There's no restriction. It's simply that your browser presents the AD account credentials to the qlik sense proxy and if that proxy is configured to use AD then you'll be authenticated using the AD account credentials. If you don't want that then configure the proxy to use another user directory that doesn't use AD accounts.
We have similar requirements in our environment and still in progress of exploring.
What we have done includes:
Create second virtual proxy serving different needs.
- First proxy is using default for AD users along with system repository services.
- Second proxy is with a prefix using FORM login.
To add second Proxy, you need to specify a PREFIX (e.g. using selflogin) in the setting and change Windows Authentication pattern under Authentication from WINDOWS to FORMS. Release this different URL to those on self login (e.g. bi.domain.com/selflogin/hub)
When we access using the second proxy, we faced " load balancing module did not return any engine service'
We think we are heading the right direction and fixing the above should solve the requirements.
Any lights in this?