Quantcast
Channel: Active Directory Rights Management Service(On premise) forum
Viewing all 1025 articles
Browse latest View live

Local admin password for Desktop and servers.

$
0
0

hi,

What is best practice to chnage local admin password on desktop and servers within your domain.

We have different password windows 7,XP and different password for Windows 2003/2008


Restrict Access to a folder by anyone, but sertain application

$
0
0
Good Day! I have a pretty straightforward task: to restrict the access to a folder by anyone but a certain application. That folder contains database and text and image files. Is there a way or a trick to do it. Respectfully thank you for your advise!

How to find existing SCP connection in Domain Forest .

$
0
0

I am trying to configure AD RMS in our domain to protect SharePoint  documents .But i am getting below message at the time of configuration

"Create new AD-RMS licensing only cluster is not showing "

http://social.technet.microsoft.com/Forums/en-US/rms/thread/71255969-8e27-4d54-b0ea-8774591d75b6

"The SCP is Registered but the root cluster can not be contacted . Yo can still join an existing cluster . The Remote name could not be resolved :'wrmserver' "

I wanted to know to how can identify the exiting SCP connection in our domain . because as per our server team there is no SCP is configured before in domain . 

I have checked in ADSI Edit in AD server ,but there is no SCP connection is registered into that .


Manage RMS Server 2012 from Server 2008 R2

$
0
0

I have an AD RMS Server installed on Windows Server 2012 and i'd like to manage it from a Server running Windows Server 2008 R2.

However if i try to add the RMS Cluster in den Management Console on Server 2008 R2 i get the following error:

I already installed the latest AD RMS Client. Is it possible to manage an RMS Server 2012 from a Computer running Server 2008 R2? 

Thanks!

Can't install addtionnal AD RMS ???

$
0
0

 My company has 3 sites at 3 cities.

 First, I installed AD RMS (Windows Server 2K8 R2 SP1) at HO (head office).

 Now, when I install a second (addtionnal) AD RMS at 2 brand office and want to join them into the same cluster with guideline:

http://technet.microsoft.com/en-us/library/cc754578%28v=ws.10%29.aspx

 And so I get error:

********************************

 Warning: Windows automatic updating is not enabled. To ensure that your newly-installed role or feature is automatically updated, turn on Windows Update in Control Panel.

Active Directory Rights Management Services: Installation succeeded with errors
   Error: Attempt to configure Active Directory Rights Management Server failed.  There is a problem logging in as the service account.  Either the entered domain, user name, and password are incorrect, or the user does not have permissions to log in to the local machine. Verify your user configuration and try again.    at Microsoft.RightsManagementServices.Configuration.ProvisioningBase.VerifyServiceAccountCredentials()
   at Microsoft.RightsManagementServices.Configuration.ProvisioningBase.CheckInstallationEnvironment(String strDatabaseName, String strDBServerName)
   at Microsoft.RightsManagementServices.Configuration.ProvisioningBase.Run()
   at Microsoft.RightsManagementServices.Configuration.ProvisionerBase.DoProvision()
   at Microsoft.RightsManagementServices.Configuration.ProvisionerHelper.Run(OperationType operationType, Object data)
   at Microsoft.RightsManagementServices.Configuration.CmdLineHandler.Run()
Remove and re-install AD RMS to attempt provisioning again.
   Warning: Before you can administer AD RMS on this server, you must log off and log on again.
   Informational: <a href="rms_help.chm|html/a928c435-77a8-49fe-b08e-bfdc6bcc1fa7.htm">If the AD RMS cluster has been configured for SSL, you must import and configure the cluster's SSL certificate on this server.</a>
   The following role services were installed:
   Active Directory Rights Management Server
**************************************

I'm sure the user and password are correct. But I dont know why???

Someone help me to fix it.

Thanks !!!

Client (XP) cant access AD RMS Site ???

$
0
0

 Sorry my E. is not good.

 This is my case.

 I have 3 sites at 3 places. Each site has 2 domain controllers.

 First, I installed AD RMS on Site A (Main Site). Everything is okie. All client (include Windows 7, windows XP ...) cant connect to AD RMS server to use it.

 But on Site B and C, only clients are using Windows 7 or Server can connect AD RMS. Windows XP is not. I installed RMS Client SP2 on all Windows XP, but they can't access website of RMS server by IE. But when I use another browser (Firefox, Chrome), they access fine.

 And if IE can't acceess, so the client can't use AD RMS.

 Somebody get the same error and has solution to fix it ???

 Thanks !!!

Where are my offline use license files stored?

$
0
0

Hi,

I have installed a test active directory with AD RMS services. The AD RMS service seems to be working ok but I noticed a strange thing - I can't find any EUL files in the DRM (c:\users\[username]\appdata\local\microsoft\DRM). Nevertheless, the computer seems to have those offline use licenses for RMS files that my test users have already opened. I have tested that I can open such files without network connectivity as long as the file has been opened previously.

I have checked all the settings I can think of but can't find anything related to this. Is there any chance that recent hotfixes have changed how RMS works or can the offline license files be stored somewhere else than in files on the disk like some Windows embedded database? I have search for the computer for .drm files but still can't find them. I only see the machine.cert, the clc and the gic. I have enabled showing all hidden files and protected OS files but no luck.

I'm running Windows 2008 R2 AD and the test computer is Windows 7 sp1 (64bit) with Office 2010 (build 14.0.6023.1000 (32bit).

Any help is appreciated!

Mikko

ADRMS 2012 with Office 2013

$
0
0

Currently with Office 2010 I have enabled the built-in scheduled task which updates the templates, and I have the registry entry deployed via group policy which defines the Office 2010 Admin Template Location, however this process does not appear to work with Office 2013.

Has the import process changed? I believe the templates are now stored in the %LocalAppData%\Microsoft\MSIPC\Templates folder, but after the initial "Connect to rights management server and retrieve templates" option is selected under File->Info->Protect Document I don't have any updated templates cached on my PC(s). I have cleared the DRM registry entries and the cached folder location out completely in an attempt to refresh everything for diagnosis, but the templates never seem to update. I have also created new templates on my ADRMS server to verify whether my client PC(s) have updated.

I'm running Server 2012 as a client with Office 2013 64-bit, Windows 8 64-bit as a client OS with Office 2013 64-bit, and Windows 7 64-bit as a client OS with Office 2013 64-bit. At the moment all three of these machines either haveold policy templates that have not updated, or cached templates that have been removed from the ADRMS server.

Any suggestions?



How to RE-setup a new AD RMS in window server 2012 for SharePoint 2013?

$
0
0

How to re-setup a new AD RMS in window server 2012 for SharePoint 2013?

Previously I have configured my server by Adding roles and features and checked the AD RMS features.
Now I want to delete the AD RMS Root Cluster, where and how can I delete the AD RMS Root Cluster.
I have referred to this guide http://www.scribd.com/doc/5987753/Removing-Active-Directory-Rights-Management-Services-StepByStep-Guide but I couldn't do it because IN:

Step 1: Decommission AD RMS Root Cluster

To enable the decommissioning service

  1. Log on to ADRMS-SRV as cpandl\adrmsadmin.
  2. Click Start, point to Administrative Tools, and then click Active DirectoryRights Management Services.
  3. If the User Account Control dialog box appears, confirm that the action itdisplays is what you want, and then click Continue.
  4. Expand the AD RMS cluster, expand Security Policies, and then click Decommissioning.
  5. In the Actions pane, click Enable Decommissioning.
  6. Click
  7. Decommission

I can't see step 3, expand security policies. I want to remove the AD RMS Root Cluster, is this the right way? If yes, please help me out.

Test-IRM Failed.

$
0
0

Hi All,

Please help,

OS I am using is windows server 2012 for adrms.

Exchange is running on 2008 r2 sp1.

Exchange is 2010 sp3.

Cryptographic mode on adrms server is set to 2.

I already assigned permissions on servercertification.asmx and publish.asmx files.

Added super users group to federated mailbox.

Exchange 2010 sp3, adrms cryptographic mode 2 i am using. Please help. 

Following error I am getting.

Results : Checking Exchange Server ...
              - PASS: Exchange Server is running in Enterprise.
          Loading IRM configuration ...
              - PASS: IRM configuration loaded successfully.
          Retrieving RMS Certification Uri ...
              - PASS: RMS Certification Uri: https://rms.easeblr.com/_wmcs/certification.
          Verifying RMS version for https://rms.easeblr.com/_wmcs/certification ...
              - PASS: RMS Version verified successfully.
          Retrieving RMS Publishing Uri ...
              - PASS: RMS Publishing Uri: https://rms.easeblr.com/_wmcs/licensing.
          Acquiring Rights Account Certificate (RAC) and Client Licensor Certificate (CLC) ...
              - FAIL: Failed to acquire a Rights Account Certificate (RAC) and/or a Client Licensor Certificate (CLC).
          This failure may cause features such as Transport Decryption, Transport Protection Rules, Journal Report Decr
          yption, IRM in Outlook Web App, IRM in Exchange ActiveSync, and IRM Search to not work. Make sure that the Ex
          change Servers Group is granted "Read" and "Read & Execute" rights on the ServerCertification.asmx and Publis
          h.asmx pipelines on your AD RMS server. For details, see "Set Permissions on the AD RMS Certification Pipelin
          e" at  http://go.microsoft.com/fwlink/?LinkId=186951.

Please help. Any help will be highly appreciated.


Manish Kumar MCSA, MCITP Enterprise Admin. MCTS Exchange server 2007, MCITP Virtualization Admin.

AD RMS client

$
0
0

Hello,

I have the following test environment:

  • 1 DC
  • 1 AD RMS server: I have configured a template on it
  • 1 client computer: Windows 7 64 bit and Microsoft Office 2007

I have a problem configuring the Windows 7 client computer so that it will use my AD RMS cluster. I followed all steps mentioned here: http://technet.microsoft.com/en-us/library/cc771971(WS.10).aspx

but the client computer can not use the RMS server.

I created the following key: HKEY_CURRENT_USER\Software\Microsoft\Office\12.0\Common\DRM and added AdminTemplatePathwith %LocalAppData%\Microsoft\DRM\Templates as a value.

I also configured the automatic scheduled task like mentioned in the article and no changes: the Templates folder is not being created and the created model is not present on the client computer. I forced a manual sync and as a result I found the error (0x8004CF48).

What should I configure to get my client computer working?

UAC rights in windows 8

$
0
0

how to give UAC login Right to the domain user, because in domain, we are not possible to disable UAC in system. and give local admin right to user. 

How to reset bios password on a Toshiba A2002-b7

$
0
0

I forgot my own bios password and when i try to acess the bios, it ask's me for the password.

Is there any software that can show me the password.

I've tried to open it to remove the bateries. However the bateries are not acessible.

Please help me

Some Registry key overrides listed below do not point to the correct RM servers Action : Please click 'Detect and Repair on the help menu in one of office applications

$
0
0

Dear All,

We have a issue with Client Machine , Please find detail in below

Environment  : 

  1. Windows XP sp3
  2. Microsoft office 2003 sp3 (pro)
  3. Ofiice 2010 (pro)
  4. compatibility pack for the 2007 office system  (FileFormatConverters.exe)

When i run IRMcheck tool i got the following error 

  • Some Registry key overrides listed below do not point to the correct RM servers Action : Please click 'Detect and Repair on the help menu in one of office applications 
  • IRM Application manifests not found

When i uninstall following from machine

  1. compatibility pack for the 2007 office system  (FileFormatConverters.exe) 

Then i run IRM checktool , Everything as success , Please help to sort out this 

Thanks in Advance

Scorpion 

Alternate access mapping and IRM in SharePoint 2010

$
0
0
Dear All, 

We have an issue with RMS with SharePoint

Please find it below

The following scenario is happening when we open a document from IRM enabled Library


Iteration 1( While creating a web application if we provide public url as same as machine name (eg:sharepoint))

http://sharepoint:123456 is your central admin

http://sharepoint:654321 is your site collection

Its working fine



Iteration 2 ( While creating a web application if we provide public url as other than machine name (eg:mossservername))

http://sharepoint:123456 is your central admin

http://mossservername:654321 is your site collection


we are facing the following issue when we open a document from IRM enabled Library

When I tried to open Excel I got following error
Microsoft Office Excel cannot access the file 'http://mossservername:654321 /Documents/Filename.xlsx'. There are several possible reasons:
 
·         The file name or path does not exist.
·         The file is being used by another program.
·         The workbook you are trying to save has the same name as a currently open workbook.
 
When I tried to open Word , I got following error
Microsoft Office Word:
"http://mossservername:654321 /Documents/Filename.doc" does not exist.Check your spelling or try another path


If We done following things in Alternate Access Mappings its working fine 

Default URL : http://mossservername:654321
Extranet URL : http://sharepoint:654321

we need to make rms working on http://mossservername:654321 rather than extranet url
Please help us to sort it out

Thanks in Advance
Scorpion

Cannot manage AD RMS ?

$
0
0

Hi all,

Does anyone face with this issue?  After AD RMS installation completed, its about to log off and log in again. then i found error while trying to manage ADRMS.


Thank you in advance

MAC

AD RMS 2008 Installation Issue

$
0
0

Hi All

Hoping for some help.

I have been trying to install the AD RMS 2008 R2 for a couple of weeks and I am unable to get past the below issue.

Active Directory Rights Management Services: Installation succeeded with errors

<Error>: Attempt to configure Active Directory Rights Management Server failed. Exception has been thrown by the target of an invocation. at System.DirectoryServices.DirectoryEntry.Invoke(String methodName, Object[] args) at Microsoft.RightsManagementServices.Admin.CommonUtility.EnsureGroupMembership(String targetComputer, String userName, String domain, String group, Boolean shouldBeMember) at Microsoft.RightsManagementServices.Configuration.ProvisioningBase.EnsureUser() at Microsoft.RightsManagementServices.Configuration.ProvisioningBase.Run() at Microsoft.RightsManagementServices.Configuration.ProvisionerBase.DoProvision() at Microsoft.RightsManagementServices.Configuration.ProvisionerHelper.Run(OperationType operationType, Object data) at Microsoft.RightsManagementServices.Configuration.CmdLineHandler.Run() Remove and re-install AD RMS to attempt provisioning again.
<Warning>: Before you can administer AD RMS on this server, you must log off and log on again.
The following role services were installed:
Active Directory Rights Management Server

EnsureGroupMembership seems to be the key part. However I have tried everything I can and still no luck. This involves new servers new accounts with and without admin rights. The service is not even registered in AD (under the services part in sites and services).

I have seen an issue involving Netbios name but this does not seem to be our issue as the server is contactable via both DNS and Netbios. I have even added an additional Nebios name with the full FQDN but still no luck.

Can somebody help?

Thanks

A connection with AD RMS cluster "Local Host" could not be established.The request failed with status 503: Service Unavailable

$
0
0

Hi All,

Need a quick help from you. i am installing AD RMS in a cluster with self signed certificates. The installation went fine without any error, but when i try to launch the AD RMS administration console from server manager i get the following error.

A connection with AD RMS cluster "Local Host" could not be established.The request failed with status 503: Service Unavailable. I get the service unavailable error again if i try to access the AD RMS role managerweb service. The account is same which was used for installation and is part of both ADRMS Ent admin and local admin group on the servers.

On checking event viewer, i also see the IIS app pool _DRMSApp pol 1 gets stopped and the eventviewer says that the accoutn used for application pool does not have login as a batch permissions.

The RMS server is installed on a memebr server with windows 2008 R2. any pointers are apprreciated.

 

Thanks

Panky

 


Panky, Learning never stops.You just need to find new subjects.

ADRMS Protected Contents takes atleast 3 minutes to open

$
0
0

I set a lab of ADRMS based on Windows Server 2008 R2. ADRMS Protected Contents takes atleast 3 minutes to open in office 2010. Is it normal?

Regards Irfan


Irfan Goolab SALES ENGINEER (Microsoft UC) MCP, MCSA, MCTS, MCITP, MCT

Azure AD RMS and Office 2010?

$
0
0
Hi,

I have two questions. 

1. Does Azure AD RMS, for example when activated within Office 365 / Sharepoint Online, support external users? I.e. users with an individual Microsoft Account (e.g. outlook.com)? I tried it with a pilot configuration, but without any luck.

2. My understanding is that in order  to use the 'cloud' version of RMS we need to install the RMS Client 2.1 on each client machine. Does this client support Office 2010 on for example a Windows 7 machine? Because we tried it in Word 2010 and the result was that we kept getting back the 'old'  signin-interface for Windows Live ID accounts. This interface does not accept Organizational Microsoft Accounts i.e. Office 365 / Sharepoint Online.

Any experience with this situation, anyone?

Many thanks,
Peter
Viewing all 1025 articles
Browse latest View live


<script src="https://jsc.adskeeper.com/r/s/rssing.com.1596347.js" async> </script>