Skip to main content

Permissions required for Active Directory

This article provides the permissions that Druva needs to back up and restore Active Directory data.

Updated over 2 weeks ago

Here is the list of permissions required for Active Directory Backup and Restore actions.

Action

Required Permissions

For Granular Backup

  • Core AD Partitions:

    • Read permissions on the domain.

    • Read permissions on the Configuration partition.

    • Read permissions on the Schema partition.

  • Specific Containers/Zones:

    • Access to the System container (required for trusts).

    • Access to DomainDnsZones (required for DNS zones).

  • Standard AD Objects:

    • Standard LDAP read access to backup Users, Groups, Organizational Units (OUs), and Computers.

  • Group Policy Objects (GPOs):

    • Group Policy read permissions to backup GPOs.

For Granular Restore

  • Object Creation/Modification:

    • Write permissions on AD to Create/update objects (User, Group, Computer, Contact, OU).

  • OU Creation and General Restore: Domain Admin rights are necessary for creating new OUs and performing general restore operations.

For System State Backup

  • Shared Folder Access:

    • Read and write NTFS permissions on the designated shared folder.

  • Storage Space:

    • Sufficient storage space in the shared path to accommodate the local system state backup.

  • Wbadmin Tool:The Wbadmin tool must be installed, and the account must have permission to execute it.

Did this answer your question?