No "Invite User" option and I can't change roles

I am a QS admin, but I can’t add users through QS. The only way for me to add users is to add them to our “Quicksight Production” group on AWS IAM, and then I have to go to one of the dashboard, click “Share”, and pick a user as viewer/co-owner. They’re automatically placed into “Admins” and I can switch them to “Authors”, but not “Readers”. I really need to be able to switch them to “Readers” at least, and possibly add them through QS as well, instead of this strange “Share Dashboard” workaround. Thanks.

qs2

when you register QuickSight subscription at the very beginning, you can choose whether you want to use IAM user only, QuickSight user only or both. If you cannot add users in QuickSight console, may be you have selected IAM only at the very beginning. Suggest you raising a support ticket to double check if it is the case

1 Like

@bogdan_laban , This sounds like an issue that we will need more information to dig into. We need to understand 1/ authentication mode you are using , seems you are defaulted to IAM only option 2/ Looks like your IAM role does only use CreateAdmin function. You will need role to also use CreateReader function.
You might need groups associated to respective role to self provision - Admin privileges will require CreateAdmin action , Author privileges need CreateUser and Reader need to be mapped to CreateReader.Once you have set up in place then seamlessly users are added to QuickSight with authorized roles.

Here are the steps to open a support case so that we can help you further: Creating support cases and case management - AWS Support. If your company has an internal IT team, you might not have direct access to AWS Support and will need to raise an internal ticket to your IT team. They’ll open an AWS Support case on your behalf.

Does this answer your question? If so, please help the community out by marking this answer as ‘Solution.’

Hi @bogdan_laban - Did @Neeraj solution work for you? I am marking his reply as, “Solution,” but let us know if this is not resolved. Thanks for posting your questions on the QuickSight Community Q&A Forum!

@Neeraj @royyung @spaluri This sadly did not help. The “quicksight-sso” role already have everything allowed (quicksight:* + other things). I still can’t get it to work.