You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Copy file name to clipboardExpand all lines: articles/active-directory/saas-apps/qliksense-enterprise-tutorial.md
+49-44Lines changed: 49 additions & 44 deletions
Display the source diff
Display the rich diff
Original file line number
Diff line number
Diff line change
@@ -12,9 +12,8 @@ ms.service: active-directory
12
12
ms.subservice: saas-app-tutorial
13
13
ms.workload: identity
14
14
ms.tgt_pltfrm: na
15
-
ms.devlang: na
16
15
ms.topic: tutorial
17
-
ms.date: 06/06/2019
16
+
ms.date: 03/03/2020
18
17
ms.author: jeedes
19
18
20
19
ms.collection: M365-identity-device-management
@@ -28,7 +27,7 @@ In this tutorial, you'll learn how to integrate Qlik Sense Enterprise with Azure
28
27
* Enable your users to be automatically signed-in to Qlik Sense Enterprise with their Azure AD accounts.
29
28
* Manage your accounts in one central location - the Azure portal.
30
29
31
-
To learn more about SaaS app integration with Azure AD, see [What is application access and single sign-on with Azure Active Directory](https://docs.microsoft.com/azure/active-directory/active-directory-appssoaccess-whatis).
30
+
To learn more about SaaS app integration with Azure AD, see [What is application access and single sign-on with Azure Active Directory](https://docs.microsoft.com/azure/active-directory/what-is-single-sign-on).
32
31
33
32
## Prerequisites
34
33
@@ -39,7 +38,11 @@ To get started, you need the following items:
39
38
40
39
## Scenario description
41
40
42
-
In this tutorial, you configure and test Azure AD SSO in a test environment. Qlik Sense Enterprise supports **SP** initiated SSO.
41
+
In this tutorial, you configure and test Azure AD SSO in a test environment.
42
+
* Qlik Sense Enterprise supports **SP** initiated SSO.
43
+
* Qlik Sense Enterprise supports **just-in-time provisioning**
44
+
45
+
* Once you configure Qlik Sense Enterprise you can enforce Session control, which protect exfiltration and infiltration of your organization’s sensitive data in real-time. Session control extend from Conditional Access. [Learn how to enforce session control with Microsoft Cloud App Security](https://docs.microsoft.com/cloud-app-security/proxy-deployment-aad)
43
46
44
47
## Adding Qlik Sense Enterprise from the gallery
45
48
@@ -59,11 +62,11 @@ Configure and test Azure AD SSO with Qlik Sense Enterprise using a test user cal
59
62
To configure and test Azure AD SSO with Qlik Sense Enterprise, complete the following building blocks:
60
63
61
64
1.**[Configure Azure AD SSO](#configure-azure-ad-sso)** - to enable your users to use this feature.
62
-
2.**[Configure Qlik Sense Enterprise SSO](#configure-qlik-sense-enterprise-sso)** - to configure the Single Sign-On settings on application side.
63
-
3.**[Create an Azure AD test user](#create-an-azure-ad-test-user)** - to test Azure AD single sign-on with Britta Simon.
64
-
4.**[Assign the Azure AD test user](#assign-the-azure-ad-test-user)** - to enable Britta Simon to use Azure AD single sign-on.
65
-
5.**[Create Qlik Sense Enterprise test user](#create-qlik-sense-enterprise-test-user)** - to have a counterpart of Britta Simon in Qlik Sense Enterprise that is linked to the Azure AD representation of user.
66
-
6.**[Test SSO](#test-sso)** - to verify whether the configuration works.
65
+
***[Create an Azure AD test user](#create-an-azure-ad-test-user)** - to test Azure AD single sign-on with Britta Simon.
66
+
***[Assign the Azure AD test user](#assign-the-azure-ad-test-user)** - to enable Britta Simon to use Azure AD single sign-on.
67
+
1.**[Configure Qlik Sense Enterprise SSO](#configure-qlik-sense-enterprise-sso)** - to configure the Single Sign-On settings on application side.
68
+
***[Create Qlik Sense Enterprise test user](#create-qlik-sense-enterprise-test-user)** - to have a counterpart of Britta Simon in Qlik Sense Enterprise that is linked to the Azure AD representation of user.
69
+
1.**[Test SSO](#test-sso)** - to verify whether the configuration works.
67
70
68
71
### Configure Azure AD SSO
69
72
@@ -79,7 +82,7 @@ Follow these steps to enable Azure AD SSO in the Azure portal.
79
82
80
83
a. In the **Sign-on URL** textbox, type a URL using the following pattern: `https://<Fully Qualified Domain Name>:443{/virtualproxyprefix}/hub`
81
84
82
-
b. In the **Identifier** textbox, type a URL using the following pattern:
85
+
b. In the **Identifier** textbox, type a URL using one of the following pattern:
83
86
84
87
||
85
88
|--|
@@ -98,7 +101,37 @@ Follow these steps to enable Azure AD SSO in the Azure portal.
1. Select the **Show password** check box, and then write down the value that's displayed in the **Password** box.
114
+
1. Click **Create**.
115
+
116
+
### Assign the Azure AD test user
117
+
118
+
In this section, you'll enable Britta Simon to use Azure single sign-on by granting access to Qlik Sense Enterprise.
119
+
120
+
1. In the Azure portal, select **Enterprise Applications**, and then select **All applications**.
121
+
1. In the applications list, select **Qlik Sense Enterprise**.
122
+
1. In the app's overview page, find the **Manage** section and select **Users and groups**.
123
+
124
+

125
+
126
+
1. Select **Add user**, then select **Users and groups** in the **Add Assignment** dialog.
127
+
128
+

129
+
130
+
1. In the **Users and groups** dialog, select **Britta Simon** from the Users list, then click the **Select** button at the bottom of the screen.
131
+
1. If you're expecting any role value in the SAML assertion, in the **Select Role** dialog, select the appropriate role for the user from the list and then click the **Select** button at the bottom of the screen.
132
+
1. In the **Add Assignment** dialog, click the **Assign** button.
133
+
134
+
## Configure Qlik Sense Enterprise SSO
102
135
103
136
1. Prepare the Federation Metadata XML file so that you can upload that to Qlik Sense server.
104
137
@@ -215,52 +248,24 @@ Follow these steps to enable Azure AD SSO in the Azure portal.
215
248
216
249
![QlikSense][qs53]
217
250
218
-
### Create an Azure AD test user
219
-
220
-
In this section, you'll create a test user in the Azure portal called Britta Simon.
221
-
222
-
1. From the left pane in the Azure portal, select **Azure Active Directory**, select **Users**, and then select **All users**.
223
-
1. Select **New user** at the top of the screen.
224
-
1. In the **User** properties, follow these steps:
1. Select the **Show password** check box, and then write down the value that's displayed in the **Password** box.
228
-
1. Click **Create**.
229
-
230
-
### Assign the Azure AD test user
231
-
232
-
In this section, you'll enable Britta Simon to use Azure single sign-on by granting access to Qlik Sense Enterprise.
233
-
234
-
1. In the Azure portal, select **Enterprise Applications**, and then select **All applications**.
235
-
1. In the applications list, select **Qlik Sense Enterprise**.
236
-
1. In the app's overview page, find the **Manage** section and select **Users and groups**.
237
-
238
-

239
-
240
-
1. Select **Add user**, then select **Users and groups** in the **Add Assignment** dialog.
241
-
242
-

243
-
244
-
1. In the **Users and groups** dialog, select **Britta Simon** from the Users list, then click the **Select** button at the bottom of the screen.
245
-
1. If you're expecting any role value in the SAML assertion, in the **Select Role** dialog, select the appropriate role for the user from the list and then click the **Select** button at the bottom of the screen.
246
-
1. In the **Add Assignment** dialog, click the **Assign** button.
247
-
248
251
### Create Qlik Sense Enterprise test user
249
252
250
-
In this section, you create a user called Britta Simon in Qlik Sense Enterprise. Work with [Qlik Sense Enterprise support team](https://www.qlik.com/us/services/support) to add the users in the Qlik Sense Enterprise platform. Users must be created and activated before you use single sign-on.
253
+
Qlik Sense Enterprise supports **just-in-time provisioning**, Users automatically added to the 'USERS' repository of Qlik Sense Enterprise as they use the SSO feature. In addition, clients can use the QMC and create a UDC (User Directory Connector) for pre-populating users in Qlik Sense Enterprise from their LDAP of choice such as Active Directory, and others.
251
254
252
255
### Test SSO
253
256
254
257
When you select the Qlik Sense Enterprise tile in the Access Panel, you should be automatically signed in to the Qlik Sense Enterprise for which you set up SSO. For more information about the Access Panel, see [Introduction to the Access Panel](https://docs.microsoft.com/azure/active-directory/active-directory-saas-access-panel-introduction).
255
258
256
-
## Additional Resources
259
+
## Additional resources
257
260
258
261
-[List of Tutorials on How to Integrate SaaS Apps with Azure Active Directory](https://docs.microsoft.com/azure/active-directory/active-directory-saas-tutorial-list)
259
262
260
-
-[What is application access and single sign-on with Azure Active Directory?](https://docs.microsoft.com/azure/active-directory/active-directory-appssoaccess-whatis)
263
+
-[What is application access and single sign-on with Azure Active Directory?](https://docs.microsoft.com/azure/active-directory/what-is-single-sign-on)
261
264
262
265
-[What is Conditional Access in Azure Active Directory?](https://docs.microsoft.com/azure/active-directory/conditional-access/overview)
263
266
267
+
-[What is session control in Microsoft Cloud App Security?](https://docs.microsoft.com/cloud-app-security/proxy-intro-aad)
0 commit comments