1

Create several users in AD

User Name Email Address
Administrator Administrator@aaa.com
Nicole Nicole@aaa.com
Jim Jim@aaa.com
Sim Sim@aaa.com

 

2

Both 'Active Directory Rights Management Services' and 'SharePoint 2010 Server' use the default instance of SQL Server 2008 R2.

The Windows Firewalls on both computers are turned off.


K2.AAA.COM

3

 

K1.AAA.COM

4

K2.AAA.COM

SharePoint Central Administration

5

6

Enable Information Rights Management on Document Library

7

8

9

10

Administrator logs onto K1.AAA.COM, where the AD RMS is installed.

When you open a word document in SharePoint Library, a popup window shows.

 

11

 


 

Administrator logs onto K2.AAA.COM, where the SharePoint 2010 Server is installed.

13

An unexpected error has occurred while trying to restrict permission to your document. Contact your administrator for assistance.

12

When accessing the word document on the SharePoint website that has the Rights Management enabled, error pops up.

Could not open 'http://k2/Shared Documents/Chapter Eight empires.docx.

14


Solution:

15

Duplicate the Domain Controller template in Certificate Template

16

Issue "Copy of Domain Controller" template in Certificate console

17

Delete the domain controller certificate

Request a new domain controller certificate

18

Problems still exist.

 


Redo the lab

K1 and K2

Install Windows 2008 R2 Standard--Run Updates

Disable Windows Firewall

Disable TCTIPv6

Install Application Role

a-01

Install Office 2010 Professional


K1 computer

Add "Active Directory Domain Services"
Run DCPROMO for aaa.com

Default Domain Controller Policy --Assign "Allow Logon locally" to Domain Users group

Active Directory Users and Computers

Create several users with email address assigned.

user account

email address

Administrator administrator@aaa.com
Jim jim@aaa.com
Simon Simon@aaa.com
Stuart Stuart@aaa.com
Nicole Nicole@aaa.com

Active Directory Rights Management Services must use email addresses.

Because I will install AD RMS in domain controller and use aaa\jim as the service account, I will add aaa\jim to Enterprise Admins group.


K1 Computer

Add role "Active Directory Certificate Services"

AD RMS will be installed in DC. I will request a customized certificate with multiple domains for my domain controller.

Duplicate "Domain Controller" certificate template

a-02

Default Domain Policy--Trusted the certificate authority

A-03


K1 computer

Add Active Directory Rights Management Services role

a-04

05

06

07

08

Logoff and log back on

Internet Explorer

09

10

11


K2 computer

Join the domain

Logon as aaa\administrator

Enable AD RMS Client schedule

12

Wait for a hour.

Open MS Word 2010

a-13

a-14

Logon as Stuart, a regular domain user

a-15


 

K2 Computer

Install SharePoint Server 2010--Stand alone

SharePoint Central Administration--Security

a-16

The required Windows Rights Management client is present but the server refused access. IRM will not work until the server grants permission. Domain account name used: "K2$@aaa.com.

 

a-17


K1 computer

c:\inetpub\wwwroot\_wmcs\

a-18

a-19

 


K2 computer

a-20

a-21

Create a word document:James Bond and restrict Stuart to change permission.

a-22

Upload the word document to Shared Library of SharePoint site

a-23

information Rights Management

a-24

a-25

Logon the K2 computer as Stuart

Accessing the SharePoint site

a-26

 

a-27

a-28

When Nicole is logging onto K2 computer and opening the document in SharePoint site, the warning window shows. She does not have the permission.

a-29


Upload several word documents without security

a-30

a-31


Log onto K2 as Stuart

Open the word document from SharePoint Library

A-32


Observations

Certificate for AD RMS is the most important.

For SharePoint to use AD RMS, the permissions of _wmcs directory are important.

If AD RMS is installed on DC, add the account used to Enterprise Admins group.