Quantcast
Channel: Active Directory Rights Management Service(On premise) forum
Viewing all 1025 articles
Browse latest View live

Information Rights Management Costs and length of protection.

$
0
0
I have a power point presentation people are asking for copies of and I when I found out about Information Rights Management it says theres a trial period and that it ends in 2 or 3 months. Afterward I may choose to continue the service for a fee. I've tried contacting Microsoft but haven't been able to reach a live person. How much do I have to pay for the services once the trial period is up and how long am I covered for after I pay the fee?

SQL Server not detected on external database when adding AD RMS role

$
0
0
I am unable to get my AD RMS server to detect any instances of SQL Server on my database server.  I have followed the MS guide to setting up AD RMS.  I am using a domain account that is in the domain Enterprise Admin group, is a local admin on the database server, and has sysadmin rights on the SQL Server.  I turned off the firewall on both the AD RMS and database servers.  I believe TCP/IP protocol is setup properly for my SQL Server as I have a Sharepoint installation on a separate server which uses it.  If I try to add the AD RMS role on the database server it does successfully detect the instances when specifying the server name for external databases.  Anyone have any ideas as to why I'm running into this problem?

adRMS production error : Broken certificate chain.

$
0
0

Hi,

I have developed an app that worked well in pre-production adRMS environment (using SDK cert.).

After getting the production certificate from Mircosoft, generating the manifest without error and running this app in production hierarchy, it runs an error every time it tries to create the safe environment.

Failed to build secure environment. Exception: Broken certificate chain.

BrokenCertChain

   at MS.Internal.Security.RightsManagement.Errors.ThrowOnErrorCode(Int32 hr)
   at MS.Internal.Security.RightsManagement.ClientSession.BuildSecureEnvironment(String applicationManifest)
   at System.Security.RightsManagement.SecureEnvironment.CriticalCreate(String applicationManifest, ContentUser user)
   at adrmsTest.rmsPub.PublishRMContent(String contentFile, String encryptedFile, String finaluser, DateTime contentValidUntil, TextBox outsidelog)

-------------------------

I've tested/installed my RMS production deployment 3x. It works well with XPSViewer (protecting documents). Using 3xWin2008R2 servers (DC, RMS, App).

ADRMS

$
0
0

Why user does have to log in every time in the document?

Is there any process that owner of the document who provide the security will doesn't require to log in every time?

Thanks & Regards

Ashish solanki


ashish solanki

Firewall

$
0
0
De service voor de Firewall is gestopt. De Firewall doet het dus niet. Kan de service niet starten krijg foutmelding ox609. Pc is niet besmet.

I want to creat an Account that can only run one program

$
0
0

I have a POS system that needs to run under an administrator account. I need to have one of the administrator accounts to be able to use all of the programs in Windows seven. The Other Administrator Account I want ti limit it to only to be able to run the POS software. this version of Windows seven is embed windows 7 with no parental controls so I can just use that.

I have removed everything off the start launch button with the exception of "ALL PROGRAMS" cant se3em to figure out how to remove that from the options.

Can anyone help?????? I will sendf you a "Starbucks Thank You Card" who ever solves this for me first

 

Serial Port

$
0
0
I cannot connect to the serial port  in windows server 2012

AD RMS Office 2010 does not give right restriction options

$
0
0

Hi,

I have installed a AD RMS server role to a dedicated server and followed these instructions: http://technet.microsoft.com/en-us/library/cc753531(v=WS.10).aspx

I have a domain let say contoso.com and servers are: ADRMS.contoso.com(MS Server 2012), DC1.contoso.com(MS Server 2008 R2) and DB1.contoso.com(MS Server 2008 R2).

I have configured the AD RMS service to use URL https://rms.conto.com and redirections are done by network traffic controller and DNS which converts the requested address to specific IP(FQDN:ADRMS.contoso.com). It uses HTTPS/SSL. I can logon localy to ADRMS cluster console(Add Cluster>Remote Computer) from the server with the URL rms.conto.com(required a regedit) and also can connect from client machines to https://rms.conto.com/_wmcs/certification/certification.asmx and https://rms.conto.com/_wmcs/licensing/license.asmx. Though I am unable to logon locally to the cluster console using Add Cluster>Local Computer.

SCP is created to DC1 with serviceBindingInformation = https://rms.conto.com/_wmcs/certification

Problem is that when I open Word 2010 and create a document and try to do a Restrict Permission by People>Restrict Access, it only offers me Microsoft Live ID or Windows Account. If I choose Windows Account it has problem contacting "restricted permission service".

Have tried to clear DRM folder from %localAppData%\Microsoft\DRM but no help.

I also happed to notice a strange log at the ADRMS-server: 

This Active Directory Rights Management Services (AD RMS) cluster cannot perform an operation on one of the AD RMS databases. Ensure that all AD RMS databases are operating correctly on the network and that the AD RMS service account has read and write permissions to the databases.

Parameter Reference
Context: STATIC
RequestId: N/A
HelpLink.ProdName: Microsoft SQL Server
HelpLink.EvtSrc: MSSQLServer
HelpLink.EvtID: 18456
HelpLink.BaseHelpUrl: http://go.microsoft.com/fwlink
HelpLink.LinkId: 20476
SqlError-0.State: 1
SqlError-0.Class: 14
SqlError-0.Server: DB1
SqlError-0.Message: Login failed for user 'NT AUTHORITY\ANONYMOUS LOGON'.
SqlError-0.Number: 18456

Microsoft.RightsManagementServices.LowSeveritySqlException
        Message: The Database Engine threw this exception in response to an error that can be corrected by the user, such as a missing database object or entity, possible data inconsistency, transaction deadlock, security setting problems, or SQL command syntax error.  Please examine the SqlError details for more information.
        HelpLink.ProdName: Microsoft SQL Server
        HelpLink.EvtSrc: MSSQLServer
        HelpLink.EvtID: 18456
        HelpLink.BaseHelpUrl: http://go.microsoft.com/fwlink
        HelpLink.LinkId: 20476
        SqlError-0.State: 1
        SqlError-0.Class: 14
        SqlError-0.Server: DB1
        SqlError-0.Message: Login failed for user 'NT AUTHORITY\ANONYMOUS LOGON'.
        SqlError-0.Number: 18456
  + System.Data.SqlClient.SqlException
  +         Message: Login failed for user 'NT AUTHORITY\ANONYMOUS LOGON'.
  +         HelpLink.ProdName: Microsoft SQL Server
  +         HelpLink.EvtSrc: MSSQLServer
  +         HelpLink.EvtID: 18456
  +         HelpLink.BaseHelpUrl: http://go.microsoft.com/fwlink
  +         HelpLink.LinkId: 20476

Why it tries to connect to SQL server(DB1) with Anonymous -account? I have installed AD RMS with ADRMSADMIN -account(with correct permissions) and configured it to use ADRMSSRVC -account as service account.

Other thing is that I can't change that service account with ADRMSADMIN from the ADRMS -console because the "Next" is grey all the time. I always have to log in to management console using "remote" cause "local machine" gives me error message. Probably this is because the cluster address is different than the machine name that is hosting the service(AD RMS -server role).

Client computer have Windows7+Office 2010 Professional Plus. Client computers does not have these registry keys:HKEY_LOCAL_MACHINE\Software\Microsoft\MSDRM , HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\MSDRM but have this: HKEY_LOCAL_MACHINE\Software\Microsoft\DRMbut empty.

HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\DRMis present and has "CachedCorpLicenseServer" and "ServiceLocations" with correct url values. Should the ServiceLocations be named like "1|2|" 2|2|?






AD RMS Client for Windows Server 2012

$
0
0

Hi everyone,

I'm looking for AD RMS Client (MSIPC.DLL) which can be applied to Windows Server 2012. I have tried to install Windows RMS Client Service Pack 2 but it doesn't support. I'm having an error that says "The required Active Directory Rights Management Service Client MSIPC.DLL is present but could not be configured properly. IRM will not work until the client is configured properly". So I think something needs to be installed in my client before connecting and using IRM protector.

Update: I have completely installed AD RMS Client 2.0 but still get the error above.

---------------------------------------------

Information Rights Management (IRM): There was a problem while creating the generic issuance license template.
All issuance licenses for protected documents are constructed from a generic, base issuance license template.
Additional Data
Error value: 0x8004020A
---------------------------------------------

Has anyone encountered the same error? I really appreciate you helps.

Regards,
-T.s


Thuan Soldier
SharePoint Vietnam | Blog | Twitter




About WinXP of STARTUP under local computer administrator or domain user

$
0
0

Hi all experts,

I add a registry of STARTUP batch file under HKEY_LOCAL_MACHINE\..\..\..\Run which it can be executed after reboot or log-out/log-in by administrator login which it is login by administartor account of local computer.

Is there any ways to make the STARTUP batch file can be activated after reboot or log-out/log-in  by Domain\user.

Since I try to add registry under HKEY_CURRENT_USER\..\..\..\RUN after reboot or log-out/log-in by Domain\user

It can be activated log-in by administrator local computer then Domain\user, but fail to be activated by Domain\user directly no matter reboot or log-out/log-in.

The STARTUP bathc file which is under a folder of C drive.

Thanks, guys.


User can't start ClickOnce app

$
0
0

I have WinForms app that is deployed through ClickOnce. Problem arise when standard user (no admin rights) download the app

  Current permissions set in app.manifest are like this

 <requestedPrivileges xmlns="urn:schemas-microsoft-com:asm.v3">
        <requestedExecutionLevel level="asInvoker" uiAccess="false" />
 </requestedPrivileges>

And those are only taht enable app to compile.

If I set like this the app wont even compile.
        <requestedExecutionLevel  level="requireAdministrator" uiAccess="false" />
<requestedExecutionLevel  level="highestAvailable" uiAccess="false" />


What is reuqired / minimum permissions for the app to run in Windows User accounts ?

ps: this surely has nothing with AD RMS but i have no clue where to post this.


SharePoint name

SharePoint Site Name

AD RMS 2008 Installation Issue

$
0
0

Hi All

Hoping for some help.

I have been trying to install the AD RMS 2008 R2 for a couple of weeks and I am unable to get past the below issue.

Active Directory Rights Management Services: Installation succeeded with errors

<Error>: Attempt to configure Active Directory Rights Management Server failed. Exception has been thrown by the target of an invocation. at System.DirectoryServices.DirectoryEntry.Invoke(String methodName, Object[] args) at Microsoft.RightsManagementServices.Admin.CommonUtility.EnsureGroupMembership(String targetComputer, String userName, String domain, String group, Boolean shouldBeMember) at Microsoft.RightsManagementServices.Configuration.ProvisioningBase.EnsureUser() at Microsoft.RightsManagementServices.Configuration.ProvisioningBase.Run() at Microsoft.RightsManagementServices.Configuration.ProvisionerBase.DoProvision() at Microsoft.RightsManagementServices.Configuration.ProvisionerHelper.Run(OperationType operationType, Object data) at Microsoft.RightsManagementServices.Configuration.CmdLineHandler.Run() Remove and re-install AD RMS to attempt provisioning again.
<Warning>: Before you can administer AD RMS on this server, you must log off and log on again.
The following role services were installed:
Active Directory Rights Management Server

EnsureGroupMembership seems to be the key part. However I have tried everything I can and still no luck. This involves new servers new accounts with and without admin rights. The service is not even registered in AD (under the services part in sites and services).

I have seen an issue involving Netbios name but this does not seem to be our issue as the server is contactable via both DNS and Netbios. I have even added an additional Nebios name with the full FQDN but still no luck.

Can somebody help?

Thanks

2003 AD folder permissions and sub-folders

$
0
0

Hello,

Here's the scenario - I need to allow department B access to a specific sub-folder from department A. I added department B to the department A AD group. Next I added a drive mapping to my login script for department B directly to the department A folder.

For example: \department A main folder\department A/B subfolder

 
This works for the moment but I would like to configure this so department B has no other access rights to department A's data (if they were to poke around).

Client (XP) cant access AD RMS Site ???

$
0
0

 Sorry my E. is not good.

 This is my case.

 I have 3 sites at 3 places. Each site has 2 domain controllers.

 First, I installed AD RMS on Site A (Main Site). Everything is okie. All client (include Windows 7, windows XP ...) cant connect to AD RMS server to use it.

 But on Site B and C, only clients are using Windows 7 or Server can connect AD RMS. Windows XP is not. I installed RMS Client SP2 on all Windows XP, but they can't access website of RMS server by IE. But when I use another browser (Firefox, Chrome), they access fine.

 And if IE can't acceess, so the client can't use AD RMS.

 Somebody get the same error and has solution to fix it ???

 Thanks !!!

How to reset bios password on a Toshiba A2002-b7

$
0
0

I forgot my own bios password and when i try to acess the bios, it ask's me for the password.

Is there any software that can show me the password.

I've tried to open it to remove the bateries. However the bateries are not acessible.

Please help me

Cannot manage AD RMS ?

$
0
0

Hi all,

Does anyone face with this issue?  After AD RMS installation completed, its about to log off and log in again. then i found error while trying to manage ADRMS.


Thank you in advance

MAC

Manage RMS Server 2012 from Server 2008 R2

$
0
0

I have an AD RMS Server installed on Windows Server 2012 and i'd like to manage it from a Server running Windows Server 2008 R2.

However if i try to add the RMS Cluster in den Management Console on Server 2008 R2 i get the following error:

I already installed the latest AD RMS Client. Is it possible to manage an RMS Server 2012 from a Computer running Server 2008 R2? 

Thanks!

ADRMS Integration with Farm based Sharepoint 2010 Users

$
0
0

We have SharePoint 2010 on-premises server having Users on SQL server. WE have AD and Different SQL user to access Sahrepoint portal.

I want to Intergrate this SharePoint 2010 with ADRMS but Want to use the sharepoint Users to use ADRMS templates.

Please let me know how can we achieve this.

Viewing all 1025 articles
Browse latest View live