AD Pro Toolkit includes built-in role-based access control. By default every feature is available to Domain Admins and Enterprise Admins. Delegating access to specific Active Directory security groups lets help desk staff, HR, or junior admins see only the tools they need.
Watch the role-based access video
How to set up role-based access
- Create one or more of the groups below, and add a user to the group.
- When that user opens the app it checks their group membership and limits their access accordingly.
Access groups
| Group name | Access |
|---|---|
ADProToolkit-Admin |
Full access to all features |
ADProToolkit-Tools |
All tools |
ADProToolkit-Reports |
All reports |
ADProToolkit-ScheduledReports |
Scheduled reports |
ADProToolkit-Settings |
Settings pages |
ADProToolkit-ToolsUsers |
All tools in the Users section |
ADProToolkit-ToolsGroups |
All tools in the Groups section |
ADProToolkit-ToolsSecurity |
All tools in the Security section |
ADProToolkit-ToolsComputers |
All tools in the Computers section |
ADProToolkit-ToolsOther |
All tools in the Other section |
ADProToolkit-PWReset |
Password Reset and Unlock only |
- A user who is not a member of any
ADProToolkit-*group gets full access.- The groups must be created as Active Directory security groups in your domain.
- If you need additional roles added, contact support.
Example
To restrict someone to reports only, add them to the ADProToolkit-Reports group. The next time they open the app, the tools and settings sections are hidden and they see reports alone.

