I had to fiddle with AD authentication to get it to work myself.
Here is what I have in my contains field
CN=Domain Admins,CN=Users,DC=mydomain,DC=com
Basically though, if a user does not have a role assigned to them they cannot log into Mailarchiva.
2009-10-26 19:41:43 UTC in MailArchiva