Ransomware attackers specifically target and attempt to destroy backup systems to increase the probability of payment. Hardening your system is critical. Please ensure you have reviewed your platform security using the Security Hardening Checklist
Cohesity

COHESITY Documentation

Explore our documentation to get started, discover products & new features, access troubleshooting guides, register sources, platforms support.

Products
Data Security Alliance
Visit Cohesity.com
Demos
Support
Blogs
Developers
Partner Portals
Cohesity Community
© 2026 Cohesity, Inc. All Rights Reserved.
Terms of Use|
Privacy Policy|
Legal|
  1. Home
  2. NetBackup™ Web UI Administrator's Guide
  3. Section II. Managing security
  4. Managing role-based access control
  5. Configuring RBAC
  6. Add AD or LDAP domains
NetBackup™ Web UI Administrator's Guide

Add AD or LDAP domains

Role-based access in the NetBackup web UI supports domain users of Active Directory (AD) or Lightweight Directory Access Protocol (LDAP). Before you can add domain users to RBAC roles, you must add the AD or the LDAP domain. A domain also must be added before you can configure that domain for smart card authentication.

You can use the POST /security/domains/vxat API or the vssat command to configure domains.

To add an AD or an LDAP domain with the vssat command

  1. Ensure that the user account (that you specify in the -m option in step 3) has the required rights to query the AD or the LDAP server.
  2. Log on to the master server as root or administrator.
  3. Run the vssat command.

    For example, to add an LDAP domain:

    vssat addldapdomain -d nbudomain -s ldap://example.com -u "OU=Users,DC=example,DC=com" 
    -g "OU=Groups,DC=example,DC=com" -m "CN=TestUser,OU=Users,DC=example,DC=com" -t msad

    For example, to add an AD domain:

    vssat addldapdomain -d nbudomain -s ldap://domaincontroller.example.com 
    -u "cn=Users,dc=example,dc=com" -g "cn=Users,dc=example,dc=com" 
    -m "CN=TestUser,OU=Users,DC=example,DC=com" -t msad

    Note that if domaincontroller.example.com, then authentication cannot be completed.

  4. Verify that the specified AD or LDAP domain was successfully added.

    vssat validateprpl -p username -d ldap:DomainName -b localhost:1556:nbatd

For more information on the vssat command and more of its options, see the NetBackup Command Reference Guide.

Feedback

Was this page helpful?
Previous

Configuring RBAC

Next

Default RBAC roles

Feedback

Was this page helpful?