Switching from Qlik Account to a corporate IdP configuration
Transition from Qlik Account to a corporate Identity Provider (IdP) of your choice, migrating users based on their email addresses.
The corporate IdP must support either OpenID Connect (OIDC) or SAML protocols.
Removing Section Access table before configuring the corporate IdP
Before you configure your corporate IdP, you must remove or comment out the Section Access table from all apps, and perform a reload afterward.
After activating the corporate IdP, you can recreate the removed Section Access table, or remove the previously added comments, using the new identities provided from the newly-configured IdP. Again, a reload is needed to reactivate the table in the data model.
For information about section access, see Managing data security with Section Access.
Configuring the corporate IdP
Configuring a corporate IdP after you have been using Qlik Account for some time may require you to give special attention to the following in order to map content (apps, spaces, etc.) for your invited Qlik Account users switching over to the corporate IdP.
Do the following:
-
Configure the interactive IdP in the Administration activity center, see Identity providers.
-
Test the verification flow and ensure the result is successful. As a tenant admin, manually verify that the email and email_verified claims are present and with a value of true. This is important for successfully mapping content after the switch. Do not activate the IdP yet.
-
Examine the Users list for the tenant via the Administration activity center.
-
Identify users whose current email address does not match the corporate email address. When you switch IdPs to preserve content, the email addresses should match.
-
For users who do not have a matching email address, the tenant admin needs to manually move content to the new account.
-
Again, check the user list via the Administration activity center and verify that the correct corporate email addresses are now assigned to all users.
-
Activate the interactive IdP.
-
Open a new browser instance or an incognito window, to avoid conflict with existing login sessions. Access the tenant URL (<tenant>.<region>.qlikcloud.com/login) and verify that it takes you to the new interactive IdP.
-
Log in and access the activity center. Verify that Qlik Account content remains available to the user.
-
Open the Administration activity center and verify that the user has the new IdP subject assigned to their existing User ID.
-
Verify that the license assignments in the Administration activity center are still set correctly for all the users who have logged into the new corporate IdP.
-
Recreate the Section Access tables, see Removing Section Access table before configuring the corporate IdP.