Unlock a world of possibilities! Login now and discover the exclusive benefits awaiting you.
Oct 20, 2023 4:46:53 AM
Nov 12, 2019 6:09:08 AM
It:
If you require MFA to be mandatory, a Qlik Sense SaaS Enterprise subscription allows for the use of a third party IdP (Identity Provider), which provides you with additional control over authentication methods.
MFA is not supported in Qlik Sense on-premise installations. See Configuring security > Authentication.
FAQ
Q - What happens if SAO is MFA locked out due to (Change of device or lost)?
A - SAO Can use the Recovery Code generated in setting up the MFA.
Q - What happens if SAO looses the MFA Recovery link or does not save the new generated one.
A - Please contact Qlik Customer Support to reset MFA How to create a case
Q - Can a user setup MFA without a mobile?
A - Yes, there are desktop options fro Google authenticator.
SAML configuration with Okta (Qlik Help)
Qlik Sense SAML: Okta Configuration (YouTube)
As a test user, not being able to test or validate SSO has a bearing on useability. I have a customer that is moving to QSense, and we cannot test to see if there are any issues, one way or the other. i have a dummy M365 tenant, and a dummy QSense account.
and in the non-integrated environment, how hard would it be to put in a setting to say, "all new users have MFA enabled" and stop the ability for end users to remove the MFA requirement.
Hi @WayneH-RNNZ we understand the requirement and are actively engaging our product team so that they make a decision. In the meantime, please engage our sales department and request a Qlik Sense Enterprise trial instead of a Qlik Sense Business one. That way you will be able to test and validate single sign on via any IDP of your choosing.
@Daniele_Purrone thank you for clearing. Was not aware and will set up with IP
Hello everyone,
i see that it is possible to enable individual users to use MFA.
What i would like to know if it's possible to enforce all users to use MFA.
The users of our tenant come from a custom IDP.
So what would be the next step in order to achieve that ?
Is that even possible ?
Thank you
Hello @random_user_3869
This article documents the use of MFA when QlikID is used as an IDP. If you have your own Identity Provider (IDP), control over Multi Factor Authentication sits with your IDP. You will need to investigate whether or not your IDP supports your requirement.
All the best,
Sonja
Thank you @Sonja_Bauernfeind for your comment.
My question is : how to know that MFA is compatible with my IDP ?
If it is then are there any setup to perfom on the qlik cloud side ?
Ay documentaiton on this topic anywhere ?
Thank you for your response
Hello @random_user_3869
You will need to speak with your IDP provider to see how they set up Multi Factor Authentication. This is entirely done on your/the Identity Provider's end. Example: If you are using Okta as your IDP, investigate what options Okta has in regards to MFA.
You mentioned you are are already using a third-party IDP, but here are the resources around setting one up regardless:
Setting up identity providers
Switching from Qlik Account to a corporate IdP configuration
This article (and any setup of MFA in QlikID) are not relevant if you use a third party provider.
All the best,
Sonja