<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>article Qlik Sense on Windows: Configuring and testing LDAP filters for User Directory Connector in Official Support Articles</title>
    <link>https://community.qlik.com/t5/Official-Support-Articles/Qlik-Sense-on-Windows-Configuring-and-testing-LDAP-filters-for/ta-p/1713947</link>
    <description>&lt;P&gt;&lt;BR /&gt;This article goes over how to use LDAP filters and common examples when setting up Qlik Sense User Directory Connector (UDC).&lt;BR /&gt;&lt;BR /&gt;&lt;STRONG&gt;Note: &lt;/STRONG&gt;Qlik Support has no scope in assisting in composing an LDAP filter that fits the environment needs. If further assistance is needed please see &lt;A href="https://community.qlik.com/t5/Support-Knowledge-Base/How-and-When-to-Contact-the-Consulting-Team/ta-p/1714936" target="_blank" rel="noopener"&gt;How and When to Contact the Consulting Team?&lt;/A&gt;&amp;nbsp;AD and Qlik Sense must be within the same Domain. If different domains refer to this article&amp;nbsp;&lt;A href="https://community.qlik.com/t5/Support-Knowledge-Base/Users-of-a-different-Active-Directory-but-with-membership-to-a/ta-p/1715263" target="_blank" rel="noopener"&gt;Users of a different Active Directory, but with membership to a group in the same Domain as the QlikSense server, are not synced&lt;/A&gt;&lt;/P&gt;
&lt;H3&gt;&lt;FONT size="5"&gt;Environment:&lt;/FONT&gt;&lt;/H3&gt;
&lt;UL&gt;
&lt;LI&gt;Qlik Sense Enterprise on Windows, all versions&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;H3&gt;&lt;FONT size="5"&gt;Resolution:&lt;/FONT&gt;&lt;BR /&gt;&amp;nbsp;&lt;div class="video-embed-center video-embed"&gt;&lt;iframe class="embedly-embed" src="https://cdn.embedly.com/widgets/media.html?src=https%3A%2F%2Fwww.youtube.com%2Fembed%2FJ3sL9g6Fo3M%3Ffeature%3Doembed&amp;amp;display_name=YouTube&amp;amp;url=https%3A%2F%2Fwww.youtube.com%2Fwatch%3Fv%3DJ3sL9g6Fo3M&amp;amp;image=https%3A%2F%2Fi.ytimg.com%2Fvi%2FJ3sL9g6Fo3M%2Fhqdefault.jpg&amp;amp;type=text%2Fhtml&amp;amp;schema=youtube" width="600" height="337" scrolling="no" title="Qlik Fix: Configuring and testing LDAP filters for User Directory Connector" frameborder="0" allow="autoplay; fullscreen; encrypted-media; picture-in-picture;" allowfullscreen="true"&gt;&lt;/iframe&gt;&lt;/div&gt;&lt;/H3&gt;
&lt;P&gt;&lt;A href="https://community.qlik.com/t5/Qlik-Fix/Qlik-Fix-How-to-configure-and-test-LDAP-filters-for-User/ta-p/1754545" target="_blank" rel="noopener"&gt;Click here for Video Transcript&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Notes:&lt;/STRONG&gt;&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;Although this article is using AD as an example, it should also apply to other Directory Services that are compatible with LDAP&lt;/LI&gt;
&lt;LI&gt;Although this example only filters users based on one single Group, more complicated filters are also supported in Qlik Sense. Please make sure the filter returns desired result before applying it to Directory Connector.&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;1. (Optional) Create a group that the filter will be based on. For example, "SenseUsers" group with 4 users is created in AD:&lt;/P&gt;
&lt;P&gt;2. Recommended: Mark all RootAdmins as&amp;nbsp;&lt;STRONG&gt;Delete Prohibited&lt;/STRONG&gt;&amp;nbsp;to prevent locking oneself out of the QMC, see&amp;nbsp;&lt;A href="https://community.qlik.com/t5/Support-Knowledge-Base/How-to-avoid-the-RootAdmin-s-from-becoming-inactive/ta-p/1715558" target="_blank" rel="noopener"&gt;How to avoid the RootAdmin(s) from becoming inactive&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;3. In this article, we will use native Windows tools to preview the LDAP query. Third party tools like LDAP Admin or LDAP Browser by Softerra are also valid tools to use.&lt;/P&gt;
&lt;P&gt;4. On the Windows Server, open the&amp;nbsp;&lt;STRONG&gt;Server Manager&lt;/STRONG&gt;:&lt;/P&gt;
&lt;P&gt;5. Click on&amp;nbsp;&lt;STRONG&gt;Manage&lt;/STRONG&gt;&amp;nbsp;then &lt;STRONG&gt;Add Roles and Features&lt;/STRONG&gt;:&lt;/P&gt;
&lt;DIV&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="1.png" style="width: 320px;"&gt;&lt;img src="https://community.qlik.com/t5/image/serverpage/image-id/57211i901763BF1F3FC292/image-size/large?v=v2&amp;amp;px=999" role="button" title="1.png" alt="1.png" /&gt;&lt;/span&gt;&lt;/DIV&gt;
&lt;P&gt;6. If&amp;nbsp;&lt;STRONG&gt;Before You Begin&lt;/STRONG&gt;&amp;nbsp;is displayed, click&amp;nbsp;&lt;STRONG&gt;Next&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;7. On&amp;nbsp;&lt;STRONG&gt;Installation Type&lt;/STRONG&gt;, select&amp;nbsp;&lt;STRONG&gt;Role-based or feature-based installation&lt;/STRONG&gt;:&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="2.png" style="width: 477px;"&gt;&lt;img src="https://community.qlik.com/t5/image/serverpage/image-id/57212iAE9E1CA86770BADD/image-size/large?v=v2&amp;amp;px=999" role="button" title="2.png" alt="2.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;8. On&amp;nbsp;&lt;STRONG&gt;Server Selection&lt;/STRONG&gt;, select the server that you are working with&lt;/P&gt;
&lt;P&gt;9. Next navigate to&amp;nbsp;&lt;STRONG&gt;Features&lt;/STRONG&gt;, and select the&amp;nbsp;&lt;STRONG&gt;Active Directory Administrative Center&lt;/STRONG&gt;&amp;nbsp;option:&lt;/P&gt;
&lt;DIV&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="3.png" style="width: 519px;"&gt;&lt;img src="https://community.qlik.com/t5/image/serverpage/image-id/57213i38DA831BB20D2E75/image-size/large?v=v2&amp;amp;px=999" role="button" title="3.png" alt="3.png" /&gt;&lt;/span&gt;&lt;/DIV&gt;
&lt;P&gt;10. Confirm that this is the feature(s) that you want to install and allow the installation to complete&lt;/P&gt;
&lt;P&gt;11. After the installation completes, Click&amp;nbsp;&lt;STRONG&gt;Start&lt;/STRONG&gt;&amp;nbsp;then select&amp;nbsp;&lt;STRONG&gt;Administrative Tools&lt;/STRONG&gt;&amp;nbsp;and open the&amp;nbsp;&lt;STRONG&gt;Active Directory Users and Computers&lt;/STRONG&gt;&amp;nbsp;module&lt;/P&gt;
&lt;P&gt;12. The main domain that the server is on should automatically be present, so right click on the domain and select&amp;nbsp;&lt;STRONG&gt;Find:&lt;/STRONG&gt;&lt;/P&gt;
&lt;DIV&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="4.png" style="width: 318px;"&gt;&lt;img src="https://community.qlik.com/t5/image/serverpage/image-id/57214i3014E423B1A18CAC/image-size/large?v=v2&amp;amp;px=999" role="button" title="4.png" alt="4.png" /&gt;&lt;/span&gt;&lt;/DIV&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;13. In the&amp;nbsp;&lt;STRONG&gt;Find&lt;/STRONG&gt;&amp;nbsp;section select&amp;nbsp;&lt;STRONG&gt;Custom Search&lt;/STRONG&gt;:&lt;/P&gt;
&lt;DIV&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="5.png" style="width: 214px;"&gt;&lt;img src="https://community.qlik.com/t5/image/serverpage/image-id/57215i932C5B7399261FDD/image-size/large?v=v2&amp;amp;px=999" role="button" title="5.png" alt="5.png" /&gt;&lt;/span&gt;&lt;/DIV&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;14. Write out your potential LDAP filter and ensure that it selects all the expected users:&lt;/P&gt;
&lt;DIV&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="6.png" style="width: 528px;"&gt;&lt;img src="https://community.qlik.com/t5/image/serverpage/image-id/57216i7F03CCF28E11ACCD/image-size/large?v=v2&amp;amp;px=999" role="button" title="6.png" alt="6.png" /&gt;&lt;/span&gt;&lt;/DIV&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;15. Once you have an LDAP filter which works correctly outside of Qlik Sense, then navigate in the QMC to&amp;nbsp;&lt;STRONG&gt;User Directory Connectors&lt;/STRONG&gt;&amp;nbsp;&amp;gt;&amp;nbsp;edit the pre-existing&amp;nbsp;&lt;STRONG&gt;Active Directory&lt;/STRONG&gt;&amp;nbsp;Connector &amp;gt; ensure that the&amp;nbsp;&lt;STRONG&gt;Advanced&lt;/STRONG&gt;&amp;nbsp;section is displayed and paste in the LDAP filter. At this step you should unselect the&amp;nbsp;&lt;STRONG&gt;Sync user data for existing users&lt;/STRONG&gt;&amp;nbsp;toggle:&lt;/P&gt;
&lt;DIV&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="7.png" style="width: 604px;"&gt;&lt;img src="https://community.qlik.com/t5/image/serverpage/image-id/57217i18C211B1E2580F88/image-size/large?v=v2&amp;amp;px=999" role="button" title="7.png" alt="7.png" /&gt;&lt;/span&gt;&lt;/DIV&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;16. The rationale for unselecting the&amp;nbsp;&lt;STRONG&gt;Sync user data for existing users&lt;/STRONG&gt;&amp;nbsp;toggle is as follows. If you are already filtering the results from AD, then it makes sense to pull in the entire set of the filtered subset of users. This step isn't strictly speaking required but if you opt for the route of using an LDAP filter then it makes logistical sense to pull in all the users in the filtered subset.&lt;/P&gt;
&lt;P&gt;17. Save the changes and go back to the root of the User Directory Connectors section and sync the altered Connector:&lt;/P&gt;
&lt;DIV&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="8.png" style="width: 582px;"&gt;&lt;img src="https://community.qlik.com/t5/image/serverpage/image-id/57218i59FAFD1FF66C722B/image-size/large?v=v2&amp;amp;px=999" role="button" title="8.png" alt="8.png" /&gt;&lt;/span&gt;&lt;/DIV&gt;
&lt;DIV&gt;&amp;nbsp;&lt;/DIV&gt;
&lt;DIV&gt;&amp;nbsp;&lt;/DIV&gt;
&lt;DIV&gt;
&lt;H4&gt;Some common filters:&lt;/H4&gt;
&lt;UL&gt;
&lt;LI&gt;All users: &lt;FONT face="courier new,courier"&gt;&lt;SPAN&gt;(&amp;amp;(objectCategory=person)(objectClass=user))&lt;/SPAN&gt;&lt;/FONT&gt;
&lt;UL&gt;
&lt;LI&gt;&lt;STRONG&gt;Caution&lt;/STRONG&gt;: do NOT use this filter on an LDAP with a lot of users. Too many users loaded to Qlik Sense could cause performance problem and once they are imported it will be difficult to remove them.&lt;/LI&gt;
&lt;/UL&gt;
&lt;/LI&gt;
&lt;LI&gt;All users in a specific group:&amp;nbsp; &lt;SPAN&gt;&lt;FONT face="courier new,courier"&gt;(&amp;amp;(objectClass=user)((memberOf:1.2.840.113556.1.4.1941:=CN=NameOfTheGroup,CN=Users,DC=domain,DC=local)))&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI&gt;User with a specific natural name:&amp;nbsp; &lt;FONT face="courier new,courier"&gt;&lt;SPAN&gt;(&amp;amp;(objectCategory=person)(objectClass=user)(CN=&lt;I&gt;FirstName LastName&lt;/I&gt;))&lt;/SPAN&gt;&lt;/FONT&gt;
&lt;UL&gt;
&lt;LI&gt;For example, if a user is called John Doe, the filter to look for him can be: &lt;FONT face="courier new,courier"&gt;&lt;SPAN&gt;(&amp;amp;(objectCategory=person)(objectClass=user)(CN=John Doe))&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;/LI&gt;
&lt;LI&gt;User with a specific login name: &lt;FONT face="courier new,courier"&gt;&lt;SPAN&gt;(&amp;amp;(objectCategory=person)(objectClass=user)(sAMAccountName=&lt;I&gt;LoginName&lt;/I&gt;))&lt;/SPAN&gt;&lt;/FONT&gt;
&lt;UL&gt;
&lt;LI&gt;For example, if John Doe's login name is DOMAIN\JDOE in the system, the filter to look for him can be: &lt;FONT face="courier new,courier"&gt;&lt;SPAN&gt;(&amp;amp;(objectCategory=person)(objectClass=user)(sAMAccountName=&lt;I&gt;jdoe&lt;/I&gt;))&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;/LI&gt;
&lt;LI&gt;The filter used by &lt;STRONG&gt;QlikView Active Directory Connector&lt;/STRONG&gt; when performing a user search(replace KEYWORD with actual search phrase):
&lt;UL&gt;
&lt;LI&gt;&lt;FONT face="courier new,courier"&gt;&lt;SPAN&gt;(&amp;amp;(|(name=&lt;I&gt;KEYWORD&lt;/I&gt;)(sAMAccountName=&lt;I&gt;KEYWORD&lt;/I&gt;))(&amp;amp;(!(objectclass=computer))(objectGUID=*))(|(&amp;amp;(objectCategory=group)(groupType:1.2.840.113556.1.4.803:=2147483648))(|(objectClass=User)(objectClass=person))))&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;/DIV&gt;
&lt;H3&gt;&lt;FONT size="5"&gt;Related Content:&lt;/FONT&gt;&lt;/H3&gt;
&lt;UL&gt;
&lt;LI&gt;
&lt;P&gt;&lt;A href="https://community.qlik.com/t5/Support-Knowledge-Base/Qlik-Sense-How-to-connect-to-AD-using-quot-Active-Directory-quot/ta-p/1714211" target="_blank" rel="noopener"&gt;Qlik Sense: How to connect to AD using "Active Directory" UDC&lt;/A&gt;&lt;/P&gt;
&lt;/LI&gt;
&lt;LI&gt;
&lt;P&gt;&lt;A href="https://community.qlik.com/t5/Support-Knowledge-Base/How-to-Filter-Active-Directory-to-Sync-Qlik-Sense-Users/ta-p/1715364" target="_blank" rel="noopener"&gt;How to Filter Active Directory to Sync Qlik Sense Users&lt;/A&gt;&lt;/P&gt;
&lt;/LI&gt;
&lt;LI&gt;
&lt;P&gt;&lt;A href="https://support.qlik.com/articles/000005638" target="_blank" rel="noopener"&gt;LDAP Filter for multiple groups in Qlik Sense&lt;/A&gt;&lt;/P&gt;
&lt;/LI&gt;
&lt;LI&gt;
&lt;P&gt;&lt;A href="https://support.qlik.com/articles/000028577" target="_blank" rel="noopener"&gt;How to approach Active Directory sync issue for Qlik Sense&lt;/A&gt;&lt;/P&gt;
&lt;/LI&gt;
&lt;LI&gt;
&lt;P&gt;&lt;A href="https://help.qlik.com/en-US/sense-admin/Subsystems/DeployAdministerQSE/Content/Sense_DeployAdminister/QSEoW/Administer_QSEoW/Managing_QSEoW/use-additional-LDAP-filter-to-retrieve-specific-users.htm" target="_blank" rel="noopener"&gt;Using Additional LDAP filter to retrieve specific users&lt;/A&gt;&lt;/P&gt;
&lt;/LI&gt;
&lt;LI&gt;
&lt;P&gt;&lt;A href="https://community.qlik.com/t5/Support-Knowledge-Base/Users-of-a-different-Active-Directory-but-with-membership-to-a/ta-p/1715263" target="_blank" rel="noopener"&gt;Users of a different Active Directory, but with membership to a group in the same Domain as the QlikSense server, are not synced&lt;/A&gt;&lt;/P&gt;
&lt;/LI&gt;
&lt;LI&gt;
&lt;P&gt;&lt;A href="https://community.qlik.com/t5/Support-Knowledge-Base/How-to-get-LDAP-filters-for-Active-Directory-groups-from-users/ta-p/1715425" target="_blank" rel="noopener"&gt;How to get LDAP filters for Active Directory groups from users already in Qlik Sense&lt;/A&gt;&lt;/P&gt;
&lt;/LI&gt;
&lt;LI&gt;
&lt;P&gt;&lt;A href="https://support.qlik.com/articles/000019573" target="_blank" rel="noopener"&gt;How to control user access to QMC/Hub/Access Point?&lt;/A&gt;&lt;/P&gt;
&lt;/LI&gt;
&lt;LI&gt;
&lt;P&gt;&lt;A href="https://support.qlik.com/articles/000030053" target="_blank" rel="noopener"&gt;LDAP filter to only include all users in a certain Organizational Unit (OU) into Qlik Sense&lt;/A&gt;&lt;/P&gt;
&lt;/LI&gt;
&lt;LI&gt;
&lt;P&gt;&lt;A href="https://community.qlik.com/t5/Qlik-Sense-Deployment-Management/Retrieve-OU-Organizational-Unit-users-from-Active-Directory-LDAP/m-p/55897" target="_blank" rel="noopener"&gt;Retrieve OU (Organizational Unit) users from Active Directory LDAP Filter&lt;/A&gt;&lt;/P&gt;
&lt;/LI&gt;
&lt;LI&gt;
&lt;P&gt;&lt;A href="https://www.youtube.com/watch?v=40GjDjvEhZ8" target="_blank" rel="noopener"&gt;Video: Qlik Sense Platform - Qlik Management Console - User Directory Connector - Part 5&lt;/A&gt;&lt;/P&gt;
&lt;/LI&gt;
&lt;LI&gt;
&lt;P&gt;&lt;A href="https://docs.microsoft.com/en-us/windows/win32/adsi/search-filter-syntax" target="_blank" rel="noopener"&gt;ADSI - Search Filter Syntax - Extended match operator / Nested groups rule&lt;/A&gt;&lt;/P&gt;
&lt;/LI&gt;
&lt;LI&gt;
&lt;P&gt;&lt;A href="https://tools.ietf.org/html/rfc2254" target="_blank" rel="noopener"&gt;RFC2254: The String Representation of LDAP Search Filters&lt;/A&gt;&lt;/P&gt;
&lt;/LI&gt;
&lt;LI&gt;
&lt;P&gt;&lt;A href="http://social.technet.microsoft.com/wiki/contents/articles/5392.active-directory-ldap-syntax-filters.aspx" target="_blank" rel="noopener"&gt;Actvive Directory: LDAP Syntax Filters&lt;/A&gt;&lt;/P&gt;
&lt;/LI&gt;
&lt;LI&gt;
&lt;P&gt;&lt;A href="http://www.ldapadmin.org/" target="_blank" rel="noopener"&gt;LDAP Admin HP&lt;/A&gt;&lt;/P&gt;
&lt;/LI&gt;
&lt;/UL&gt;</description>
    <pubDate>Mon, 21 Jun 2021 17:20:17 GMT</pubDate>
    <dc:creator>Andre_Sostizzo</dc:creator>
    <dc:date>2021-06-21T17:20:17Z</dc:date>
    <item>
      <title>Qlik Sense on Windows: Configuring and testing LDAP filters for User Directory Connector</title>
      <link>https://community.qlik.com/t5/Official-Support-Articles/Qlik-Sense-on-Windows-Configuring-and-testing-LDAP-filters-for/ta-p/1713947</link>
      <description>&lt;P&gt;&lt;BR /&gt;This article goes over how to use LDAP filters and common examples when setting up Qlik Sense User Directory Connector (UDC).&lt;BR /&gt;&lt;BR /&gt;&lt;STRONG&gt;Note: &lt;/STRONG&gt;Qlik Support has no scope in assisting in composing an LDAP filter that fits the environment needs. If further assistance is needed please see &lt;A href="https://community.qlik.com/t5/Support-Knowledge-Base/How-and-When-to-Contact-the-Consulting-Team/ta-p/1714936" target="_blank" rel="noopener"&gt;How and When to Contact the Consulting Team?&lt;/A&gt;&amp;nbsp;AD and Qlik Sense must be within the same Domain. If different domains refer to this article&amp;nbsp;&lt;A href="https://community.qlik.com/t5/Support-Knowledge-Base/Users-of-a-different-Active-Directory-but-with-membership-to-a/ta-p/1715263" target="_blank" rel="noopener"&gt;Users of a different Active Directory, but with membership to a group in the same Domain as the QlikSense server, are not synced&lt;/A&gt;&lt;/P&gt;
&lt;H3&gt;&lt;FONT size="5"&gt;Environment:&lt;/FONT&gt;&lt;/H3&gt;
&lt;UL&gt;
&lt;LI&gt;Qlik Sense Enterprise on Windows, all versions&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;H3&gt;&lt;FONT size="5"&gt;Resolution:&lt;/FONT&gt;&lt;BR /&gt;&amp;nbsp;&lt;div class="video-embed-center video-embed"&gt;&lt;iframe class="embedly-embed" src="https://cdn.embedly.com/widgets/media.html?src=https%3A%2F%2Fwww.youtube.com%2Fembed%2FJ3sL9g6Fo3M%3Ffeature%3Doembed&amp;amp;display_name=YouTube&amp;amp;url=https%3A%2F%2Fwww.youtube.com%2Fwatch%3Fv%3DJ3sL9g6Fo3M&amp;amp;image=https%3A%2F%2Fi.ytimg.com%2Fvi%2FJ3sL9g6Fo3M%2Fhqdefault.jpg&amp;amp;type=text%2Fhtml&amp;amp;schema=youtube" width="600" height="337" scrolling="no" title="Qlik Fix: Configuring and testing LDAP filters for User Directory Connector" frameborder="0" allow="autoplay; fullscreen; encrypted-media; picture-in-picture;" allowfullscreen="true"&gt;&lt;/iframe&gt;&lt;/div&gt;&lt;/H3&gt;
&lt;P&gt;&lt;A href="https://community.qlik.com/t5/Qlik-Fix/Qlik-Fix-How-to-configure-and-test-LDAP-filters-for-User/ta-p/1754545" target="_blank" rel="noopener"&gt;Click here for Video Transcript&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Notes:&lt;/STRONG&gt;&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;Although this article is using AD as an example, it should also apply to other Directory Services that are compatible with LDAP&lt;/LI&gt;
&lt;LI&gt;Although this example only filters users based on one single Group, more complicated filters are also supported in Qlik Sense. Please make sure the filter returns desired result before applying it to Directory Connector.&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;1. (Optional) Create a group that the filter will be based on. For example, "SenseUsers" group with 4 users is created in AD:&lt;/P&gt;
&lt;P&gt;2. Recommended: Mark all RootAdmins as&amp;nbsp;&lt;STRONG&gt;Delete Prohibited&lt;/STRONG&gt;&amp;nbsp;to prevent locking oneself out of the QMC, see&amp;nbsp;&lt;A href="https://community.qlik.com/t5/Support-Knowledge-Base/How-to-avoid-the-RootAdmin-s-from-becoming-inactive/ta-p/1715558" target="_blank" rel="noopener"&gt;How to avoid the RootAdmin(s) from becoming inactive&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;3. In this article, we will use native Windows tools to preview the LDAP query. Third party tools like LDAP Admin or LDAP Browser by Softerra are also valid tools to use.&lt;/P&gt;
&lt;P&gt;4. On the Windows Server, open the&amp;nbsp;&lt;STRONG&gt;Server Manager&lt;/STRONG&gt;:&lt;/P&gt;
&lt;P&gt;5. Click on&amp;nbsp;&lt;STRONG&gt;Manage&lt;/STRONG&gt;&amp;nbsp;then &lt;STRONG&gt;Add Roles and Features&lt;/STRONG&gt;:&lt;/P&gt;
&lt;DIV&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="1.png" style="width: 320px;"&gt;&lt;img src="https://community.qlik.com/t5/image/serverpage/image-id/57211i901763BF1F3FC292/image-size/large?v=v2&amp;amp;px=999" role="button" title="1.png" alt="1.png" /&gt;&lt;/span&gt;&lt;/DIV&gt;
&lt;P&gt;6. If&amp;nbsp;&lt;STRONG&gt;Before You Begin&lt;/STRONG&gt;&amp;nbsp;is displayed, click&amp;nbsp;&lt;STRONG&gt;Next&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;7. On&amp;nbsp;&lt;STRONG&gt;Installation Type&lt;/STRONG&gt;, select&amp;nbsp;&lt;STRONG&gt;Role-based or feature-based installation&lt;/STRONG&gt;:&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="2.png" style="width: 477px;"&gt;&lt;img src="https://community.qlik.com/t5/image/serverpage/image-id/57212iAE9E1CA86770BADD/image-size/large?v=v2&amp;amp;px=999" role="button" title="2.png" alt="2.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;8. On&amp;nbsp;&lt;STRONG&gt;Server Selection&lt;/STRONG&gt;, select the server that you are working with&lt;/P&gt;
&lt;P&gt;9. Next navigate to&amp;nbsp;&lt;STRONG&gt;Features&lt;/STRONG&gt;, and select the&amp;nbsp;&lt;STRONG&gt;Active Directory Administrative Center&lt;/STRONG&gt;&amp;nbsp;option:&lt;/P&gt;
&lt;DIV&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="3.png" style="width: 519px;"&gt;&lt;img src="https://community.qlik.com/t5/image/serverpage/image-id/57213i38DA831BB20D2E75/image-size/large?v=v2&amp;amp;px=999" role="button" title="3.png" alt="3.png" /&gt;&lt;/span&gt;&lt;/DIV&gt;
&lt;P&gt;10. Confirm that this is the feature(s) that you want to install and allow the installation to complete&lt;/P&gt;
&lt;P&gt;11. After the installation completes, Click&amp;nbsp;&lt;STRONG&gt;Start&lt;/STRONG&gt;&amp;nbsp;then select&amp;nbsp;&lt;STRONG&gt;Administrative Tools&lt;/STRONG&gt;&amp;nbsp;and open the&amp;nbsp;&lt;STRONG&gt;Active Directory Users and Computers&lt;/STRONG&gt;&amp;nbsp;module&lt;/P&gt;
&lt;P&gt;12. The main domain that the server is on should automatically be present, so right click on the domain and select&amp;nbsp;&lt;STRONG&gt;Find:&lt;/STRONG&gt;&lt;/P&gt;
&lt;DIV&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="4.png" style="width: 318px;"&gt;&lt;img src="https://community.qlik.com/t5/image/serverpage/image-id/57214i3014E423B1A18CAC/image-size/large?v=v2&amp;amp;px=999" role="button" title="4.png" alt="4.png" /&gt;&lt;/span&gt;&lt;/DIV&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;13. In the&amp;nbsp;&lt;STRONG&gt;Find&lt;/STRONG&gt;&amp;nbsp;section select&amp;nbsp;&lt;STRONG&gt;Custom Search&lt;/STRONG&gt;:&lt;/P&gt;
&lt;DIV&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="5.png" style="width: 214px;"&gt;&lt;img src="https://community.qlik.com/t5/image/serverpage/image-id/57215i932C5B7399261FDD/image-size/large?v=v2&amp;amp;px=999" role="button" title="5.png" alt="5.png" /&gt;&lt;/span&gt;&lt;/DIV&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;14. Write out your potential LDAP filter and ensure that it selects all the expected users:&lt;/P&gt;
&lt;DIV&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="6.png" style="width: 528px;"&gt;&lt;img src="https://community.qlik.com/t5/image/serverpage/image-id/57216i7F03CCF28E11ACCD/image-size/large?v=v2&amp;amp;px=999" role="button" title="6.png" alt="6.png" /&gt;&lt;/span&gt;&lt;/DIV&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;15. Once you have an LDAP filter which works correctly outside of Qlik Sense, then navigate in the QMC to&amp;nbsp;&lt;STRONG&gt;User Directory Connectors&lt;/STRONG&gt;&amp;nbsp;&amp;gt;&amp;nbsp;edit the pre-existing&amp;nbsp;&lt;STRONG&gt;Active Directory&lt;/STRONG&gt;&amp;nbsp;Connector &amp;gt; ensure that the&amp;nbsp;&lt;STRONG&gt;Advanced&lt;/STRONG&gt;&amp;nbsp;section is displayed and paste in the LDAP filter. At this step you should unselect the&amp;nbsp;&lt;STRONG&gt;Sync user data for existing users&lt;/STRONG&gt;&amp;nbsp;toggle:&lt;/P&gt;
&lt;DIV&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="7.png" style="width: 604px;"&gt;&lt;img src="https://community.qlik.com/t5/image/serverpage/image-id/57217i18C211B1E2580F88/image-size/large?v=v2&amp;amp;px=999" role="button" title="7.png" alt="7.png" /&gt;&lt;/span&gt;&lt;/DIV&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;16. The rationale for unselecting the&amp;nbsp;&lt;STRONG&gt;Sync user data for existing users&lt;/STRONG&gt;&amp;nbsp;toggle is as follows. If you are already filtering the results from AD, then it makes sense to pull in the entire set of the filtered subset of users. This step isn't strictly speaking required but if you opt for the route of using an LDAP filter then it makes logistical sense to pull in all the users in the filtered subset.&lt;/P&gt;
&lt;P&gt;17. Save the changes and go back to the root of the User Directory Connectors section and sync the altered Connector:&lt;/P&gt;
&lt;DIV&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="8.png" style="width: 582px;"&gt;&lt;img src="https://community.qlik.com/t5/image/serverpage/image-id/57218i59FAFD1FF66C722B/image-size/large?v=v2&amp;amp;px=999" role="button" title="8.png" alt="8.png" /&gt;&lt;/span&gt;&lt;/DIV&gt;
&lt;DIV&gt;&amp;nbsp;&lt;/DIV&gt;
&lt;DIV&gt;&amp;nbsp;&lt;/DIV&gt;
&lt;DIV&gt;
&lt;H4&gt;Some common filters:&lt;/H4&gt;
&lt;UL&gt;
&lt;LI&gt;All users: &lt;FONT face="courier new,courier"&gt;&lt;SPAN&gt;(&amp;amp;(objectCategory=person)(objectClass=user))&lt;/SPAN&gt;&lt;/FONT&gt;
&lt;UL&gt;
&lt;LI&gt;&lt;STRONG&gt;Caution&lt;/STRONG&gt;: do NOT use this filter on an LDAP with a lot of users. Too many users loaded to Qlik Sense could cause performance problem and once they are imported it will be difficult to remove them.&lt;/LI&gt;
&lt;/UL&gt;
&lt;/LI&gt;
&lt;LI&gt;All users in a specific group:&amp;nbsp; &lt;SPAN&gt;&lt;FONT face="courier new,courier"&gt;(&amp;amp;(objectClass=user)((memberOf:1.2.840.113556.1.4.1941:=CN=NameOfTheGroup,CN=Users,DC=domain,DC=local)))&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI&gt;User with a specific natural name:&amp;nbsp; &lt;FONT face="courier new,courier"&gt;&lt;SPAN&gt;(&amp;amp;(objectCategory=person)(objectClass=user)(CN=&lt;I&gt;FirstName LastName&lt;/I&gt;))&lt;/SPAN&gt;&lt;/FONT&gt;
&lt;UL&gt;
&lt;LI&gt;For example, if a user is called John Doe, the filter to look for him can be: &lt;FONT face="courier new,courier"&gt;&lt;SPAN&gt;(&amp;amp;(objectCategory=person)(objectClass=user)(CN=John Doe))&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;/LI&gt;
&lt;LI&gt;User with a specific login name: &lt;FONT face="courier new,courier"&gt;&lt;SPAN&gt;(&amp;amp;(objectCategory=person)(objectClass=user)(sAMAccountName=&lt;I&gt;LoginName&lt;/I&gt;))&lt;/SPAN&gt;&lt;/FONT&gt;
&lt;UL&gt;
&lt;LI&gt;For example, if John Doe's login name is DOMAIN\JDOE in the system, the filter to look for him can be: &lt;FONT face="courier new,courier"&gt;&lt;SPAN&gt;(&amp;amp;(objectCategory=person)(objectClass=user)(sAMAccountName=&lt;I&gt;jdoe&lt;/I&gt;))&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;/LI&gt;
&lt;LI&gt;The filter used by &lt;STRONG&gt;QlikView Active Directory Connector&lt;/STRONG&gt; when performing a user search(replace KEYWORD with actual search phrase):
&lt;UL&gt;
&lt;LI&gt;&lt;FONT face="courier new,courier"&gt;&lt;SPAN&gt;(&amp;amp;(|(name=&lt;I&gt;KEYWORD&lt;/I&gt;)(sAMAccountName=&lt;I&gt;KEYWORD&lt;/I&gt;))(&amp;amp;(!(objectclass=computer))(objectGUID=*))(|(&amp;amp;(objectCategory=group)(groupType:1.2.840.113556.1.4.803:=2147483648))(|(objectClass=User)(objectClass=person))))&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;/DIV&gt;
&lt;H3&gt;&lt;FONT size="5"&gt;Related Content:&lt;/FONT&gt;&lt;/H3&gt;
&lt;UL&gt;
&lt;LI&gt;
&lt;P&gt;&lt;A href="https://community.qlik.com/t5/Support-Knowledge-Base/Qlik-Sense-How-to-connect-to-AD-using-quot-Active-Directory-quot/ta-p/1714211" target="_blank" rel="noopener"&gt;Qlik Sense: How to connect to AD using "Active Directory" UDC&lt;/A&gt;&lt;/P&gt;
&lt;/LI&gt;
&lt;LI&gt;
&lt;P&gt;&lt;A href="https://community.qlik.com/t5/Support-Knowledge-Base/How-to-Filter-Active-Directory-to-Sync-Qlik-Sense-Users/ta-p/1715364" target="_blank" rel="noopener"&gt;How to Filter Active Directory to Sync Qlik Sense Users&lt;/A&gt;&lt;/P&gt;
&lt;/LI&gt;
&lt;LI&gt;
&lt;P&gt;&lt;A href="https://support.qlik.com/articles/000005638" target="_blank" rel="noopener"&gt;LDAP Filter for multiple groups in Qlik Sense&lt;/A&gt;&lt;/P&gt;
&lt;/LI&gt;
&lt;LI&gt;
&lt;P&gt;&lt;A href="https://support.qlik.com/articles/000028577" target="_blank" rel="noopener"&gt;How to approach Active Directory sync issue for Qlik Sense&lt;/A&gt;&lt;/P&gt;
&lt;/LI&gt;
&lt;LI&gt;
&lt;P&gt;&lt;A href="https://help.qlik.com/en-US/sense-admin/Subsystems/DeployAdministerQSE/Content/Sense_DeployAdminister/QSEoW/Administer_QSEoW/Managing_QSEoW/use-additional-LDAP-filter-to-retrieve-specific-users.htm" target="_blank" rel="noopener"&gt;Using Additional LDAP filter to retrieve specific users&lt;/A&gt;&lt;/P&gt;
&lt;/LI&gt;
&lt;LI&gt;
&lt;P&gt;&lt;A href="https://community.qlik.com/t5/Support-Knowledge-Base/Users-of-a-different-Active-Directory-but-with-membership-to-a/ta-p/1715263" target="_blank" rel="noopener"&gt;Users of a different Active Directory, but with membership to a group in the same Domain as the QlikSense server, are not synced&lt;/A&gt;&lt;/P&gt;
&lt;/LI&gt;
&lt;LI&gt;
&lt;P&gt;&lt;A href="https://community.qlik.com/t5/Support-Knowledge-Base/How-to-get-LDAP-filters-for-Active-Directory-groups-from-users/ta-p/1715425" target="_blank" rel="noopener"&gt;How to get LDAP filters for Active Directory groups from users already in Qlik Sense&lt;/A&gt;&lt;/P&gt;
&lt;/LI&gt;
&lt;LI&gt;
&lt;P&gt;&lt;A href="https://support.qlik.com/articles/000019573" target="_blank" rel="noopener"&gt;How to control user access to QMC/Hub/Access Point?&lt;/A&gt;&lt;/P&gt;
&lt;/LI&gt;
&lt;LI&gt;
&lt;P&gt;&lt;A href="https://support.qlik.com/articles/000030053" target="_blank" rel="noopener"&gt;LDAP filter to only include all users in a certain Organizational Unit (OU) into Qlik Sense&lt;/A&gt;&lt;/P&gt;
&lt;/LI&gt;
&lt;LI&gt;
&lt;P&gt;&lt;A href="https://community.qlik.com/t5/Qlik-Sense-Deployment-Management/Retrieve-OU-Organizational-Unit-users-from-Active-Directory-LDAP/m-p/55897" target="_blank" rel="noopener"&gt;Retrieve OU (Organizational Unit) users from Active Directory LDAP Filter&lt;/A&gt;&lt;/P&gt;
&lt;/LI&gt;
&lt;LI&gt;
&lt;P&gt;&lt;A href="https://www.youtube.com/watch?v=40GjDjvEhZ8" target="_blank" rel="noopener"&gt;Video: Qlik Sense Platform - Qlik Management Console - User Directory Connector - Part 5&lt;/A&gt;&lt;/P&gt;
&lt;/LI&gt;
&lt;LI&gt;
&lt;P&gt;&lt;A href="https://docs.microsoft.com/en-us/windows/win32/adsi/search-filter-syntax" target="_blank" rel="noopener"&gt;ADSI - Search Filter Syntax - Extended match operator / Nested groups rule&lt;/A&gt;&lt;/P&gt;
&lt;/LI&gt;
&lt;LI&gt;
&lt;P&gt;&lt;A href="https://tools.ietf.org/html/rfc2254" target="_blank" rel="noopener"&gt;RFC2254: The String Representation of LDAP Search Filters&lt;/A&gt;&lt;/P&gt;
&lt;/LI&gt;
&lt;LI&gt;
&lt;P&gt;&lt;A href="http://social.technet.microsoft.com/wiki/contents/articles/5392.active-directory-ldap-syntax-filters.aspx" target="_blank" rel="noopener"&gt;Actvive Directory: LDAP Syntax Filters&lt;/A&gt;&lt;/P&gt;
&lt;/LI&gt;
&lt;LI&gt;
&lt;P&gt;&lt;A href="http://www.ldapadmin.org/" target="_blank" rel="noopener"&gt;LDAP Admin HP&lt;/A&gt;&lt;/P&gt;
&lt;/LI&gt;
&lt;/UL&gt;</description>
      <pubDate>Mon, 21 Jun 2021 17:20:17 GMT</pubDate>
      <guid>https://community.qlik.com/t5/Official-Support-Articles/Qlik-Sense-on-Windows-Configuring-and-testing-LDAP-filters-for/ta-p/1713947</guid>
      <dc:creator>Andre_Sostizzo</dc:creator>
      <dc:date>2021-06-21T17:20:17Z</dc:date>
    </item>
    <item>
      <title>Re: Qlik Sense on Windows: Configuring and testing LDAP filters for User Directory Connector</title>
      <link>https://community.qlik.com/t5/Official-Support-Articles/Qlik-Sense-on-Windows-Configuring-and-testing-LDAP-filters-for/tac-p/2437819#M13672</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Please follow the below steps&amp;nbsp;&lt;/P&gt;
&lt;P&gt;1. Create a Security Group (like Data Analytics) and add those users.&lt;/P&gt;
&lt;P&gt;2.&amp;nbsp;&lt;SPAN&gt;Navigate in the QMC to&amp;nbsp;&lt;/SPAN&gt;&lt;STRONG&gt;User Directory Connectors&lt;/STRONG&gt;&lt;SPAN&gt;&amp;nbsp;&amp;gt;&amp;nbsp;edit the pre-existing&amp;nbsp;&lt;/SPAN&gt;&lt;STRONG&gt;Active Directory&lt;/STRONG&gt;&lt;SPAN&gt;&amp;nbsp;Connector &amp;gt; ensure that the&amp;nbsp;&lt;/SPAN&gt;&lt;STRONG&gt;Advanced&lt;/STRONG&gt;&lt;SPAN&gt;&amp;nbsp;section is displayed and paste in the LDAP filter. At this step you should unselect the&amp;nbsp;&lt;/SPAN&gt;&lt;STRONG&gt;Sync user data for existing users&lt;/STRONG&gt;&lt;SPAN&gt;&amp;nbsp;toggle:&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Additional LDAP Filer :-&amp;nbsp;(memberOf=CN=Data Analytics,OU=Qlik,DC=ABC,DC=local)&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Thanks&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Sanjeev Gupta&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 04 Apr 2024 11:01:30 GMT</pubDate>
      <guid>https://community.qlik.com/t5/Official-Support-Articles/Qlik-Sense-on-Windows-Configuring-and-testing-LDAP-filters-for/tac-p/2437819#M13672</guid>
      <dc:creator>sanjeev_gupta10</dc:creator>
      <dc:date>2024-04-04T11:01:30Z</dc:date>
    </item>
  </channel>
</rss>

