### Prerequisites
ITDR add-on
The following permissions enable users to use and manage ITDR features. You can manage these role permissions under **Settings** → **Configurations** → **Access Management** → **Roles**.
<table><thead><tr><th>Feature</th><th width="249">Description</th><th>Roles</th></tr></thead><tbody><tr><td>Conditional Access Policy</td><td>Configure and manage real time, risk-based authentication rules and MFA enforcement.</td><td><ul><li><strong>Viewer</strong>: Read-only access to current Conditional Access Policies.</li><li><strong>Administrator</strong>: Full access including configuring Conditional Access Policies.<br></li></ul></td></tr><tr><td>Identity Security Runtime</td><td>Access identity-specific risk dashboards, interactive risk views, and identity detection rules.</td><td><ul><li><strong>Viewer</strong>: Read-only access to identity runtime operations.</li><li><strong>Administrator</strong>: Full access to identity runtime operations, including managing LDAP Protection and other ITDR capabilities.</li></ul></td></tr></tbody></table>