Note
Access to this page requires authorization. You can try signing in or changing directories.
Access to this page requires authorization. You can try changing directories.
Microsoft and Qlik Sense worked together to provide remote access using Microsoft Entra application proxy.
Prerequisites
Publish your applications in Microsoft Entra
To publish Qlik Sense, publish two applications in Azure.
Application #1:
Publish your application in Microsoft Entra. For a more detailed walkthrough of steps 1-8, see Publish applications using Microsoft Entra application proxy.
- Sign in to the Microsoft Entra admin center as at least an Application Administrator.
- Browse to Entra ID > Enterprise apps.
- Select New application at the top of the page.
- Select On-premises application.
- Fill out the required fields with information about your new app.
- Internal URL: This application should have an internal URL that is the Qlik Sense URL itself. For example, https//demo.qlikemm.com:4244.
- Pre-authentication method: Microsoft Entra ID (recommended but not required).
 
- Internal URL: This application should have an internal URL that is the Qlik Sense URL itself. For example, 
- Select Add at the bottom of the page. Your application is added, and the quick start menu opens.
- In the quick start menu, select Assign a user for testing, and add at least one user to the application. Make sure this test account has access to the on premises application.
- Select Assign to save the test user assignment.
- (Optional) On the app management page, select single sign-on. Choose Kerberos Constrained Delegation from the drop-down menu, and fill out the required fields based on your Qlik Sense configuration. Select Save.
Application #2:
Follow the same steps as for Application #1, with the following exceptions:
Step #5: The Internal URL should now be the Qlik Sense URL with the authentication port used by the application. The default is 4244 for HTTPS, and 4248 for HTTP for Qlik Sense releases before April 2018. The default for Qlik Sense releases after April 2018 is 443 for HTTPS and 80 for HTTP. For example, https//demo.qlik.com:4244.
Step #10: Don’t set up single sign-on. Leave the single sign-on option disabled.
Testing
Your application is now ready to test. Access the external URL you used to publish Qlik Sense in Application #1, and sign in as a user assigned to both applications.
References
For more information about publishing Qlik Sense with application proxy, see following the Qlik Community Articles:
- Microsoft Entra ID with integrated Windows authentication using a Kerberos Constrained Delegation with Qlik Sense
- Qlik Sense integration with Microsoft Entra application proxy