Do not input private or sensitive data. View Qlik Privacy & Cookie Policy.
Skip to main content

Announcements
Streamlining user types in Qlik Cloud capacity-based subscriptions: Read the Details
cancel
Showing results for 
Search instead for 
Did you mean: 
jalanhart
Creator
Creator

Section Access Active Directory groups

Hello, 

 

I have figured out how to use section access using an inline "ACCESS, USER.EMAIL, REDUCTION" type format. but with a lot of users that's tedious. So we want to use AD groups instead. 

So we created a group called 03qlik that has me in it and i set that to admin / all, and another user in a group called 14qlik and reduction to one only some data. it's telling that that access has been denied on reload. 

What is the syntax for Azure AD groups? i was using "ACCESS, GROUP, REDUCTION" and then i tried just the name, the domain\name, the domain.com\name. those all did not work. i also tried user.email and the email address of the group and that did not work either. 

 

Help would be appreciated! thanks

Labels (4)
1 Reply
Miguel_Angel_Baeyens

If this is Qlik Sense Enterprise on Windows, make sure that the your account in Qlik Sense is retrieving the groups. One way to check that is going to the QMC > Users, look up for your account and click on the "i" icon at the right of the first column for the user ID. If you see groups there, make sure that those are written the same in the section access table.

If the groups are not there, you will need to set up a user directory connector, or any other way to make sure that the groups for your account are sent to Qlik Sense. An example on how to set up a virtual proxy to use SAML: https://community.qlik.com/t5/Official-Support-Articles/Example-auth0-SAML-setup-with-Qlik-Sense-Ent....

If you are using Qlik Cloud, the Identity Provider must have a claim to send the groups. An example for Azure Active Directory is here: https://community.qlik.com/t5/Official-Support-Articles/How-To-Configure-Qlik-Sense-Enterprise-SaaS-....