Unlock a world of possibilities! Login now and discover the exclusive benefits awaiting you.
We have successfully deployed ADFS on QlikSense and using it at the moment. However we are trying to set up license allocation and access rules based on AD groups. We are having some trouble as the AD groups for the ADFS users are not being synced to QLikSense.
Do i need to do something on the ADFS side to get the AD Groups for users to carry through to QlikSense?
Option (1), align the user directory and userId to match the user directory and userId which is found in AD (aka do not have DOMAIN\user and domain\user@domain.tld as users inside of Qlik Sense). For a general pointer in this direction: https://community.qlik.com/t5/New-to-Qlik-Sense/How-to-retain-user-security-rules-when-transitioning...
For ADFS specific guidance, I am using this on my end.
Sense:
Option (2), pass the group memberships in the SAML assertion (https://community.qlik.com/t5/Qlik-Design-Blog/User-Environment-What-Session-Attributes-in-Qlik-Sens...). I am doing it like so in ADFS:
ADFS:
Sense:
Do note with the session groups, the security (or license) rule syntax is going to be different.