Module 10: Designing an AD RMS Infrastructure in Windows Server 2008
Module Overview Gathering Information for an Active Directory Rights Management Services (AD RMS) Design Designing AD RMS Clusters and Access Designing AD RMS Backup and Recovery
Key Components of AD RMS Author AD RMS- enabled applications AD RMS Server Database server Consumer AD DS
Considerations for External Client AD RMS Access Consider the following methods for providing external clients better access to AD RMS: The root certification cluster URL must be accessible from the Internet and Intranet Deploy a dedicated license server for external clients in complex environments Require SSL for external clients when accessing AD RMS Define the method for granting external users access to AD RMS (external trusted domains, Windows Live IDs, AD FS)
What are AD RMS Rights Policy Templates? AD RMS rights policy templates specify the rights and conditions that apply to protected content Rights policy templates allow you to: Establish different rules for protecting different types of information – in a manageable way In Windows Vista SP1 and Windows Server 2008, a distribution mechanism is available that enables the client to automatically retrieve templates from the AD RMS server Create customized templates
Lesson 2: Designing AD RMS Clusters and Access Options for Configuring AD RMS Clusters Guidelines for Designing AD RMS Clusters Options for Granting External Users Access to AD RMS Guidelines for Designing AD RMS Access
Options for Configuring AD RMS Clusters The two types of clusters in Windows Server 2008: Licensing clusterRoot cluster Simple cluster: The simplest form of a cluster is one AD RMS server Root cluster: The first server installed is always the root cluster Handles all certification and licensing requests for the domain Complex cluster: Multiple servers can be configured as a cluster behind a single, shared URL Licensing-only clusters can be created in addition to the root cluster
Guidelines for Designing AD RMS Clusters When designing AD RMS clusters, follow these guidelines: In small environments with limited resources, use single- server clusters For high availability, add multiple servers in a cluster behind a single URL Use only a root cluster and join more AD RMS servers to this cluster For complex environments, create licensing-only clusters For redundancy and load balancing, add multiple servers to the installation and create a licensing cluster
Options for Granting External Users Access to AD RMS There are several ways to support multiple forests and provide external users with authentication and access: External trusted user domains Trusted publishing domains Windows Live ID credentials A federated trust
Guidelines for Designing AD RMS Access When designing AD RMS access, follow these guidelines: Set the root certification cluster URL to an address that: Can be accessed over the Internet Resolved in the intranet to AD RMS servers for the same cluster Enable SSL and require an SSL connection between the AD RMS clients and the AD RMS server Set up a license server dedicated to extranet users and configure the extranet cluster URL appropriately Use ISA Server 2006 publishing to connect securely to AD RMS from external clients
Guidelines for Implementing an AD RMS Backup and Recovery Strategy When designing a backup and restore strategy for AD RMS, consider the following guidelines: The AD RMS private key must be backed up and managed Always maintain a current backup of AD RMS database Provide a redundant Internet link for AD RMS if you are servicing external clients Backup all certificates on AD RMS Backup custom templates on AD RMS Test your backup