Note This feature is only available when you either use SAML or OAuth/OpenID for authentication
To grant license on sign-in with SAML- Login to the backend of your Curator instance (e.g.
http://curatorexample.com/backend). - Navigate to the Settings > Tableau > Tableau Server Settings section from the left-hand menu.
- In the Authentication tab, expand the SAML Advanced section and enable the “License Users if Unlicensed” toggle.
- Login to the backend of your Curator instance (e.g.
http://curatorexample.com/backend). - Navigate to the Settings > Tableau > Tableau Server Settings section from the left-hand menu.
- In the Authentication tab, expand the Customization section and enable the “License Users if Unlicensed” toggle.
Active Directory and LDAP Group-Managed Licenses
When Tableau Server is configured to sync licenses through Active Directory (AD) or LDAP groups, the license lifecycle is managed by Tableau’s own group sync process rather than by Curator. This creates an important distinction in how automatic license provisioning behaves. Direct license removal vs. AD/LDAP group removal:- Direct removal — If a user’s Tableau license is removed directly (e.g., by an administrator setting the user to Unlicensed in Tableau Server), Curator’s “License Users if Unlicensed” feature can automatically restore the license the next time the user signs in.
- AD/LDAP group removal — If a user’s license is removed because they were removed from an AD or LDAP group that grants a Tableau site role, Tableau Server manages the license through its group sync schedule. Even after the user is re-added to the AD group, the license is not restored until Tableau Server completes its next group sync. Curator cannot override this because Tableau’s AD/LDAP sync controls the site role assignment for group-managed users.
Troubleshooting: License Not Restored After AD Group Re-Addition
If a user was removed from an AD or LDAP group and then re-added but still cannot access Curator, verify the following:- Confirm the user is back in the AD/LDAP group. Check with your directory administrator that the group membership change has replicated across all domain controllers.
- Wait for Tableau Server’s group sync to complete. Tableau syncs AD/LDAP groups on a schedule configured by your Tableau Server administrator. The user’s license will not be restored until this sync runs. You can check the sync schedule in Tableau Server > Settings > General under the group sync section.
- Manually trigger a group sync if needed. A Tableau Server administrator can manually sync groups from the Groups page in Tableau Server to restore the user’s site role without waiting for the next scheduled sync.
- Verify the user’s site role in Tableau Server. After the sync completes, confirm the user has been assigned the expected site role (e.g., Viewer, Explorer) in Tableau Server’s Users list.
- Have the user sign in to Curator again. Once the Tableau license is restored through the group sync, the user should be able to access Curator normally.