Skip to main content

Permissions required for Active Directory

This article provides the permissions that Druva needs to back up and restore Active Directory data.

Updated today

Here is the list of permissions required for Active Directory Backup and Restore actions.

Action

Required Permissions

For Granular Backup

  • Core AD Partitions:

    • Read permissions on the domain.

    • Read permissions on the Configuration partition.

    • Read permissions on the Schema partition.

  • Specific Containers/Zones:

    • Access to the System container (required for trusts).

    • Access to DomainDnsZones (required for DNS zones).

  • Standard AD Objects:

    • Standard LDAP read access to backup Users, Groups, Organizational Units (OUs), and Computers.

  • Group Policy Objects (GPOs):

    • Group Policy read permissions to backup GPOs.

For Granular Restore

  • Object Creation/Modification:

    • Write permissions on AD to Create/update objects (User, Group, Computer, Contact, OU).

  • OU Creation and General Restore: Domain Admin rights are necessary for creating new OUs and performing general restore operations.

For System State Backup

  • Shared Folder Access:

    • Read and write NTFS permissions on the designated shared folder.

  • Storage Space:

    • Sufficient storage space in the shared path to accommodate the local system state backup.

  • Wbadmin Tool:The Wbadmin tool must be installed, and the account must have permission to execute it.

Did this answer your question?