We recently converted over to Qliksense Saas using azure AD as our identity provider.
Previsoulsy in Qlikview and Qliksense on premise, we were using LDAP for user identity authentication.
Simultaneously for user access we created Windows AD groups for users that had access to Qlikview/Qliksense
In qliksense you were able to create an connection to LDAP and query specific AD groups to filter down to Qlik users. From that list you could proactively provision and assign a professional or analyzer license within the Qlik console before they connected to Qlik.
In Saas, there is not an option to provision users. Today we have to turn on Entitlements for dynamic assignment of professional and Analyzer users.
We would like to provision users first and prevent other users for gaining access to the Saas and taking up a license without the proper permissions and associations to the correct AD group.