Active Directory Rights Management Services (AD RMS) is a service that protects sensitive and intellectual documents of an organization from the unauthorized users. One of the major advantages of using AD RMS over other security features such as NTFS permission is that AD RMS permission travels along with the documents. Does not matter how and where you copy or move the documents. In this post, we will see how to install and configure AD RMS in Windows Server 2016.
In order to install and configure AD RMS in Windows Server 2016, you need to perform the following high-level steps:
Preparing AD RMS server.
Installing the AD RMS server role.
Creating an AD RMS Cluster.
Configuring the AD RMS templates.
Testing and verifying AD RMS Configuration.
Preparing AD RMS Server
For the successful AD RMS deployment, first, you need to make sure that you fulfill all the AD RMS prerequisites. For this, first, you need to perform the following steps:
On DC1 , create a user named ADRMSSRVC that will be used as AD RMS service account.
Add this account in to the member list of the Domain Admins group. Refer the following figure.<img class=”aligncenter wp-image-2089″ title=”AD RMS Service Account” src=”https://i1.wp.com/protechgurus.com/wp-content/uploads/2016/09/word-image-189.png?resize=411%2C538&ssl=1″ alt=”Creating AD RMS Service Account” width=411 height=538 srcset=”https://i1.wp.com/protechgurus.com/wp-content/uploads/2016/09/word-image-189.png?w=411&ssl=1 411w, https://i1.wp.com/protechgurus.com/wp-content/uploads/2016/09/word-image-189.png?resize=300%2C393&ssl=1 300w, https://i1.wp.com/protechgurus.com/wp-content/uploads/2016/09/word-image-189.png?resize=100%2C131&ssl=1 100w, https://i1.wp.com/protechgurus.com/wp-content/uploads/2016/09/word-image-189.png?resize=150%2C196&ssl=1 150w, https://i1.wp.com/protechgurus.com/wp-content/uploads/2016/09/word-image-189.png?resize=200%2C262&ssl=1 200w” sizes=”(max-width: 411px) 100vw, 411px” data-recalc-dims=1>
Now, create the following Active Directory objects:
Create an OU named Sales and create Peter user under it.
Create one more OU named Finance and create Shawn user under it.
When you make the users, ensure that you also set the email addresses for the respective user accounts. For example, set [email protected] email account for Peter user and [email protected] for Shawn user. Refer the following figure.<img class=”aligncenter wp-image-2090″ title=”Active Directory Rights Management Services” src=”https://i2.wp.com/protechgurus.com/wp-content/uploads/2016/09/word-image-190.png?resize=500%2C420&ssl=1″ alt=”AD RMS Accounts” width=500 height=420 srcset=”https://i2.wp.com/protechgurus.com/wp-content/uploads/2016/09/word-image-190.png?w=656&ssl=1 656w, https://i2.wp.com/protechgurus.com/wp-content/uploads/2016/09/word-image-190.png?resize=600%2C505&ssl=1 600w, https://i2.wp.com/protechgurus.com/wp-content/uploads/2016/09/word-image-190.png?resize=300%2C252&ssl=1 300w, https://i2.wp.com/protechgurus.com/wp-content/uploads/2016/09/word-image-190.png?resize=100%2C84&ssl=1 100w, https://i2.wp.com/protechgurus.com/wp-content/uploads/2016/09/word-image-190.png?resize=150%2C126&ssl=1 150w, https://i2.wp.com/protechgurus.com/wp-content/uploads/2016/09/word-image-190.png?resize=200%2C168&ssl=1 200w, https://i2.wp.com/protechgurus.com/wp-content/uploads/2016/09/word-image-190.png?resize=450%2C379&ssl=1 450w” sizes=”(max-width: 500px) 100vw, 500px” data-recalc-dims=1>
Now, create a shared folder named Secret that will be used as Shared Distribution Point (SDP) .
Right-click Secret and navigate to Share with Specific people to share this folder.<img class=”aligncenter wp-image-2091″ title=”AD RMS Software Distribution Point” src=”https://i2.wp.com/protechgurus.com/wp-content/uploads/2016/09/word-image-191.png?resize=501%2C357&ssl=1″ alt=”Creating AD RMS SDP” width=501 height=357 srcset=”https://i2.wp.com/protechgurus.com/wp-content/uploads/2016/09/word-image-191.png?w=639&ssl=1 639w, https://i2.wp.com/protechgurus.com/wp-content/uploads/2016/09/word-image-191.png?resize=600%2C427&ssl=1 600w, https://i2.wp.com/protechgurus.com/wp-content/uploads/2016/09/word-image-191.png?resize=300%2C214&ssl=1 300w, https://i2.wp.com/protechgurus.com/wp-content/uploads/2016/09/word-image-191.png?resize=100%2C71&ssl=1 100w, https://i2.wp.com/protechgurus.com/wp-content/uploads/2016/09/word-image-191.png?resize=150%2C107&ssl=1 150w, https://i2.wp.com/protechgurus.com/wp-content/uploads/2016/09/word-image-191.png?resize=200%2C142&ssl=1 200w, https://i2.wp.com/protechgurus.com/wp-content/uploads/2016/09/word-image-191.png?resize=450%2C320&ssl=1 450w” sizes=”(max-width: 501px) 100vw, 501px” data-recalc-dims=1>
On the File Sharing dialog box, type Peter , and then click Add .
Set the permission level as Read/Write .<img class=”aligncenter wp-image-2092″ title=”Install and configure AD RMS in Windows Server 2016″ src=”https://i0.wp.com/protechgurus.com/wp-content/uploads/2016/09/word-image-192.png?resize=500%2C370&ssl=1″ alt=”AD RMS Shared Folder” width=500 height=370 srcset=”https://i0.wp.com/protechgurus.com/wp-content/uploads/2016/09/word-image-192.png?w=614&ssl=1 614w, https://i0.wp.com/protechgurus.com/wp-content/uploads/2016/09/word-image-192.png?resize=600%2C444&ssl=1 600w, https://i0.wp.com/protechgurus.com/wp-content/uploads/2016/09/word-image-192.png?resize=300%2C222&ssl=1 300w, https://i0.wp.com/protechgurus.com/wp-content/uploads/2016/09/word-image-192.png?resize=100%2C74&ssl=1 100w, https://i0.wp.com/protechgurus.com/wp-content/uploads/2016/09/word-image-192.png?resize=150%2C111&ssl=1 150w, https://i0.wp.com/protechgurus.com/wp-content/uploads/2016/09/word-image-192.png?resize=200%2C148&ssl=1 200w, https://i0.wp.com/protechgurus.com/wp-content/uploads/2016/09/word-image-192.png?resize=450%2C333&ssl=1 450w” sizes=”(max-width: 500px) 100vw, 500px” data-recalc-dims=1>
Using the same steps, also set the Read/Write permission for the ADRMSSRVC user account.
Installing AD RMS in Windows Server 2016
In order to install the Active Directory Rights Management Services (AD RMS) role, you need to perform the following steps:
On DC1 , using the Server Manager console, launch the Add Roles and Features Wizard .
Click Next and accept the default selections till the Select server roles page displays.
Select the Active Directory Right Management Service s role and click Next .<img class=”aligncenter wp-image-2093″ title=”Installing Active Directory Rights Management Services in Windows Server 2016″ src=”https://i1.wp.com/protechgurus.com/wp-content/uploads/2016/09/word-image-193.png?resize=502%2C358&ssl=1″ alt=”Installing Active Directory Rights Management Services” width=502 height=358 srcset=”https://i1.wp.com/protechgurus.com/wp-content/uploads/2016/09/word-image-193.png?w=786&ssl=1 786w, https://i1.wp.com/protechgurus.com/wp-content/uploads/2016/09/word-image-193.png?resize=600%2C427&ssl=1 600w, https://i1.wp.com/protechgurus.com/wp-content/uploads/2016/09/word-image-193.png?resize=300%2C214&ssl=1 300w, https://i1.wp.com/protechgurus.com/wp-content/uploads/2016/09/word-image-193.png?resize=100%2C71&ssl=1 100w, https://i1.wp.com/protechgurus.com/wp-content/uploads/2016/09/word-image-193.png?resize=150%2C107&ssl=1 150w, https://i1.wp.com/protechgurus.com/wp-content/uploads/2016/09/word-image-193.png?resize=200%2C142&ssl=1 200w, https://i1.wp.com/protechgurus.com/wp-content/uploads/2016/09/word-image-193.png?resize=450%2C321&ssl=1 450w” sizes=”(max-width: 502px) 100vw, 502px” data-recalc-dims=1>
Click Next and navigate to the Select role services page.
Ensure that Active Directory Management Server option is selected and then click Next to proceed.<img class=”aligncenter wp-image-2094″ title=”Selecting Active Directory Rights Management Server role” src=”https://i2.wp.com/protechgurus.com/wp-content/uploads/2016/09/word-image-194.png?resize=501%2C357&ssl=1″ alt=”Selecting Active Directory Rights Management Services role” width=501 height=357 srcset=”https://i2.wp.com/protechgurus.com/wp-content/uploads/2016/09/word-image-194.png?w=786&ssl=1 786w, https://i2.wp.com/protechgurus.com/wp-content/uploads/2016/09/word-image-194.png?resize=600%2C427&ssl=1 600w, https://i2.wp.com/protechgurus.com/wp-content/uploads/2016/09/word-image-194.png?resize=300%2C214&ssl=1 300w, https://i2.wp.com/protechgurus.com/wp-content/uploads/2016/09/word-image-194.png?resize=100%2C71&ssl=1 100w, https://i2.wp.com/protechgurus.com/wp-content/uploads/2016/09/word-image-194.png?resize=150%2C107&ssl=1 150w, https://i2.wp.com/protechgurus.com/wp-content/uploads/2016/09/word-image-194.png?resize=200%2C142&ssl=1 200w, https://i2.wp.com/protechgurus.com/wp-content/uploads/2016/09/word-image-194.png?resize=450%2C321&ssl=1 450w” sizes=”(max-width: 501px) 100vw, 501px” data-recalc-dims=1>
Finally, click Install and complete the installation process.
Creating an AD RMS Cluster
After installing AD RMS server role, the next task is to create a new AD RMS cluster. For this, you need to perform the following steps:
On the Server Manager console, click the Notifications icon, and then click Perform additional configuration .<img class=”aligncenter wp-image-2095″ title=”Configure AD RMS in Windows Server 2016″ src=”https://i0.wp.com/protechgurus.com/wp-content/uploads/2016/09/word-image-195.png?resize=500%2C338&ssl=1″ alt=”Perform Active Directory Rights Management Services post configuration” width=500 height=338 srcset=”https://i0.wp.com/protechgurus.com/wp-content/uploads/2016/09/word-image-195.png?w=766&ssl=1 766w, https://i0.wp.com/protechgurus.com/wp-content/uploads/2016/09/word-image-195.png?resize=600%2C406&ssl=1 600w, https://i0.wp.com/protechgurus.com/wp-content/uploads/2016/09/word-image-195.png?resize=300%2C203&ssl=1 300w, https://i0.wp.com/protechgurus.com/wp-content/uploads/2016/09/word-image-195.png?resize=100%2C68&ssl=1 100w, https://i0.wp.com/protechgurus.com/wp-content/uploads/2016/09/word-image-195.png?resize=150%2C101&ssl=1 150w, https://i0.wp.com/protechgurus.com/wp-content/uploads/2016/09/word-image-195.png?resize=200%2C135&ssl=1 200w, https://i0.wp.com/protechgurus.com/wp-content/uploads/2016/09/word-image-195.png?resize=450%2C304&ssl=1 450w” sizes=”(max-width: 500px) 100vw, 500px” data-recalc-dims=1>
On the Configuration required for Active Directory Rights Management Services page, click Next .
On the AD RMS Cluster page, ensure that the Create a new AD RMS root cluster radio button is selected, and then click Next .<img class=”aligncenter wp-image-2096″ title=”Creating a new AD RMS root Cluster” src=”https://i2.wp.com/protechgurus.com/wp-content/uploads/2016/09/word-image-196.png?resize=500%2C368&ssl=1″ alt=”Create a new AD RMS root Cluster” width=500 height=368 srcset=”https://i2.wp.com/protechgurus.com/wp-content/uploads/2016/09/word-image-196.png?w=761&ssl=1 761w, https://i2.wp.com/protechgurus.com/wp-content/uploads/2016/09/word-image-196.png?resize=600%2C442&ssl=1 600w, https://i2.wp.com/protechgurus.com/wp-content/uploads/2016/09/word-image-196.png?resize=300%2C221&ssl=1 300w, https://i2.wp.com/protechgurus.com/wp-content/uploads/2016/09/word-image-196.png?resize=100%2C74&ssl=1 100w, https://i2.wp.com/protechgurus.com/wp-content/uploads/2016/09/word-image-196.png?resize=150%2C110&ssl=1 150w, https://i2.wp.com/protechgurus.com/wp-content/uploads/2016/09/word-image-196.png?resize=200%2C147&ssl=1 200w, https://i2.wp.com/protechgurus.com/wp-content/uploads/2016/09/word-image-196.png?resize=450%2C331&ssl=1 450w” sizes=”(max-width: 500px) 100vw, 500px” data-recalc-dims=1>
On the Configuration Database page, select the Use Windows Internal Database on this server option, and then click Next . Alternatively, you can also specify the SQL server database, if already configured.<img class=”aligncenter wp-image-2097″ title=”Selecting Windows Internal Database for AD RMS” src=”https://i0.wp.com/protechgurus.com/wp-content/uploads/2016/09/word-image-197.png?resize=500%2C368&ssl=1″ alt=”Selecting AD RMS configuration database server” width=500 height=368 srcset=”https://i0.wp.com/protechgurus.com/wp-content/uploads/2016/09/word-image-197.png?w=761&ssl=1 761w, https://i0.wp.com/protechgurus.com/wp-content/uploads/2016/09/word-image-197.png?resize=600%2C442&ssl=1 600w, https://i0.wp.com/protechgurus.com/wp-content/uploads/2016/09/word-image-197.png?resize=300%2C221&ssl=1 300w, https://i0.wp.com/protechgurus.com/wp-content/uploads/2016/09/word-image-197.png?resize=100%2C74&ssl=1 100w, https://i0.wp.com/protechgurus.com/wp-content/uploads/2016/09/word-image-197.png?resize=150%2C110&ssl=1 150w, https://i0.wp.com/protechgurus.com/wp-content/uploads/2016/09/word-image-197.png?resize=200%2C147&ssl=1 200w, https://i0.wp.com/protechgurus.com/wp-content/uploads/2016/09/word-image-197.png?resize=450%2C331&ssl=1 450w” sizes=”(max-width: 500px) 100vw, 500px” data-recalc-dims=1>
On the Service Account page, click Specify to specify the ADRMS Service account that is mcsalab\adrmssrvc and click Next to proceed.<img class=”aligncenter wp-image-2098″ title=”Specifying AD RMS Service Account” src=”https://i1.wp.com/protechgurus.com/wp-content/uploads/2016/09/word-image-198.png?resize=500%2C368&ssl=1″ alt=”AD RMS Service Account” width=500 height=368 srcset=”https://i1.wp.com/protechgurus.com/wp-content/uploads/2016/09/word-image-198.png?w=761&ssl=1 761w, https://i1.wp.com/protechgurus.com/wp-content/uploads/2016/09/word-image-198.png?resize=600%2C442&ssl=1 600w, https://i1.wp.com/protechgurus.com/wp-content/uploads/2016/09/word-image-198.png?resize=300%2C221&ssl=1 300w, https://i1.wp.com/protechgurus.com/wp-content/uploads/2016/09/word-image-198.png?resize=100%2C74&ssl=1 100w, https://i1.wp.com/protechgurus.com/wp-content/uploads/2016/09/word-image-198.png?resize=150%2C110&ssl=1 150w, https://i1.wp.com/protechgurus.com/wp-content/uploads/2016/09/word-image-198.png?resize=200%2C147&ssl=1 200w, https://i1.wp.com/protechgurus.com/wp-content/uploads/2016/09/word-image-198.png?resize=450%2C331&ssl=1 450w” sizes=”(max-width: 500px) 100vw, 500px” data-recalc-dims=1>
Accept the default selections till the AD RMS Cluster Key Password page. Specify a cluster key password and click Next to proceed.<img class=”aligncenter wp-image-2099″ title=”Specifying AD RMS Cluster Key PAssword” src=”https://i1.wp.com/protechgurus.com/wp-content/uploads/2016/09/word-image-199.png?resize=501%2C369&ssl=1″ alt=”AD RMS Cluster Key Password” width=501 height=369 srcset=”https://i1.wp.com/protechgurus.com/wp-content/uploads/2016/09/word-image-199.png?w=761&ssl=1 761w, https://i1.wp.com/protechgurus.com/wp-content/uploads/2016/09/word-image-199.png?resize=600%2C442&ssl=1 600w, https://i1.wp.com/protechgurus.com/wp-content/uploads/2016/09/word-image-199.png?resize=300%2C221&ssl=1 300w, https://i1.wp.com/protechgurus.com/wp-content/uploads/2016/09/word-image-199.png?resize=100%2C74&ssl=1 100w, https://i1.wp.com/protechgurus.com/wp-content/uploads/2016/09/word-image-199.png?resize=150%2C110&ssl=1 150w, https://i1.wp.com/protechgurus.com/wp-content/uploads/2016/09/word-image-199.png?resize=200%2C147&ssl=1 200w, https://i1.wp.com/protechgurus.com/wp-content/uploads/2016/09/word-image-199.png?resize=450%2C331&ssl=1 450w” sizes=”(max-width: 501px) 100vw, 501px” data-recalc-dims=1>
On the Cluster Web Site page, accept the default selection, and then click Next .
On the Specify Cluster Address page, select the Use an unencrypted connection (http://) radio button, specify DC1.MCSALAB.LOCAL as FQDN name and click Next to proceed.<img class=”aligncenter wp-image-2100″ title=”Specifying AD RMS Cluster Address” src=”https://i1.wp.com/protechgurus.com/wp-content/uploads/2016/09/word-image-200.png?resize=503%2C370&ssl=1″ alt=”AD RMS Cluster Address” width=503 height=370 srcset=”https://i1.wp.com/protechgurus.com/wp-content/uploads/2016/09/word-image-200.png?w=761&ssl=1 761w, https://i1.wp.com/protechgurus.com/wp-content/uploads/2016/09/word-image-200.png?resize=600%2C442&ssl=1 600w, https://i1.wp.com/protechgurus.com/wp-content/uploads/2016/09/word-image-200.png?resize=300%2C221&ssl=1 300w, https://i1.wp.com/protechgurus.com/wp-content/uploads/2016/09/word-image-200.png?resize=100%2C74&ssl=1 100w, https://i1.wp.com/protechgurus.com/wp-content/uploads/2016/09/word-image-200.png?resize=150%2C110&ssl=1 150w, https://i1.wp.com/protechgurus.com/wp-content/uploads/2016/09/word-image-200.png?resize=200%2C147&ssl=1 200w, https://i1.wp.com/protechgurus.com/wp-content/uploads/2016/09/word-image-200.png?resize=450%2C331&ssl=1 450w” sizes=”(max-width: 503px) 100vw, 503px” data-recalc-dims=1>
On the Licensor Certificate page, accept the default name, and then click Next .
On the SCP Registration page, accept the default selection, and then click Next .
On the Confirmation page, review all the options you have chosen. Click Previous to make the changes.<img class=”aligncenter wp-image-2101″ title=”Confirming AD RMS Installation Selections” src=”https://i1.wp.com/protechgurus.com/wp-content/uploads/2016/09/word-image-201.png?resize=500%2C368&ssl=1″ alt=”Completing AD RMS Cluster configuration” width=500 height=368 srcset=”https://i1.wp.com/protechgurus.com/wp-content/uploads/2016/09/word-image-201.png?w=761&ssl=1 761w, https://i1.wp.com/protechgurus.com/wp-content/uploads/2016/09/word-image-201.png?resize=600%2C442&ssl=1 600w, https://i1.wp.com/protechgurus.com/wp-content/uploads/2016/09/word-image-201.png?resize=300%2C221&ssl=1 300w, https://i1.wp.com/protechgurus.com/wp-content/uploads/2016/09/word-image-201.png?resize=100%2C74&ssl=1 100w, https://i1.wp.com/protechgurus.com/wp-content/uploads/2016/09/word-image-201.png?resize=150%2C110&ssl=1 150w, https://i1.wp.com/protechgurus.com/wp-content/uploads/2016/09/word-image-201.png?resize=200%2C147&ssl=1 200w, https://i1.wp.com/protechgurus.com/wp-content/uploads/2016/09/word-image-201.png?resize=450%2C331&ssl=1 450w” sizes=”(max-width: 500px) 100vw, 500px” data-recalc-dims=1>
Finally, click Install and complete the installation process.
Ensure that installation process is completed without any error.<img class=”wp-image-2102 aligncenter” src=”https://i1.wp.com/protechgurus.com/wp-content/uploads/2016/09/word-image-202.png?resize=501%2C369&ssl=1″ width=501 height=369 srcset=”https://i1.wp.com/protechgurus.com/wp-content/uploads/2016/09/word-image-202.png?w=761&ssl=1 761w, https://i1.wp.com/protechgurus.com/wp-content/uploads/2016/09/word-image-202.png?resize=600%2C442&ssl=1 600w, https://i1.wp.com/protechgurus.com/wp-content/uploads/2016/09/word-image-202.png?resize=300%2C221&ssl=1 300w, https://i1.wp.com/protechgurus.com/wp-content/uploads/2016/09/word-image-202.png?resize=100%2C74&ssl=1 100w, https://i1.wp.com/protechgurus.com/wp-content/uploads/2016/09/word-image-202.png?resize=150%2C110&ssl=1 150w, https://i1.wp.com/protechgurus.com/wp-content/uploads/2016/09/word-image-202.png?resize=200%2C147&ssl=1 200w, https://i1.wp.com/protechgurus.com/wp-content/uploads/2016/09/word-image-202.png?resize=450%2C331&ssl=1 450w” sizes=”(max-width: 501px) 100vw, 501px” data-recalc-dims=1>
Now, Sign off to Administrator and Sign in to as MCSALAB\adrmssrvc user account.
Open the Active Directory Rights Management Services console using the Server Manager console. Verify that there is no error display.<img class=”aligncenter wp-image-2103″ title=”Opening Active Directory Rights Management Services console” src=”https://i0.wp.com/protechgurus.com/wp-content/uploads/2016/09/word-image-203.png?resize=499%2C381&ssl=1″ alt=”Active Directory Rights Management Services console” width=499 height=381 srcset=”https://i0.wp.com/protechgurus.com/wp-content/uploads/2016/09/word-image-203.png?w=739&ssl=1 739w, https://i0.wp.com/protechgurus.com/wp-content/uploads/2016/09/word-image-203.png?resize=600%2C458&ssl=1 600w, https://i0.wp.com/protechgurus.com/wp-content/uploads/2016/09/word-image-203.png?resize=300%2C229&ssl=1 300w, https://i0.wp.com/protechgurus.com/wp-content/uploads/2016/09/word-image-203.png?resize=100%2C76&ssl=1 100w, https://i0.wp.com/protechgurus.com/wp-content/uploads/2016/09/word-image-203.png?resize=150%2C114&ssl=1 150w, https://i0.wp.com/protechgurus.com/wp-content/uploads/2016/09/word-image-203.png?resize=200%2C153&ssl=1 200w, https://i0.wp.com/protechgurus.com/wp-content/uploads/2016/09/word-image-203.png?resize=450%2C343&ssl=1 450w” sizes=”(max-width: 499px) 100vw, 499px” data-recalc-dims=1>
Configure AD RMS in Windows Server 2016
Once you installed the AD RMS server role, the next step is to configure AD RMS templates. For this, you need to perform the following steps:
On the Active Directory Rights Management Services console, expand dc1.mcsalab.local , select and right-click Rights Policy Templates , and then select Properties .<img class=”aligncenter wp-image-2104″ title=”Configuring Rights Policy Templates Properties” src=”https://i0.wp.com/protechgurus.com/wp-content/uploads/2016/09/word-image-204.png?resize=500%2C382&ssl=1″ alt=”Configuring Rights Policy Templates” width=500 height=382 srcset=”https://i0.wp.com/protechgurus.com/wp-content/uploads/2016/09/word-image-204.png?w=739&ssl=1 739w, https://i0.wp.com/protechgurus.com/wp-content/uploads/2016/09/word-image-204.png?resize=600%2C458&ssl=1 600w, https://i0.wp.com/protechgurus.com/wp-content/uploads/2016/09/word-image-204.png?resize=300%2C229&ssl=1 300w, https://i0.wp.com/protechgurus.com/wp-content/uploads/2016/09/word-image-204.png?resize=100%2C76&ssl=1 100w, https://i0.wp.com/protechgurus.com/wp-content/uploads/2016/09/word-image-204.png?resize=150%2C114&ssl=1 150w, https://i0.wp.com/protechgurus.com/wp-content/uploads/2016/09/word-image-204.png?resize=200%2C153&ssl=1 200w, https://i0.wp.com/protechgurus.com/wp-content/uploads/2016/09/word-image-204.png?resize=450%2C343&ssl=1 450w” sizes=”(max-width: 500px) 100vw, 500px” data-recalc-dims=1>
Select the Enable export check box, type the path of SDP that is \\dc1.mcsalab.local\secret and then click OK .<img class=”aligncenter wp-image-2105″ title=”Specifying templates file location” src=”https://i2.wp.com/protechgurus.com/wp-content/uploads/2016/09/word-image-205.png?resize=421%2C485&ssl=1″ alt=”Right Policy Templates File Location” width=421 height=485 srcset=”https://i2.wp.com/protechgurus.com/wp-content/uploads/2016/09/word-image-205.png?w=421&ssl=1 421w, https://i2.wp.com/protechgurus.com/wp-content/uploads/2016/09/word-image-205.png?resize=300%2C346&ssl=1 300w, https://i2.wp.com/protechgurus.com/wp-content/uploads/2016/09/word-image-205.png?resize=100%2C115&ssl=1 100w, https://i2.wp.com/protechgurus.com/wp-content/uploads/2016/09/word-image-205.png?resize=150%2C173&ssl=1 150w, https://i2.wp.com/protechgurus.com/wp-content/uploads/2016/09/word-image-205.png?resize=200%2C230&ssl=1 200w” sizes=”(max-width: 421px) 100vw, 421px” data-recalc-dims=1>
Click Create distributed rights policy template to create the distributed rights policy template.<img class=”aligncenter wp-image-2106″ title=”Creating Distributed Rights Policy Templates” src=”https://i0.wp.com/protechgurus.com/wp-content/uploads/2016/09/word-image-206.png?resize=501%2C382&ssl=1″ alt=”Create Distributed Rights Policy Templates” width=501 height=382 srcset=”https://i0.wp.com/protechgurus.com/wp-content/uploads/2016/09/word-image-206.png?w=739&ssl=1 739w, https://i0.wp.com/protechgurus.com/wp-content/uploads/2016/09/word-image-206.png?resize=600%2C458&ssl=1 600w, https://i0.wp.com/protechgurus.com/wp-content/uploads/2016/09/word-image-206.png?resize=300%2C229&ssl=1 300w, https://i0.wp.com/protechgurus.com/wp-content/uploads/2016/09/word-image-206.png?resize=100%2C76&ssl=1 100w, https://i0.wp.com/protechgurus.com/wp-content/uploads/2016/09/word-image-206.png?resize=150%2C114&ssl=1 150w, https://i0.wp.com/protechgurus.com/wp-content/uploads/2016/09/word-image-206.png?resize=200%2C153&ssl=1 200w, https://i0.wp.com/protechgurus.com/wp-content/uploads/2016/09/word-image-206.png?resize=450%2C343&ssl=1 450w” sizes=”(max-width: 501px) 100vw, 501px” data-recalc-dims=1>
On the Add New Template Identification Information page, click Add .
Specify template name and description, click Add , and then click Next to proceed.<img class=”aligncenter wp-image-2107″ title=”Adding new Template Identification information” src=”https://i0.wp.com/protechgurus.com/wp-content/uploads/2016/09/word-image-207.png?resize=500%2C395&ssl=1″ alt=”Template Identification Information” width=500 height=395 srcset=”https://i0.wp.com/protechgurus.com/wp-content/uploads/2016/09/word-image-207.png?w=688&ssl=1 688w, https://i0.wp.com/protechgurus.com/wp-content/uploads/2016/09/word-image-207.png?resize=600%2C474&ssl=1 600w, https://i0.wp.com/protechgurus.com/wp-content/uploads/2016/09/word-image-207.png?resize=300%2C237&ssl=1 300w, https://i0.wp.com/protechgurus.com/wp-content/uploads/2016/09/word-image-207.png?resize=100%2C79&ssl=1 100w, https://i0.wp.com/protechgurus.com/wp-content/uploads/2016/09/word-image-207.png?resize=150%2C119&ssl=1 150w, https://i0.wp.com/protechgurus.com/wp-content/uploads/2016/09/word-image-207.png?resize=200%2C158&ssl=1 200w, https://i0.wp.com/protechgurus.com/wp-content/uploads/2016/09/word-image-207.png?resize=450%2C356&ssl=1 450w” sizes=”(max-width: 500px) 100vw, 500px” data-recalc-dims=1>
On the Add User Rights page, click Add . Type email of Peter user in The e-mail address of a user or group text box, and then click OK .<img class=”aligncenter wp-image-2108″ title=”Specifying AD RMS User Rights” src=”https://i0.wp.com/protechgurus.com/wp-content/uploads/2016/09/word-image-208.png?resize=500%2C395&ssl=1″ alt=”AD RMS User Rights” width=500 height=395 srcset=”https://i0.wp.com/protechgurus.com/wp-content/uploads/2016/09/word-image-208.png?w=688&ssl=1 688w, https://i0.wp.com/protechgurus.com/wp-content/uploads/2016/09/word-image-208.png?resize=600%2C474&ssl=1 600w, https://i0.wp.com/protechgurus.com/wp-content/uploads/2016/09/word-image-208.png?resize=300%2C237&ssl=1 300w, https://i0.wp.com/protechgurus.com/wp-content/uploads/2016/09/word-image-208.png?resize=100%2C79&ssl=1 100w, https://i0.wp.com/protechgurus.com/wp-content/uploads/2016/09/word-image-208.png?resize=150%2C119&ssl=1 150w, https://i0.wp.com/protechgurus.com/wp-content/uploads/2016/09/word-image-208.png?resize=200%2C158&ssl=1 200w, https://i0.wp.com/protechgurus.com/wp-content/uploads/2016/09/word-image-208.png?resize=450%2C356&ssl=1 450w” sizes=”(max-width: 500px) 100vw, 500px” data-recalc-dims=1>
Using the same steps, add Shawn user account, assign the View permission, and proceed to Next .<img class=”aligncenter wp-image-2109″ title=”Adding Users and Groups for AD RMS” src=”https://i1.wp.com/protechgurus.com/wp-content/uploads/2016/09/word-image-209.png?resize=500%2C395&ssl=1″ alt=”Configure AD RMS Permissions” width=500 height=395 srcset=”https://i1.wp.com/protechgurus.com/wp-content/uploads/2016/09/word-image-209.png?w=688&ssl=1 688w, https://i1.wp.com/protechgurus.com/wp-content/uploads/2016/09/word-image-209.png?resize=600%2C474&ssl=1 600w, https://i1.wp.com/protechgurus.com/wp-content/uploads/2016/09/word-image-209.png?resize=300%2C237&ssl=1 300w, https://i1.wp.com/protechgurus.com/wp-content/uploads/2016/09/word-image-209.png?resize=100%2C79&ssl=1 100w, https://i1.wp.com/protechgurus.com/wp-content/uploads/2016/09/word-image-209.png?resize=150%2C119&ssl=1 150w, https://i1.wp.com/protechgurus.com/wp-content/uploads/2016/09/word-image-209.png?resize=200%2C158&ssl=1 200w, https://i1.wp.com/protechgurus.com/wp-content/uploads/2016/09/word-image-209.png?resize=450%2C356&ssl=1 450w” sizes=”(max-width: 500px) 100vw, 500px” data-recalc-dims=1>
On the Expiration Policy page, set the desired expiry date for this template and click Next to proceed.
On the Specify Extended Policy page, click Next .
On the Specify Revocation Policy page, click Finish .<img class=”aligncenter wp-image-2110″ title=”Specifying AD RMS Revocation Policy” src=”https://i0.wp.com/protechgurus.com/wp-content/uploads/2016/09/word-image-210.png?resize=500%2C395&ssl=1″ alt=”AD RMS Revocation Policy” width=500 height=395 srcset=”https://i0.wp.com/protechgurus.com/wp-content/uploads/2016/09/word-image-210.png?w=688&ssl=1 688w, https://i0.wp.com/protechgurus.com/wp-content/uploads/2016/09/word-image-210.png?resize=600%2C474&ssl=1 600w, https://i0.wp.com/protechgurus.com/wp-content/uploads/2016/09/word-image-210.png?resize=300%2C237&ssl=1 300w, https://i0.wp.com/protechgurus.com/wp-content/uploads/2016/09/word-image-210.png?resize=100%2C79&ssl=1 100w, https://i0.wp.com/protechgurus.com/wp-content/uploads/2016/09/word-image-210.png?resize=150%2C119&ssl=1 150w, https://i0.wp.com/protechgurus.com/wp-content/uploads/2016/09/word-image-210.png?resize=200%2C158&ssl=1 200w, https://i0.wp.com/protechgurus.com/wp-content/uploads/2016/09/word-image-210.png?resize=450%2C356&ssl=1 450w” sizes=”(max-width: 500px) 100vw, 500px” data-recalc-dims=1>
Close the Active Directory Rights Management Services console.
Verifying AD RMS Client
Now, you have successfully configured AD RMS, the next step is to verify your AD RMS configuration. In order to verify the AD RMS configuration, you need to perform the following steps:
Switch and sign in to CLIENT1 as MCSALAB\Peter.
Open the Internet options , click the Security tab, click Local intranet , and then click Sites .
Click Advanced , type http://DC1.MCSALAB.LOCAL in the Add this website to the zone and then click Add .
Open a blank Word 2013 document and then type a descriptive message in the document.
Click Protect Document using the File tab and navigate to Restrict AccessRestricted Access > Connect to Rights Management Services.<img class=”aligncenter wp-image-2114″ title=”AD RMS Client Configuration” src=”https://i0.wp.com/protechgurus.com/wp-content/uploads/2016/09/ADRMS-Client.png?resize=500%2C370&ssl=1″ alt=”Install and Configure AD RMS” width=500 height=370 srcset=”https://i0.wp.com/protechgurus.com/wp-content/uploads/2016/09/ADRMS-Client.png?w=687&ssl=1 687w, https://i0.wp.com/protechgurus.com/wp-content/uploads/2016/09/ADRMS-Client.png?resize=600%2C444&ssl=1 600w, https://i0.wp.com/protechgurus.com/wp-content/uploads/2016/09/ADRMS-Client.png?resize=300%2C222&ssl=1 300w, https://i0.wp.com/protechgurus.com/wp-content/uploads/2016/09/ADRMS-Client.png?resize=100%2C74&ssl=1 100w, https://i0.wp.com/protechgurus.com/wp-content/uploads/2016/09/ADRMS-Client.png?resize=150%2C111&ssl=1 150w, https://i0.wp.com/protechgurus.com/wp-content/uploads/2016/09/ADRMS-Client.png?resize=200%2C148&ssl=1 200w, https://i0.wp.com/protechgurus.com/wp-content/uploads/2016/09/ADRMS-Client.png?resize=450%2C333&ssl=1 450w” sizes=”(max-width: 500px) 100vw, 500px” data-recalc-dims=1>
Select the Restrict permission to this document check box in the Permission dialog box, and then type [email protected] in the Read text box.
Type [email protected] in the Change text box.
Click OK to close the Permission dialog box.
Click Save As from the File menu, and then save the file as \\DC1\Secret\ADRMS_Test.docx . You can notice that Peter user can make changes.
Switch user as MCSALAB\Shawn and open File Explorer , and then browse to \\DC1\Secret .
Try to open the ADRMS_Test.docx file. Notice the message that displays.
Click View Permission and verify that Shawn user has the view permission.
Click the File tab and notice that the Print option is not available.
In this article, we have learned how to install and configure AD RMS in Windows Server 2016. Drop your queries, suggestions, feedback in the comment box.