Skip to main content
Version: 2025.1

Roles

The security model of VisualDrive Server relies on a combination of global server-wide roles and specific permissions configured for individual items such as drives, files, and folders.

Roles define the actions users are authorized to perform at a general level. However, these actions remain constrained by permissions set on individual drives, files, and folders. Roles are assigned to users based on Active Directory groups.

Defined roles

The following roles are defined within VisualDrive Server:

Drive User role

The Drive User role grants standard access to VisualDrive Server, enabling users to interact with their personal and shared drives. This role has limited management capabilities.

This role is required for accessing VisualDrive Server via the OneDrive app and the web interface.

Drive Operator role

The Drive Operator role includes all capabilities provided to Drive Users, with additional privileges for managing shared drives.

Allowed actions

The following table summarizes actions permitted for each role. Actions remain constrained by permissions configured at the drive, file, or folder level:

ActionDrive UserDrive Operator
Access personal drives
Access shared drives
Sync, edit, delete files/folders
Create shared drives
Rename shared drives
Delete empty shared drives

Default role assignments

After initial installation, roles are assigned by default as follows:

RoleDefault assignment
Drive UsersAll authenticated users in domain
Drive OperatorsNo assigned users

Configuring role assignments

Follow these steps to configure or modify role assignments:

  1. Open VisualDrive Server Manager.
  2. Click ActionServer Configuration.
  3. In the Roles section, select the tab for the role to configure (Drive Users or Drive Operators).
  4. Click Change… and select the Active Directory group whose members will be assigned this role.
  5. Click Apply to save your changes.

If a user was recently added to the corresponding group, they’ll need to sign out of Windows and then sign back in for the group membership to update.