Prerequisite:
I. Qlik Sense Service account is a domain user and a member of local Administrators group.
II. Qlik Sense Administrator account is a domain user and a member of local Administrators group.
III. Create these domain groups with appropriate members
1) QSUserAccess
2) QSLoginAccess
NOTE: The administrator account should be a member of both groups
e.g.
QSUserAccess = {QSAdmin, User1, User2}
QSLoginAccess = {QSAdmin, User3}
1. QMC > Start > User directory connectors, Press Create new
![User-added image](https://qlik.my.salesforce.com/servlet/servlet.ImageServer?id=015D0000003s7qm&oid=00D20000000IGPX&lastMod=1491380000000)
2. Select Active Directory
![User-added image](https://qlik.my.salesforce.com/servlet/servlet.ImageServer?id=015D0000003s7qr&oid=00D20000000IGPX&lastMod=1491380046000)
3. Name=AD and press Apply
![User-added image](https://qlik.my.salesforce.com/servlet/servlet.ImageServer?id=015D0000003s7qw&oid=00D20000000IGPX&lastMod=1491380061000)
4. Start > Tasks, Select AD_usersynctask, press Start
![User-added image](https://qlik.my.salesforce.com/servlet/servlet.ImageServer?id=015D0000003s7r1&oid=00D20000000IGPX&lastMod=1491380075000)
5. Press
![User-added image](https://qlik.my.salesforce.com/servlet/servlet.ImageServer?id=015D0000003s7r6&oid=00D20000000IGPX&lastMod=1491380094000)
[Refresh] icon and make sure the Status become Success
![User-added image](https://qlik.my.salesforce.com/servlet/servlet.ImageServer?id=015D0000003s7rB&oid=00D20000000IGPX&lastMod=1491380107000)
6. Start > Users, click
next to your user name (e.g. QSAdmin)
Make sure that both QSUserAccess group and QSLoginAccess group are synced
![User-added image](https://qlik.my.salesforce.com/servlet/servlet.ImageServer?id=015D0000003s7rL&oid=00D20000000IGPX&lastMod=1491380157000)
7. Start > License and tokens > User access rules, press Create new
![User-added image](https://qlik.my.salesforce.com/servlet/servlet.ImageServer?id=015D0000003s7rQ&oid=00D20000000IGPX&lastMod=1491380178000)
8. Create user access rule and press Apply
user: userDirectory =
value: <your domain>
AND
user: group =
value: QSUserAccess
![User-added image](https://qlik.my.salesforce.com/servlet/servlet.ImageServer?id=015D0000003s7rV&oid=00D20000000IGPX&lastMod=1491380192000)
9. Start > License and tokens > User login rules, press Create new
![User-added image](https://qlik.my.salesforce.com/servlet/servlet.ImageServer?id=015D0000003s7ra&oid=00D20000000IGPX&lastMod=1491380206000)
10. Create Login access rule and press Apply
IDENTIFICSTION: Login Access
TOKENS: <number>
![User-added image](https://qlik.my.salesforce.com/servlet/servlet.ImageServer?id=015D0000003s7rf&oid=00D20000000IGPX&lastMod=1491380221000)
11. Create license rule and press Apply
user: userDirectory =
value: <your domain>
AND
user: group =
value: QSLoginAccess
AND
user: name !=
value: QSAdmin
![User-added image](https://qlik.my.salesforce.com/servlet/servlet.ImageServer?id=015D0000003s7rk&oid=00D20000000IGPX&lastMod=1491380241000)
Related Topic
Do not un-check "Sync user data for existing users" There is no need to bring all users into Qlik Sense
New users are not added when syncing an User connector in Qlik Sense