains-with-Advanced/tac-p/1849435#M4598</guid>
      <dc:creator>Sonja_Bauernfeind</dc:creator>
      <dc:date>2021-10-20T12:41:27Z</dc:date>
    </item>
    <item>
      <title>Re: Sync Active Directory users from multiple domains with Advanced LDAP - Qlik Sense Enterprise on Windows</title>
      <link>https://community.qlik.com/t5/Official-Support-Articles/Sync-Active-Directory-users-from-multiple-domains-with-Advanced/tac-p/1849453#M4600</link>
      <description>&lt;P&gt;Thanks a lot&amp;nbsp;&lt;a href="https://community.qlik.com/t5/user/viewprofilepage/user-id/28597"&gt;@Sonja_Bauernfeind&lt;/a&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I saw this article yesterday, i'm going to insist on my client to take a closer look at it.&lt;/P&gt;
&lt;P&gt;For information i already created a message on the partner teams. Do you think it will be better to post the question in the forum too ?&lt;/P&gt;
&lt;P&gt;Thanks again.&lt;/P&gt;
&lt;P&gt;Johann&lt;/P&gt;</description>
      <pubDate>Wed, 20 Oct 2021 12:47:55 GMT</pubDate>
      <guid>https://community.qlik.com/t5/Official-Support-Articles/Sync-Active-Directory-users-from-multiple-domains-with-Advanced/tac-p/1849453#M4600</guid>
      <dc:creator>jchoucq</dc:creator>
      <dc:date>2021-10-20T12:47:55Z</dc:date>
    </item>
    <item>
      <title>Re: Sync Active Directory users from multiple domains with Advanced LDAP - Qlik Sense Enterprise on Windows</title>
      <link>https://community.qlik.com/t5/Official-Support-Articles/Sync-Active-Directory-users-from-multiple-domains-with-Advanced/tac-p/1849522#M4602</link>
      <description>&lt;P&gt;I think the forums are always a great idea! You'll get the input from a lot more people there.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 20 Oct 2021 13:55:36 GMT</pubDate>
      <guid>https://community.qlik.com/t5/Official-Support-Articles/Sync-Active-Directory-users-from-multiple-domains-with-Advanced/tac-p/1849522#M4602</guid>
      <dc:creator>Sonja_Bauernfeind</dc:creator>
      <dc:date>2021-10-20T13:55:36Z</dc:date>
    </item>
    <item>
      <title>Re: Sync Active Directory users from multiple domains with Advanced LDAP - Qlik Sense Enterprise on Windows</title>
      <link>https://community.qlik.com/t5/Official-Support-Articles/Sync-Active-Directory-users-from-multiple-domains-with-Advanced/tac-p/1849901#M4613</link>
      <description>&lt;P&gt;just did it &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://community.qlik.com/t5/Deployment-Management/Sync-Active-Directory-users-from-multiple-domains-with-Advanced/m-p/1849899" target="_blank"&gt;https://community.qlik.com/t5/Deployment-Management/Sync-Active-Directory-users-from-multiple-domains-with-Advanced/m-p/1849899&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;thanks a lot&amp;nbsp;&lt;a href="https://community.qlik.com/t5/user/viewprofilepage/user-id/28597"&gt;@Sonja_Bauernfeind&lt;/a&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 21 Oct 2021 07:49:53 GMT</pubDate>
      <guid>https://community.qlik.com/t5/Official-Support-Articles/Sync-Active-Directory-users-from-multiple-domains-with-Advanced/tac-p/1849901#M4613</guid>
      <dc:creator>jchoucq</dc:creator>
      <dc:date>2021-10-21T07:49:53Z</dc:date>
    </item>
    <item>
      <title>Re: Sync Active Directory users from multiple domains with Advanced LDAP - Qlik Sense Enterprise on Windows</title>
      <link>https://community.qlik.com/t5/Official-Support-Articles/Sync-Active-Directory-users-from-multiple-domains-with-Advanced/tac-p/1850566#M4628</link>
      <description>&lt;P&gt;For information, i noticed that the Ldap Filter you add in the "Search Ldap Filter" property is not exactly what will be executed by Qlik Sense. Let's assume we write "&lt;STRONG&gt;MyLdapFilter&lt;/STRONG&gt;", here is what we can find in debug log file :&amp;nbsp;&lt;/P&gt;
&lt;DIV&gt;(|(&amp;amp;(objectClass=person)(&lt;STRONG&gt;MyLdapFilter&lt;/STRONG&gt;))(objectClass=group))&lt;/DIV&gt;
&lt;DIV&gt;&amp;nbsp;&lt;/DIV&gt;
&lt;DIV&gt;this is a problem in my case, because this filter gets backs too many groups i never asked for !&lt;/DIV&gt;
&lt;DIV&gt;&amp;nbsp;&lt;/DIV&gt;
&lt;DIV&gt;Surprising, this is not the same&amp;nbsp;&lt;SPAN style="font-family: inherit;"&gt;behaviour with Active Directory connector which change your Ldap filter in&amp;nbsp;&lt;/SPAN&gt;&lt;/DIV&gt;
&lt;DIV&gt;
&lt;DIV&gt;(&amp;amp;(objectCategory=person)(&lt;STRONG&gt;MyLdapFilter&lt;/STRONG&gt;))&lt;/DIV&gt;
&lt;DIV&gt;&amp;nbsp;&lt;/DIV&gt;
&lt;DIV&gt;&lt;a href="https://community.qlik.com/t5/user/viewprofilepage/user-id/28597"&gt;@Sonja_Bauernfeind&lt;/a&gt;&amp;nbsp;&lt;a href="https://community.qlik.com/t5/user/viewprofilepage/user-id/2019"&gt;@Bastien_Laugiero&lt;/a&gt;&amp;nbsp;have you got an idea of what can be done to try to fix that ?&lt;/DIV&gt;
&lt;DIV&gt;Thanks a lot.&lt;/DIV&gt;
&lt;DIV&gt;johann&lt;/DIV&gt;
&lt;/DIV&gt;</description>
      <pubDate>Fri, 22 Oct 2021 09:54:04 GMT</pubDate>
      <guid>https://community.qlik.com/t5/Official-Support-Articles/Sync-Active-Directory-users-from-multiple-domains-with-Advanced/tac-p/1850566#M4628</guid>
      <dc:creator>jchoucq</dc:creator>
      <dc:date>2021-10-22T09:54:04Z</dc:date>
    </item>
    <item>
      <title>Re: Sync Active Directory users from multiple domains with Advanced LDAP - Qlik Sense Enterprise on Windows</title>
      <link>https://community.qlik.com/t5/Official-Support-Articles/Sync-Active-Directory-users-from-multiple-domains-with-Advanced/tac-p/1852529#M4670</link>
      <description>&lt;P&gt;The "|"&amp;nbsp; and "&lt;SPAN&gt;(objectClass=group)" is added by design when you use Active Directory to get all the Group Attribute.&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;In recent version there is an option called "Use optimized query" to change the mode to retrive the Groups in case you use instead Generic LDAP or Advanced LDAP UDC Configuration.&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;If with the Generic/Advanced LDAP configuration and the option "Use Optimized query" you still don't get all the attribute for the page size issue an alternate SSO / UDC could be evaluated/studied with our Professional Services.&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 27 Oct 2021 13:14:54 GMT</pubDate>
      <guid>https://community.qlik.com/t5/Official-Support-Articles/Sync-Active-Directory-users-from-multiple-domains-with-Advanced/tac-p/1852529#M4670</guid>
      <dc:creator>Filippo_Nicolussi_P</dc:creator>
      <dc:date>2021-10-27T13:14:54Z</dc:date>
    </item>
    <item>
      <title>Re: Sync Active Directory users from multiple domains with Advanced LDAP - Qlik Sense Enterprise on Windows</title>
      <link>https://community.qlik.com/t5/Official-Support-Articles/Sync-Active-Directory-users-from-multiple-domains-with-Advanced/tac-p/1852636#M4674</link>
      <description>&lt;P&gt;hi&amp;nbsp;&lt;a href="https://community.qlik.com/t5/user/viewprofilepage/user-id/36623"&gt;@Filippo_Nicolussi_P&lt;/a&gt;&amp;nbsp;, thank you very much for your answer.&lt;/P&gt;
&lt;P&gt;With the propery "&lt;SPAN&gt;optimized query" we go further in the process, but at the end we still get an error.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;indeed, ti seems that they are many steps, first, it adds users respecting the filter, that is correct. But after, for the groups, it seems looping to get all the groups from the groups it detected in the precedent ldap request, regardless the initial filter.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;In our case, this is why it goes over the page size ... the customer ldap experts do not understand why, as what is done for users, the groups it tries to get back do not respect the initial LDAP Filter.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;Thanks again&lt;/P&gt;
&lt;P&gt;Johann&lt;/P&gt;</description>
      <pubDate>Wed, 27 Oct 2021 15:25:45 GMT</pubDate>
      <guid>https://community.qlik.com/t5/Official-Support-Articles/Sync-Active-Directory-users-from-multiple-domains-with-Advanced/tac-p/1852636#M4674</guid>
      <dc:creator>jchoucq</dc:creator>
      <dc:date>2021-10-27T15:25:45Z</dc:date>
    </item>
    <item>
      <title>Re: Sync Active Directory users from multiple domains with Advanced LDAP - Qlik Sense Enterprise on Windows</title>
      <link>https://community.qlik.com/t5/Official-Support-Articles/Sync-Active-Directory-users-from-multiple-domains-with-Advanced/tac-p/1852708#M4675</link>
      <description>&lt;P&gt;Hi Johann&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Just a little follow-up on a Active Directory perspective; based on the official site&amp;nbsp;&lt;A href="https://docs.microsoft.com/en-US/troubleshoot/windows-server/identity/domain-controller-returns-500-values-ldap-response" target="_blank"&gt;DC returns only 5000 values in LDAP response - Windows Server | Microsoft Docs&lt;/A&gt;&amp;nbsp;there are some hardcoded limitations introduced:&lt;/P&gt;
&lt;P&gt;"&lt;SPAN&gt;Internal LDAP limitations have been introduced in Windows Server 2008 R2 and Windows Server 2008 to prevent overloading the domain controller. These limits overwrite the LDAP policy setting when the policy value should be higher"&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;with hardcoded&amp;nbsp;&lt;SPAN&gt;MaxPageSize=20000 and MaxValRange=5000&amp;nbsp; .&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Many thanks. &lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Filippo&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 27 Oct 2021 18:36:32 GMT</pubDate>
      <guid>https://community.qlik.com/t5/Official-Support-Articles/Sync-Active-Directory-users-from-multiple-domains-with-Advanced/tac-p/1852708#M4675</guid>
      <dc:creator>Filippo_Nicolussi_P</dc:creator>
      <dc:date>2021-10-27T18:36:32Z</dc:date>
    </item>
    <item>
      <title>Re: Sync Active Directory users from multiple domains with Advanced LDAP - Qlik Sense Enterprise on Windows</title>
      <link>https://community.qlik.com/t5/Official-Support-Articles/Sync-Active-Directory-users-from-multiple-domains-with-Advanced/tac-p/1854668#M4719</link>
      <description>&lt;P&gt;Thank you&amp;nbsp;&lt;a href="https://community.qlik.com/t5/user/viewprofilepage/user-id/36623"&gt;@Filippo_Nicolussi_P&lt;/a&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;For a specific need my customer changed the MaxPageSize in the past to 30000, but even with this high threshold, this is not enough in our context.&lt;/P&gt;
&lt;P&gt;With the "use optimized query", in the debug log, in can find than the last ldap filter executed by qlik sense is&amp;nbsp;(objectClass=group) what seems far too broad and not in line with what we asked for.&lt;/P&gt;
&lt;P&gt;Johann&lt;/P&gt;</description>
      <pubDate>Tue, 02 Nov 2021 13:12:58 GMT</pubDate>
      <guid>https://community.qlik.com/t5/Official-Support-Articles/Sync-Active-Directory-users-from-multiple-domains-with-Advanced/tac-p/1854668#M4719</guid>
      <dc:creator>jchoucq</dc:creator>
      <dc:date>2021-11-02T13:12:58Z</dc:date>
    </item>
    <item>
      <title>Re: Sync Active Directory users from multiple domains with Advanced LDAP - Qlik Sense Enterprise on Windows</title>
      <link>https://community.qlik.com/t5/Official-Support-Articles/Sync-Active-Directory-users-from-multiple-domains-with-Advanced/tac-p/2006163#M7808</link>
      <description>&lt;P&gt;Thank you for the article and details. What I would like to know is once this has been setup will the users get a SSO experience or be prompted to enter username and password depending on the domains?&lt;/P&gt;
&lt;P&gt;Alternatively what I'm trying to do is have an SSO experience for two domains - is this possible? It is currently SSO for the domain the Server is installed with, but not for Domain B&lt;/P&gt;
&lt;P&gt;Thanks&lt;/P&gt;
&lt;P&gt;Rakesh&lt;/P&gt;</description>
      <pubDate>Fri, 18 Nov 2022 00:10:03 GMT</pubDate>
      <guid>https://community.qlik.com/t5/Official-Support-Articles/Sync-Active-Directory-users-from-multiple-domains-with-Advanced/tac-p/2006163#M7808</guid>
      <dc:creator>rakeshshah</dc:creator>
      <dc:date>2022-11-18T00:10:03Z</dc:date>
    </item>
    <item>
      <title>Re: Sync Active Directory users from multiple domains with Advanced LDAP - Qlik Sense Enterprise on Windows</title>
      <link>https://community.qlik.com/t5/Official-Support-Articles/Sync-Active-Directory-users-from-multiple-domains-with-Advanced/tac-p/2008004#M7849</link>
      <description>&lt;P&gt;Hello&amp;nbsp;&lt;a href="https://community.qlik.com/t5/user/viewprofilepage/user-id/27488"&gt;@rakeshshah&lt;/a&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Authentication in this case is still being carried out by Windows and if Windows requires a prompt, a prompt will be displayed. You would likely need to build an independent single sign on system in front of both domains to achieve this.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Please post about your requirements in our forums:&amp;nbsp;&lt;A href="https://community.qlik.com/t5/Deployment-Management/bd-p/qlik-sense-deployment" target="_blank" rel="noopener"&gt;Deployment and Management&lt;/A&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;All the best,&lt;BR /&gt;Sonja&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 23 Nov 2022 08:43:08 GMT</pubDate>
      <guid>https://community.qlik.com/t5/Official-Support-Articles/Sync-Active-Directory-users-from-multiple-domains-with-Advanced/tac-p/2008004#M7849</guid>
      <dc:creator>Sonja_Bauernfeind</dc:creator>
      <dc:date>2022-11-23T08:43:08Z</dc:date>
    </item>
  </channel>
</rss>

