<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>article Security Rules Fail For SSO/SAML Users and The Group or Other User Attributes Returned from SSO / SAML Provider Are Not Seen in the User Record in Official Support Articles</title>
    <link>https://community.qlik.com/t5/Official-Support-Articles/Security-Rules-Fail-For-SSO-SAML-Users-and-The-Group-or-Other/ta-p/1715208</link>
    <description>&lt;P&gt;When a user authenticates with SAML/JWT/Ticket, security rules based on the attributes from the SSO provider do not work and the attributes are not visible in the QMC under the User record.&lt;/P&gt;
&lt;H4&gt;&lt;FONT color="#339966"&gt;&lt;STRONG&gt;Environment&lt;/STRONG&gt;&lt;/FONT&gt;&lt;/H4&gt;
&lt;UL&gt;
&lt;LI&gt;Qlik Sense Enterprise, all versions&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;When a user authenticates with SAML, a list of attributes will be given to Qlik Sense based on what is set up in the virtual proxy.&amp;nbsp; The attributes depend on the implementation.&lt;BR /&gt;&lt;BR /&gt;&lt;IMG src="https://qlik.my.salesforce.com/servlet/servlet.ImageServer?id=015D0000003sAvG&amp;amp;oid=00D20000000IGPX&amp;amp;lastMod=1491979583000" border="0" alt="User-added image" width="600" /&gt;&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt;However, these User attribute(s) returned from the SSO provider are&lt;I&gt; &lt;STRONG&gt;only kept for the user session&lt;/STRONG&gt;&lt;/I&gt; and are &lt;STRONG&gt;&lt;I&gt;not stored/persisted in the Qlik Sense Repository Database&lt;/I&gt;&lt;/STRONG&gt;. Therefore, they do not appear in the QMC like attributes synchronized via a UDC connection (data which &lt;I&gt;is&amp;nbsp;&lt;/I&gt;persisted to the database).&lt;BR /&gt;&amp;nbsp;&lt;/P&gt;
&lt;H3&gt;Resolution:&lt;/H3&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;OL&gt;
&lt;LI&gt;Reference the attributes via&amp;nbsp;&lt;SPAN&gt;&lt;I&gt;user.&lt;U&gt;environment&lt;/U&gt;.[attribute name]&lt;/I&gt;&lt;/SPAN&gt; (not &lt;SPAN&gt;user.[attribute name]&lt;/SPAN&gt;)&lt;/LI&gt;
&lt;LI&gt;View the exact attributes returned from the SSO provider by examining the logs:&lt;BR /&gt;&lt;BR /&gt;
&lt;OL class="lia-list-style-type-lower-alpha"&gt;
&lt;LI&gt;Set the Proxy Audit Logs to the DEBUG level&lt;BR /&gt;&lt;BR /&gt;&lt;IMG src="https://qlik.my.salesforce.com/servlet/servlet.ImageServer?id=015D0000003sAvL&amp;amp;oid=00D20000000IGPX&amp;amp;lastMod=1491979611000" border="0" alt="User-added image" /&gt;&lt;/LI&gt;
&lt;LI&gt;After enabling debug logging, the&amp;nbsp;(Trace/Audit) Proxy logs will reveal the extracted attribute(s). No restart is required.&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;The default location for this log is in &lt;FONT face="courier new,courier"&gt;C:\ProgramData\Qlik\Sense\Log\Proxy\Trace\servername_Proxy_audit.txt&lt;/FONT&gt;&lt;BR /&gt;&lt;BR /&gt;Example&amp;nbsp;&lt;SPAN&gt;Headers that will be injected:&lt;BR /&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;[X-Qlik-Security, OS=Windows; Device=Default; Browser=Firefox 50.0; IP=fe80::f0bf:12cb:47cd:2086%14; ClientOsVersion=6.3; SecureRequest=true; Context=AppAccess;&lt;STRONG&gt; &lt;U&gt;role=Domain+Users; role=group5;&lt;/U&gt;&lt;/STRONG&gt; ] || [X-Qlik-User, UserDirectory=DOMAIN; UserId=user5] || [X-Qlik-ProxySession, b29118dd-4539-4742-ad65-fe307eb10b54] || [X-Qlik-ProxyId, ProxyId=38daa8e0-5330-4581-9f40-49d7418b858f; Prefix=adfs] || [X-Qlik-Trace, cf2e0117-ee82-4d26-bba8-b781fc4ef19e:::]&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/LI&gt;
&lt;/OL&gt;
&lt;/LI&gt;
&lt;/OL&gt;</description>
    <pubDate>Mon, 12 Jan 2026 12:00:55 GMT</pubDate>
    <dc:creator>Damien_V</dc:creator>
    <dc:date>2026-01-12T12:00:55Z</dc:date>
    <item>
      <title>Security Rules Fail For SSO/SAML Users and The Group or Other User Attributes Returned from SSO / SAML Provider Are Not Seen in the User Record</title>
      <link>https://community.qlik.com/t5/Official-Support-Articles/Security-Rules-Fail-For-SSO-SAML-Users-and-The-Group-or-Other/ta-p/1715208</link>
      <description>&lt;P&gt;When a user authenticates with SAML/JWT/Ticket, security rules based on the attributes from the SSO provider do not work and the attributes are not visible in the QMC under the User record.&lt;/P&gt;
&lt;H4&gt;&lt;FONT color="#339966"&gt;&lt;STRONG&gt;Environment&lt;/STRONG&gt;&lt;/FONT&gt;&lt;/H4&gt;
&lt;UL&gt;
&lt;LI&gt;Qlik Sense Enterprise, all versions&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;When a user authenticates with SAML, a list of attributes will be given to Qlik Sense based on what is set up in the virtual proxy.&amp;nbsp; The attributes depend on the implementation.&lt;BR /&gt;&lt;BR /&gt;&lt;IMG src="https://qlik.my.salesforce.com/servlet/servlet.ImageServer?id=015D0000003sAvG&amp;amp;oid=00D20000000IGPX&amp;amp;lastMod=1491979583000" border="0" alt="User-added image" width="600" /&gt;&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt;However, these User attribute(s) returned from the SSO provider are&lt;I&gt; &lt;STRONG&gt;only kept for the user session&lt;/STRONG&gt;&lt;/I&gt; and are &lt;STRONG&gt;&lt;I&gt;not stored/persisted in the Qlik Sense Repository Database&lt;/I&gt;&lt;/STRONG&gt;. Therefore, they do not appear in the QMC like attributes synchronized via a UDC connection (data which &lt;I&gt;is&amp;nbsp;&lt;/I&gt;persisted to the database).&lt;BR /&gt;&amp;nbsp;&lt;/P&gt;
&lt;H3&gt;Resolution:&lt;/H3&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;OL&gt;
&lt;LI&gt;Reference the attributes via&amp;nbsp;&lt;SPAN&gt;&lt;I&gt;user.&lt;U&gt;environment&lt;/U&gt;.[attribute name]&lt;/I&gt;&lt;/SPAN&gt; (not &lt;SPAN&gt;user.[attribute name]&lt;/SPAN&gt;)&lt;/LI&gt;
&lt;LI&gt;View the exact attributes returned from the SSO provider by examining the logs:&lt;BR /&gt;&lt;BR /&gt;
&lt;OL class="lia-list-style-type-lower-alpha"&gt;
&lt;LI&gt;Set the Proxy Audit Logs to the DEBUG level&lt;BR /&gt;&lt;BR /&gt;&lt;IMG src="https://qlik.my.salesforce.com/servlet/servlet.ImageServer?id=015D0000003sAvL&amp;amp;oid=00D20000000IGPX&amp;amp;lastMod=1491979611000" border="0" alt="User-added image" /&gt;&lt;/LI&gt;
&lt;LI&gt;After enabling debug logging, the&amp;nbsp;(Trace/Audit) Proxy logs will reveal the extracted attribute(s). No restart is required.&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;The default location for this log is in &lt;FONT face="courier new,courier"&gt;C:\ProgramData\Qlik\Sense\Log\Proxy\Trace\servername_Proxy_audit.txt&lt;/FONT&gt;&lt;BR /&gt;&lt;BR /&gt;Example&amp;nbsp;&lt;SPAN&gt;Headers that will be injected:&lt;BR /&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;[X-Qlik-Security, OS=Windows; Device=Default; Browser=Firefox 50.0; IP=fe80::f0bf:12cb:47cd:2086%14; ClientOsVersion=6.3; SecureRequest=true; Context=AppAccess;&lt;STRONG&gt; &lt;U&gt;role=Domain+Users; role=group5;&lt;/U&gt;&lt;/STRONG&gt; ] || [X-Qlik-User, UserDirectory=DOMAIN; UserId=user5] || [X-Qlik-ProxySession, b29118dd-4539-4742-ad65-fe307eb10b54] || [X-Qlik-ProxyId, ProxyId=38daa8e0-5330-4581-9f40-49d7418b858f; Prefix=adfs] || [X-Qlik-Trace, cf2e0117-ee82-4d26-bba8-b781fc4ef19e:::]&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/LI&gt;
&lt;/OL&gt;
&lt;/LI&gt;
&lt;/OL&gt;</description>
      <pubDate>Mon, 12 Jan 2026 12:00:55 GMT</pubDate>
      <guid>https://community.qlik.com/t5/Official-Support-Articles/Security-Rules-Fail-For-SSO-SAML-Users-and-The-Group-or-Other/ta-p/1715208</guid>
      <dc:creator>Damien_V</dc:creator>
      <dc:date>2026-01-12T12:00:55Z</dc:date>
    </item>
    <item>
      <title>Re: Security Rules Fail For SSO/SAML Users and The Group or Other User Attributes Returned from SSO / SAML Provider Are Not Seen in the User Record</title>
      <link>https://community.qlik.com/t5/Official-Support-Articles/Security-Rules-Fail-For-SSO-SAML-Users-and-The-Group-or-Other/tac-p/2514326#M15684</link>
      <description>&lt;P&gt;Thanks for the article!&lt;/P&gt;&lt;P&gt;I'm having some problems, though, while trying to use the new field in a security rule.&lt;/P&gt;&lt;P&gt;I've mapped the SAML field I receive to environment.group and it's detected correctly. If I go to Users and click the information of the user, a lot of environment.group appear for that user with the groups I need. But when I create a security rule trying to use the new user.environment.group, and I put the value as received (as I see it in the user's description), the rule doesn't work. I tried to use an "=" for the condition and tried different cases, also tried to use LIKE and combine the complete name of the group or a partial one with * and the rule doesn't work.&lt;/P&gt;&lt;P&gt;Is there a way to see why the rule doesn't apply? The claim mapping is working correctly.&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;</description>
      <pubDate>Mon, 14 Apr 2025 20:35:30 GMT</pubDate>
      <guid>https://community.qlik.com/t5/Official-Support-Articles/Security-Rules-Fail-For-SSO-SAML-Users-and-The-Group-or-Other/tac-p/2514326#M15684</guid>
      <dc:creator>jpbartolomeo1</dc:creator>
      <dc:date>2025-04-14T20:35:30Z</dc:date>
    </item>
    <item>
      <title>Re: Security Rules Fail For SSO/SAML Users and The Group or Other User Attributes Returned from SSO / SAML Provider Are Not Seen in the User Record</title>
      <link>https://community.qlik.com/t5/Official-Support-Articles/Security-Rules-Fail-For-SSO-SAML-Users-and-The-Group-or-Other/tac-p/2520783#M15932</link>
      <description>&lt;P&gt;&lt;a href="https://community.qlik.com/t5/user/viewprofilepage/user-id/29425"&gt;@Damien_V&lt;/a&gt;&amp;nbsp; &lt;A href="https://community.qlik.com/t5/user/viewprofilepage/user-id/28597" target="_blank" rel="noopener"&gt;&lt;SPAN class=""&gt;@Sonja_Bauernfeind&lt;/SPAN&gt;&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN class=""&gt;&lt;SPAN&gt;We are currently in the process of integrating our Qlik system with OKTA SSO and have a couple of questions regarding this integration. Specifically, we would like to verify whether it is possible to populate the "Name" field and if we can also populate custom properties on user accounts through a SAML attribute assertion.&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN class=""&gt;&lt;SPAN&gt;We've encountered this issue while trying to configure SAML attributes mapping in Qlik QMC. We've attempted to set different values for user id, email, names, etc. However, despite these efforts, the update only appears in the proxy logs and is not reflected in QMC. The QMC seems to be populating the name field solely with the value we have for user Id, completely ignoring the configurations we've made in the SAML attributes mapping. Please let us know. Thanks&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 10 Jun 2025 20:44:18 GMT</pubDate>
      <guid>https://community.qlik.com/t5/Official-Support-Articles/Security-Rules-Fail-For-SSO-SAML-Users-and-The-Group-or-Other/tac-p/2520783#M15932</guid>
      <dc:creator>yeheyies</dc:creator>
      <dc:date>2025-06-10T20:44:18Z</dc:date>
    </item>
    <item>
      <title>Re: Security Rules Fail For SSO/SAML Users and The Group or Other User Attributes Returned from SSO / SAML Provider Are Not Seen in the User Record</title>
      <link>https://community.qlik.com/t5/Official-Support-Articles/Security-Rules-Fail-For-SSO-SAML-Users-and-The-Group-or-Other/tac-p/2520793#M15934</link>
      <description>&lt;P&gt;&lt;a href="https://community.qlik.com/t5/user/viewprofilepage/user-id/182427"&gt;@yeheyies&lt;/a&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;It's not possible to populate the name (display name) with a SAML attribute, please see&lt;/P&gt;
&lt;P&gt;&lt;A href="https://community.qlik.com/t5/Official-Support-Articles/Qlik-Sense-Is-it-possible-to-use-a-SAML-attribute-for-the/ta-p/1712576" target="_blank"&gt;https://community.qlik.com/t5/Official-Support-Articles/Qlik-Sense-Is-it-possible-to-use-a-SAML-attribute-for-the/ta-p/1712576&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 11 Jun 2025 01:21:15 GMT</pubDate>
      <guid>https://community.qlik.com/t5/Official-Support-Articles/Security-Rules-Fail-For-SSO-SAML-Users-and-The-Group-or-Other/tac-p/2520793#M15934</guid>
      <dc:creator>Damien_V</dc:creator>
      <dc:date>2025-06-11T01:21:15Z</dc:date>
    </item>
  </channel>
</rss>

