Migrating users, groups, rules, and user allocations
Users and groups
Do this before users log in for the first time if you need to assign space permissions (by users).
-
In the Migration App, on the Users sheet, open the Users for Export.
-
Filter the users you want to migrate, click Export, and save as users.csv
-
Run CLI script 1_setusers.ps1
-
User definitions are added to the tenant as users log in.
-
Prepopulate if you need to assign space permissions (by user) before users log in for the first time.
-
Prepopulate Users using CLI script 1_setusers.ps1
-
-
Group definitions are added to the tenant as users log in.
Configuring the identity provider
When configuring the identity provider (IdP), the subject is likely to have the format DOMAIN\USERID, if you are using Active Directory. When migrating, you need to ensure that either the IdP you move to continues to provide that same format, or you will need to import the users with whatever new subject the IdP is using.
Other formats:
-
User Principal Name (UPN): UserID@DOMAIN
-
SAML: can vary, but often is the email address.
The IdPs don't need to be the same as long as the user matches.
Administrative roles
Identify and assign users and groups to admin/user roles. In most cases you want users to have the same roles as before, and so you can create a list that maps the users to a role similar to what they had in Qlik Sense Enterprise on Windows.
Mapping roles in Qlik Sense Client-Managed to Qlik Cloud
This is the recommended mapping of roles in Qlik Sense Client-Managed to roles in Qlik Cloud. Use the Roles tab in the Migration Worksheet for planning help.
-
Content Admin > Analytics Admin
-
Deployment Admin > Tenant Admin
-
Root Admin > Tenant Admin
-
Security Admin > Tenant Admin
-
Audit Admin > Audit Admin
-
Custom roles > Qlik Cloud roles and permissions
Additional roles
The following roles are not admin roles, but roles assigned to users who need permission to create shared, managed, or data spaces, or generate API keys. You can have more than one of these roles.
-
Shared space creator: can create shared spaces
-
Project team users, Collaborators, BI Admins, Developers
-
-
Managed space creator: can create managed spaces
-
BI Admins, IT
-
-
Data space creator: can create data spaces
-
Developer: can generate API keys
Security rules in Qlik Sense Client-Managed
Use the Security Rules tab in the Migration Worksheet for planning help.
-
Look through your Qlik Sense Client-Managed security rules, and note any groups used. The worksheet shows mapping from default rules to Qlik Cloud.
-
Note custom rules and define the business process around these.
-
Note the groups all of these rules are using as they will be used in Qlik Cloud.
Entitlements
Use the Licenses tab in the Migration Worksheet for planning help.
Qlik Sense Client-Managed | Qlik Cloud |
---|---|
Professional | Professional |
Analyzer | Analyzer |
Analyzer Capacity | Analyzer Capacity |
Qlik Analytics Platform/Qlik Core | Analyzer Capacity |