<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>article Multi-cloud deployment: difference between using  an Identity Provider (IdP) and a Local Bearer Token in Official Support Articles</title>
    <link>https://community.qlik.com/t5/Official-Support-Articles/Multi-cloud-deployment-difference-between-using-an-Identity/ta-p/1803844</link>
    <description>&lt;DIV class="lia-message-template-question-zone"&gt;
&lt;H4&gt;Question:&lt;/H4&gt;
&lt;P&gt;The &lt;A href="https://help.qlik.com/en-US/sense-admin/latest/Subsystems/DeployAdministerQSE/Content/Sense_DeployAdminister/Multi-Cloud/Cloud-deployment.htm" target="_blank" rel="noopener"&gt;help site for Qlik Sense Enterprise for Windows mentions&lt;/A&gt;, among the&amp;nbsp;&lt;SPAN&gt;characteristics of a multi-cloud deployment, "an identity provider that supports OIDC and SAML to integrate user authentication between on-premises and cloud, &lt;STRONG&gt;or&lt;/STRONG&gt; a local bearer token".&lt;BR /&gt;What is the difference between the two options?&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Environment:&lt;/STRONG&gt;&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;&lt;LI-PRODUCT title="Qlik Sense Enterprise SaaS" id="qlikSenseEnterpriseSaaS"&gt;&lt;/LI-PRODUCT&gt;&amp;nbsp; with &lt;LI-PRODUCT title="Qlik Sense Enterprise on Windows" id="qlikSenseEnterpriseWindows"&gt;&lt;/LI-PRODUCT&gt;&amp;nbsp; multi-cloud setup&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;/DIV&gt;
&lt;DIV class="lia-message-template-answer-zone"&gt;
&lt;H4&gt;Answer:&lt;/H4&gt;
&lt;P&gt;While it's not necessary to have an identity provider (check the &lt;A href="https://community.qlik.com/t5/Knowledge-Base/Qlik-Multi-Cloud-Frequently-Asked-Questions-FAQ/ta-p/1713427" target="_blank" rel="noopener"&gt;Multi-Cloud FAQ&lt;/A&gt; for more details), that is the recommended option for having a fully integrated set-up, where users are shared between the on-premise and SaaS environments. &lt;BR /&gt;Here are the main differences:&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;Identity Provider (IdP)
&lt;UL class="lia-list-style-type-circle"&gt;
&lt;LI&gt;no duplicated users, which means that one person will only consume one license allocation&lt;/LI&gt;
&lt;LI&gt;a central repository for all users, integrated between environments&lt;/LI&gt;
&lt;LI&gt;it requires getting the service from a third party (generally at a cost) and implementing a solution&lt;BR /&gt;&lt;BR /&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;/LI&gt;
&lt;LI&gt;Local Bearer Token
&lt;UL class="lia-list-style-type-circle"&gt;
&lt;LI&gt;can be used immediately, without having an Identity Provider&lt;/LI&gt;
&lt;LI&gt;easy setup&lt;/LI&gt;
&lt;LI&gt;separate set of user repositories. Typically: Active Directory for on-premise access and QlikID for SaaS access&lt;STRONG&gt;*&lt;/STRONG&gt;&lt;/LI&gt;
&lt;LI&gt;the same person will use two license allocations when accessing SaaS and on-premise applications&lt;/LI&gt;
&lt;/UL&gt;
&lt;/LI&gt;
&lt;/UL&gt;
&lt;P class="lia-indent-padding-left-60px"&gt;&lt;EM&gt;&lt;STRONG&gt;*&lt;/STRONG&gt; For some companies this might actually be a preferred choice (e.g.: granting SaaS access to external users authenticating with QlikID, and keeping the on premise version for internal ones on AD)&lt;/EM&gt;&lt;/P&gt;
&lt;/DIV&gt;</description>
    <pubDate>Tue, 10 May 2022 18:59:01 GMT</pubDate>
    <dc:creator>Daniele_Purrone</dc:creator>
    <dc:date>2022-05-10T18:59:01Z</dc:date>
    <item>
      <title>Multi-cloud deployment: difference between using  an Identity Provider (IdP) and a Local Bearer Token</title>
      <link>https://community.qlik.com/t5/Official-Support-Articles/Multi-cloud-deployment-difference-between-using-an-Identity/ta-p/1803844</link>
      <description>&lt;DIV class="lia-message-template-question-zone"&gt;
&lt;H4&gt;Question:&lt;/H4&gt;
&lt;P&gt;The &lt;A href="https://help.qlik.com/en-US/sense-admin/latest/Subsystems/DeployAdministerQSE/Content/Sense_DeployAdminister/Multi-Cloud/Cloud-deployment.htm" target="_blank" rel="noopener"&gt;help site for Qlik Sense Enterprise for Windows mentions&lt;/A&gt;, among the&amp;nbsp;&lt;SPAN&gt;characteristics of a multi-cloud deployment, "an identity provider that supports OIDC and SAML to integrate user authentication between on-premises and cloud, &lt;STRONG&gt;or&lt;/STRONG&gt; a local bearer token".&lt;BR /&gt;What is the difference between the two options?&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Environment:&lt;/STRONG&gt;&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;&lt;LI-PRODUCT title="Qlik Sense Enterprise SaaS" id="qlikSenseEnterpriseSaaS"&gt;&lt;/LI-PRODUCT&gt;&amp;nbsp; with &lt;LI-PRODUCT title="Qlik Sense Enterprise on Windows" id="qlikSenseEnterpriseWindows"&gt;&lt;/LI-PRODUCT&gt;&amp;nbsp; multi-cloud setup&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;/DIV&gt;
&lt;DIV class="lia-message-template-answer-zone"&gt;
&lt;H4&gt;Answer:&lt;/H4&gt;
&lt;P&gt;While it's not necessary to have an identity provider (check the &lt;A href="https://community.qlik.com/t5/Knowledge-Base/Qlik-Multi-Cloud-Frequently-Asked-Questions-FAQ/ta-p/1713427" target="_blank" rel="noopener"&gt;Multi-Cloud FAQ&lt;/A&gt; for more details), that is the recommended option for having a fully integrated set-up, where users are shared between the on-premise and SaaS environments. &lt;BR /&gt;Here are the main differences:&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;Identity Provider (IdP)
&lt;UL class="lia-list-style-type-circle"&gt;
&lt;LI&gt;no duplicated users, which means that one person will only consume one license allocation&lt;/LI&gt;
&lt;LI&gt;a central repository for all users, integrated between environments&lt;/LI&gt;
&lt;LI&gt;it requires getting the service from a third party (generally at a cost) and implementing a solution&lt;BR /&gt;&lt;BR /&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;/LI&gt;
&lt;LI&gt;Local Bearer Token
&lt;UL class="lia-list-style-type-circle"&gt;
&lt;LI&gt;can be used immediately, without having an Identity Provider&lt;/LI&gt;
&lt;LI&gt;easy setup&lt;/LI&gt;
&lt;LI&gt;separate set of user repositories. Typically: Active Directory for on-premise access and QlikID for SaaS access&lt;STRONG&gt;*&lt;/STRONG&gt;&lt;/LI&gt;
&lt;LI&gt;the same person will use two license allocations when accessing SaaS and on-premise applications&lt;/LI&gt;
&lt;/UL&gt;
&lt;/LI&gt;
&lt;/UL&gt;
&lt;P class="lia-indent-padding-left-60px"&gt;&lt;EM&gt;&lt;STRONG&gt;*&lt;/STRONG&gt; For some companies this might actually be a preferred choice (e.g.: granting SaaS access to external users authenticating with QlikID, and keeping the on premise version for internal ones on AD)&lt;/EM&gt;&lt;/P&gt;
&lt;/DIV&gt;</description>
      <pubDate>Tue, 10 May 2022 18:59:01 GMT</pubDate>
      <guid>https://community.qlik.com/t5/Official-Support-Articles/Multi-cloud-deployment-difference-between-using-an-Identity/ta-p/1803844</guid>
      <dc:creator>Daniele_Purrone</dc:creator>
      <dc:date>2022-05-10T18:59:01Z</dc:date>
    </item>
  </channel>
</rss>

