Skip to main content
Announcements
Join us at Qlik Connect for 3 magical days of learning, networking,and inspiration! REGISTER TODAY and save!

How to Setup Multi-Factor Authentication (MFA) for Qlik Sense Business

No ratings
cancel
Showing results for 
Search instead for 
Did you mean: 
Andre_Sostizzo
Digital Support
Digital Support

How to Setup Multi-Factor Authentication (MFA) for Qlik Sense Business

Last Update:

Oct 20, 2023 4:46:53 AM

Updated By:

Sonja_Bauernfeind

Created date:

Nov 12, 2019 6:09:08 AM



Multi-factor authentication (MFA) is an extra layer of security to access Qlik Sense Business.

It:

  • Is Optional for Service Account Owner (SAO) with a paid Qlik Sense Business Subscription. 
  • Is Optional for Invitees and Tenant Admins
  • Can be disabled at any time
If you require MFA to be mandatory, a Qlik Sense SaaS Enterprise subscription allows for the use of a third party IdP (Identity Provider), which provides you with additional control over authentication methods.

MFA is not supported in Qlik Sense on-premise installations. See Configuring security > Authentication.
 

Resolution:

  1. Access to My Qlik Portal How to Access My Qlik Portal
  2. Go to Password & Security
  3. Click on Setup

    01.png

  4. Install a Multi Factor Authentication (MFA) on phone. There are several on the market, (Google Authenticator - LastPass Authenticator - Microsoft Authenticator and more)

    Note: Using just a QR reader will not work, Only a MFA Authetication app will.
     
  5. Scan the QR code with your MFA Authenticator

    How to Setup Multi-Factor Authentication02.png

  6. Proceeded to use the code created from MFA authenticator 
  7. You are given an important recovery link. The link is ONE time use - IMPORTANT - Save this code for recovery purposes *

    How to Setup Multi-Factor Authentication03.png

  8. You will see that the MFA is successfully set.

    How to Setup Multi-Factor Authentication.jpg

    * If you see yourself the need to use the MFA Recovery code, Note that a new one will be generated. Please save the last one generated.

  9. If in the future MFA needs to be disabled, navigate to the same screen and click "Remove"...

    How to Setup Multi-Factor Authenticatio02.jpg

  10. Click "Yes, remove"

    How to Setup Multi-Factor Authentication03.jpg

 

 

FAQ

Q - What happens if SAO is MFA locked out due to (Change of device or lost)?
A - SAO Can use the Recovery Code generated in setting up the MFA.

Q - What happens if SAO looses the MFA Recovery link or does not save the new generated one.
A - Please contact Qlik Customer Support to reset MFA How to create a case

Q - Can a user setup MFA without a mobile?
A - Yes, there are desktop options fro Google authenticator.
 

Related content:

SAML configuration with Okta (Qlik Help)
Qlik Sense SAML: Okta Configuration (YouTube)

Tags (1)
Labels (1)
Comments
WayneH-RNNZ
Contributor
Contributor

As a test user, not being able to test or validate SSO has a bearing on useability. I have a customer that is moving to QSense, and we cannot test to see if there are any issues, one way or the other. i have a dummy M365 tenant, and a dummy QSense account.

and in the non-integrated environment, how hard would it be to put in a setting to say, "all new users have MFA enabled" and stop the ability for end users to remove the MFA requirement.

Daniele_Purrone
Support
Support

Hi @WayneH-RNNZ we understand the requirement and are actively engaging our product team so that they make a decision. In the meantime, please engage our sales department and request a Qlik Sense Enterprise trial instead of a Qlik Sense Business one.  That way you will be able to test and validate single sign on via any IDP of your choosing.

retretrt
Contributor II
Contributor II

@Daniele_Purrone thank you for clearing. Was not aware and will set up with IP

random_user_3869
Partner - Creator III
Partner - Creator III

Hello everyone,

i see that it is possible to enable individual users to use MFA.

What i would like to know if it's possible to enforce all users to use MFA.

The users of our tenant come from a custom IDP.

So what would be the next step in order to achieve that ?

Is that even possible ?

 

Thank you

Sonja_Bauernfeind
Digital Support
Digital Support

Hello @random_user_3869 

This article documents the use of MFA when QlikID is used as an IDP. If you have your own Identity Provider (IDP), control over Multi Factor Authentication sits with your IDP. You will need to investigate whether or not your IDP supports your requirement. 

All the best,
Sonja 

random_user_3869
Partner - Creator III
Partner - Creator III

Thank you @Sonja_Bauernfeind  for your comment.

My question is : how to know that MFA is compatible with my IDP ?

If it is then are there any setup to perfom on the qlik cloud side ?

Ay documentaiton on this topic anywhere ?

Thank you for your response

Sonja_Bauernfeind
Digital Support
Digital Support

Hello @random_user_3869 

You will need to speak with your IDP provider to see how they set up Multi Factor Authentication. This is entirely done on your/the Identity Provider's end. Example: If you are using Okta as your IDP, investigate what options Okta has in regards to MFA.

You mentioned you are are already using a third-party IDP, but here are the resources around setting one up regardless:

Setting up identity providers 
Switching from Qlik Account to a corporate IdP configuration 

This article (and any setup of MFA in QlikID) are not relevant if you use a third party provider.

All the best,
Sonja 

Version history
Last update:
‎2023-10-20 04:46 AM
Updated by: