Skip to main content
Announcements
Qlik Community Office Hours, March 20th. Former Talend Community users, ask your questions live. SIGN UP
cancel
Showing results for 
Search instead for 
Did you mean: 
mehdibassam
Partner - Contributor III
Partner - Contributor III

Syncing Active Directory groups while using ADFS on QlikSense

We have successfully deployed ADFS on QlikSense and using it at the moment. However we are trying to set up license allocation and access rules based on AD groups. We are having some trouble as the AD groups for the ADFS users are not being synced to QLikSense.

Do i need to do something on the ADFS side to get the AD Groups for users to carry through to QlikSense?

Labels (7)
1 Reply
Levi_Turner
Employee
Employee

Option (1), align the user directory and userId to match the user directory and userId which is found in AD (aka do not have DOMAIN\user and domain\user@domain.tld as users inside of Qlik Sense). For a general pointer in this direction: https://community.qlik.com/t5/New-to-Qlik-Sense/How-to-retain-user-security-rules-when-transitioning...

For ADFS specific guidance, I am using this on my end.

  • UserID: SAM-Account-Name as Common Name:

Common_Name.png

Sense:

sense.png

Option (2), pass the group memberships in the SAML assertion (https://community.qlik.com/t5/Qlik-Design-Blog/User-Environment-What-Session-Attributes-in-Qlik-Sens...). I am doing it like so in ADFS:

ADFS:

adfs-groups.png

Sense:

groups.png

 

Do note with the session groups, the security (or license) rule syntax is going to be different.