All roles are managed inside the NetXMS, LDAP is used onlu to log in. You can create required groups inside the NetXMS or use groups that are imported from LDAP and just assign required access rights to those groups, you can add groups inside the groups. If your LDAP structure does not change a lot you can use imported groups, but I personally create group with correct rights just in case if in LDAP group will be removed all rights will not be lost. I add LDAP imported groups in to the manually created groups.