---
title: "Role-based Access Control"
canonical: "https://sesame-software-documentation.refined.site/space/bandr/386367508/Role-based%20Access%20Control"
format: markdown
---
**Backup and Recovery** supports user access management through **roles**, **groups**, and integration with **LDAP/AD**, including **Azure Active Directory (AD)**.

---

### ✅ **Configuring Azure AD Groups**

To include Azure AD Groups:

1. Navigate to your **App Details** in Azure.
2. Click **Token configuration**.
3. Add and configure group claims as needed.

---

### 🔑 **Supported Roles**

The product supports **three main roles**:

- **Admin**
- **Manager**
- **Reader**

Below is a breakdown of the permissions for each role:

| Action | Admin | Manager | Reader |
| --- | --- | --- | --- |
| **Delete** | ✅ Yes | ❌ No | ❌ No |
| **Access Admin Section** | ✅ Yes | ❌ No | ❌ No |
| **Edit** | ✅ Yes | ✅ Yes | ❌ No |
| **Recover Records** | ✅ Yes | ✅ Yes | ❌ No |
| **View Recovery** | ✅ Yes | ✅ Yes | ❌ No |
| **View Backup History** | ✅ Yes | ✅ Yes | ✅ Yes |
| **Start Backup** | ✅ Yes | ✅ Yes | ✅ Yes |
| **Query Records** | ✅ Yes | ✅ Yes | ❌ No |
| **GDPR** | ✅ Yes | ✅ Yes | ❌ No |
| **View Schedule** | ✅ Yes | ✅ Yes | ✅ Yes |
| **View Metadata** | ✅ Yes | ✅ Yes | ✅ Yes |
| **Run Metadata** | ✅ Yes | ✅ Yes | ✅ Yes |
| **Sandbox Seeding** | ✅ Yes | ✅ Yes | ❌ No |

---

### ⚙️ **LDAP/AD Properties**

Use these properties to configure LDAP integration:

| Property | Description |
| --- | --- |
| **rj.ldap.userDnPatterns** | For fixed user location in the directory. |
| **rj.ldap.userSearchBase** | Search base for user lookups. |
| **rj.ldap.userSearchFilter** | LDAP filter for searching users *(optional)*. |
| **rj.ldap.groupSearchBase** | Search base for group membership lookups. |
| **rj.ldap.groupSearchFilter** | LDAP filter for searching groups. Defaults to `"(uniqueMember={0})"` where `{0}` is the user DN. |
| **rj.ldap.groupRoleAttribute** | Attribute containing the role name. Default is `"cn"`. |
| **rj.ldap.groupSearchSubtree** | If `true`, performs a subtree scope search for groups. |
| **rj.ldap.ldapAuthoritiesPopulator** | Specifies the `LdapAuthoritiesPopulator`. |
| **rj.ldap.passwordEncoder** | Defaults to `sha256`. Other options: `ldapsha`, `bcrypt`, `noop`, `pbkdf2`, `scrypt`. |