Skip to main content Skip to complementary content

Migrating users, groups, rules, and user allocations

Users and groups

Do this before users log in for the first time if you need to assign space permissions (by users).

  1. In the Migration App, on the Users sheet, open the Users for Export.

  2. Filter the users you want to migrate, click Export, and save as users.csv

  3. Run CLI script 1_setusers.ps1

  • User definitions are added to the tenant as users log in.

    • Prepopulate if you need to assign space permissions (by user) before users log in for the first time.

    • Prepopulate Users using CLI script 1_setusers.ps1

  • Group definitions are added to the tenant as users log in.

Configuring the identity provider

When configuring the identity provider (IdP), the subject is likely to have the format DOMAIN\USERID, if you are using Active Directory. When migrating, you need to ensure that either the IdP you move to continues to provide that same format, or you will need to import the users with whatever new subject the IdP is using.

Other formats:

  • User Principal Name (UPN): UserID@DOMAIN

  • SAML: can vary, but often is the email address.

The IdPs don't need to be the same as long as the user matches.

Example with a mismatching IdP subject (left) and a matching one (right).

Administrative roles

Identify and assign users and groups to admin/user roles. In most cases you want users to have the same roles as before, and so you can create a list that maps the users to a role similar to what they had in Qlik Sense Enterprise on Windows.

Mapping roles in Qlik Sense Client-Managed to Qlik Cloud

This is the recommended mapping of roles in Qlik Sense Client-Managed to roles in Qlik Cloud. Use the Roles tab in the Migration Worksheet for planning help.

  • Content Admin > Analytics Admin

  • Deployment Admin > Tenant Admin

  • Root Admin > Tenant Admin

  • Security Admin > Tenant Admin

  • Audit Admin > Audit Admin

  • Custom roles > Qlik Cloud roles and permissions

Additional roles

The following roles are not admin roles, but roles assigned to users who need permission to create shared, managed, or data spaces, or generate API keys. You can have more than one of these roles.

  • Shared space creator: can create shared spaces

    • Project team users, Collaborators, BI Admins, Developers

  • Managed space creator: can create managed spaces

    • BI Admins, IT

  • Data space creator: can create data spaces

  • Developer: can generate API keys

Security rules in Qlik Sense Client-Managed

Use the Security Rules tab in the Migration Worksheet for planning help.

  1. Look through your Qlik Sense Client-Managed security rules, and note any groups used. The worksheet shows mapping from default rules to Qlik Cloud.

  2. Note custom rules and define the business process around these.

  3. Note the groups all of these rules are using as they will be used in Qlik Cloud.

Entitlements

Use the Licenses tab in the Migration Worksheet for planning help.

Qlik Sense Client-Managed Qlik Cloud
Professional Professional
Analyzer Analyzer
Analyzer Capacity Analyzer Capacity
Qlik Analytics Platform/Qlik Core Analyzer Capacity

Visit the discussion forum at community.qlik.com

Did this page help you?

If you find any issues with this page or its content – a typo, a missing step, or a technical error – let us know how we can improve!