> For the complete documentation index, see [llms.txt](https://docs.lithnet.io/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://docs.lithnet.io/ams/v3.0/help-and-support/application-help-pages/authorization-rules/role-authorization-rules-page.md).

# Role authorization rules page

![](https://1500666603-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FzPrDxVWpXXpSNTpkDVnR%2Fuploads%2Fgit-blob-a959f2a19a62d635d1d16c8c63a7cf190bfb5d0d%2Fui-page-authorization-rules-roles.png?alt=media)

## Role authorization rules

Access Manager can provide just-in-time access to roles represented by Active Directory groups. Access to roles is provided through role authorization rules. An authorization rule defines the role and who is allowed to access it.

You can add, edit and delete individual rules using the authorization rule editor.

The `Save permission report` tool allows you to export a list of all the principals that are granted access via the selected rules to a CSV file. Note, that any PowerShell based rules are not included in this report.

## Authorization rule editor

### Rule settings

![](https://1500666603-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FzPrDxVWpXXpSNTpkDVnR%2Fuploads%2Fgit-blob-2fd0559f8ca55ae7edd5677916b6eae38833466b%2Fui-page-authorization-rules-roles-edit-rule-rule-settings.png?alt=media)

Each role must be given a name that will be shown to users in the web app. Users will also be able to see the description field, which allows you to provide more information about what the role enables access to.

You must select an Active Directory group as the target for the role.

The rule can be disabled at any time by selecting the `disable rule` checkbox. You can also choose to expire the rule at a certain point, by checking the `expire rule` checkbox and selecting the date and time the rule should expire.

### Access control

![](https://1500666603-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FzPrDxVWpXXpSNTpkDVnR%2Fuploads%2Fgit-blob-83c0ea531b0ff429fa7e2acb37cc44bdb7837b71%2Fui-page-authorization-rules-roles-edit-rule-access-control.png?alt=media)

#### Maximum duration

Specifies the absolute maximum time the user can request access for

#### Default duration

Specifies the time that is pre-filled for the user in the web app when they request access to this role. They can decrease or increase the requested time, up to the value specified by `Maximum duration`

#### Allow user to extend the request before expiry

If the user has previously requested access to the role, and their access has not yet expired, enabling this option will allow them to extend their access duration up to the amount specified by `Maximum duration`.

When this option is disabled, a user who re-requests access before their original access period has expired will not be permitted to extend that access.

#### Edit permissions

Use this option to assign users and groups that are permitted to access this role.

#### Request reason

When a user accesses a role, you can prompt them to provide a reason for accessing the role. You can choose to make this prompt mandatory, optional, or not shown at all.

### Advanced settings

![](https://1500666603-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FzPrDxVWpXXpSNTpkDVnR%2Fuploads%2Fgit-blob-3c07d49f8c2d6221b186b0d6fdf5aaa237292a15%2Fui-page-authorization-rules-roles-edit-rule-advanced-settings.png?alt=media)

#### Domain controller targeting mode

This option allows you to control how Access Manager selects a domain controller to perform the JIT operation against. This is important, as in multi-site Active Directory environments, there can be delays of 15 minutes between being granted JIT access, and the target system seeing the new group membership. You can choose a targeting mode that ensures that the group membership change is available on a domain controller in the same site as the app or service you are applying permission to.

| Option                                      | Description                                                                                                                                                      |
| ------------------------------------------- | ---------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| Automatically select a domain controller    | The AMS service will use the same domain controller that the server it is running on is connected to. This is typically a DC in the same site as the AMS server. |
| Find a domain controller in a specific site | AMS will attempt to locate a DC in the site you specify. If one cannot be found, AMS will default back to its own domain controller                              |
| Use a specific domain controller            | This option instructs AMS to use only the domain controller specified                                                                                            |

### Notifications

Set the audit notification channels you want to be notified on success or failure events for this rule. See [the auditing](broken://pages/EQwVKobYKxKObFsJuVce) help topic for information about creating notification channels.


---

# Agent Instructions
This documentation is published with GitBook. GitBook is the documentation platform designed so that both humans and AI agents can read, navigate, and reason over technical content effectively. Learn more at gitbook.com.

## Querying This Documentation
If you need additional information that is not directly available in this page, you can query the documentation dynamically by asking a question.

Perform an HTTP GET request on the current page URL with the `ask` query parameter, and the optional `goal` query parameter:

```
GET https://docs.lithnet.io/ams/v3.0/help-and-support/application-help-pages/authorization-rules/role-authorization-rules-page.md?ask=<question>&goal=<endgoal>
```

`ask` is the immediate question: it should be specific, self-contained, and written in natural language.
`goal` is optional and describes the broader end goal you are ultimately trying to accomplish on behalf of the user. GitBook uses it to tailor the answer towards what is most useful for that goal.

The response will contain a direct answer to the question and relevant excerpts and sources from the documentation.

Use this mechanism when the answer is not explicitly present in the current page, you need clarification or additional context, or you want to retrieve related documentation sections.
