<?xml version="1.0" encoding="UTF-8" ?>
<?xml-stylesheet type="text/xsl" href="http://blogs.msdn.com/utility/FeedStylesheets/rss.xsl" media="screen"?><rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:slash="http://purl.org/rss/1.0/modules/slash/" xmlns:wfw="http://wellformedweb.org/CommentAPI/"><channel><title>Active Directory Rights Management Services - AD RMS</title><link>http://blogs.msdn.com/rms/default.aspx</link><description>This blog provides help and community for developers and IT professionals using AD RMS.</description><dc:language>en-US</dc:language><generator>CommunityServer 2.1 SP1 (Build: 61025.2)</generator><item><title>Custom IRM Protectors</title><link>http://blogs.msdn.com/rms/archive/2009/11/06/custom-irm-protectors.aspx</link><pubDate>Fri, 06 Nov 2009 19:52:00 GMT</pubDate><guid isPermaLink="false">91d46819-8472-40ad-a661-2c78acb4018c:9918771</guid><dc:creator>tonytri</dc:creator><slash:comments>3</slash:comments><comments>http://blogs.msdn.com/rms/comments/9918771.aspx</comments><wfw:commentRss>http://blogs.msdn.com/rms/commentrss.aspx?PostID=9918771</wfw:commentRss><wfw:comment>http://blogs.msdn.com/rms/rsscomments.aspx?PostID=9918771</wfw:comment><description>&lt;P&gt;We occasionally get questions from customers about creating &lt;A href="http://msdn.microsoft.com/en-us/library/ms439253.aspx" mce_href="http://msdn.microsoft.com/en-us/library/ms439253.aspx"&gt;custom IRM protectors&lt;/A&gt;. Protectors are components that are used to apply AD RMS protection to files when they are added to document libraries like those in &lt;A href="http://technet.microsoft.com/en-us/windowsserver/sharepoint/bb684453.aspx" mce_href="http://technet.microsoft.com/en-us/windowsserver/sharepoint/bb684453.aspx"&gt;Windows SharePoint Services 3.0&lt;/A&gt;. Specifically, protectors “convert custom files types to rights-management formats when the user downloads them, and then convert those files back to nonencrypted file formats when the user uploads them for storage in the document library.”&lt;/P&gt;
&lt;P&gt;The AD RMS team recently released an &lt;A href="http://code.msdn.microsoft.com/OfficeProtectors" mce_href="http://code.msdn.microsoft.com/OfficeProtectors"&gt;IRM protector implementation&lt;/A&gt; that protects files in Microsoft Office formats, such as .docx, .xlsx, and so on. Included with these is some &lt;A href="http://code.msdn.microsoft.com/OfficeProtectors/Release/ProjectReleases.aspx?ReleaseId=1182" mce_href="http://code.msdn.microsoft.com/OfficeProtectors/Release/ProjectReleases.aspx?ReleaseId=1182"&gt;documentation&lt;/A&gt; that can help you implement these protectors provided by the AD RMS team or with your own custom protector implementation. &lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Documentation_OfficeFileFormatProtectors –&lt;/STRONG&gt; This document contains reference documentation for the protector interface and other required interfaces.&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Developer’s Walkthrough Microsoft Office 2007 File Format Protectors for AD RMS –&lt;/STRONG&gt; This document discusses setting up a pre-production development environment and implementing the I_IrmCyrpt interface, which is used to enable document encryption and decryption, and I_IrmPolicyInfoRMS, which holds licenses and other information used by a protector.&lt;BR&gt;&amp;nbsp;&lt;/P&gt;&lt;img src="http://blogs.msdn.com/aggbug.aspx?PostID=9918771" width="1" height="1"&gt;</description><category domain="http://blogs.msdn.com/rms/archive/tags/RMS/default.aspx">RMS</category><category domain="http://blogs.msdn.com/rms/archive/tags/SharePoint/default.aspx">SharePoint</category></item><item><title>The AD RMS Bulk Protection Tool Has Arrived</title><link>http://blogs.msdn.com/rms/archive/2009/10/30/the-ad-rms-bulk-protection-tool-has-arrived.aspx</link><pubDate>Fri, 30 Oct 2009 18:21:00 GMT</pubDate><guid isPermaLink="false">91d46819-8472-40ad-a661-2c78acb4018c:9915404</guid><dc:creator>tonytri</dc:creator><slash:comments>0</slash:comments><comments>http://blogs.msdn.com/rms/comments/9915404.aspx</comments><wfw:commentRss>http://blogs.msdn.com/rms/commentrss.aspx?PostID=9915404</wfw:commentRss><wfw:comment>http://blogs.msdn.com/rms/rsscomments.aspx?PostID=9915404</wfw:comment><description>&lt;P&gt;We heard from the AD RMS community and we acted! Today, we are extremely proud to announce the availability of the &lt;A href="http://www.microsoft.com/downloads/details.aspx?displaylang=en&amp;amp;FamilyID=f9fbe58f-c175-41d0-afdc-6f160ab809cd#tm" mce_href="http://www.microsoft.com/downloads/details.aspx?displaylang=en&amp;amp;FamilyID=f9fbe58f-c175-41d0-afdc-6f160ab809cd#tm"&gt;AD RMS Bulk Protection Tool&lt;/A&gt; on &lt;A href="http://www.microsoft.com/downloads/en/default.aspx" mce_href="http://www.microsoft.com/downloads/en/default.aspx"&gt;Microsoft Download Center&lt;/A&gt;.&lt;/P&gt;
&lt;P&gt;The AD RMS Bulk Protection Tool is a command-line tool that can decrypt multiple AD RMS protected files or encrypt multiple files to a predefined rights-policy template. This tool can be used to perform e-discovery of content for litigation or audit purposes, or to safeguard existing sensitive data on company shares. It&amp;nbsp;also works&amp;nbsp;in conjunction with the &lt;A href="http://www.microsoft.com/windowsserver2008/en/us/fci.aspx" mce_href="http://www.microsoft.com/windowsserver2008/en/us/fci.aspx"&gt;File Classification Infrastructure (FCI)&lt;/A&gt; feature in Windows Server 2008 R2 to classify and protect sensitive company data.&lt;/P&gt;
&lt;P&gt;Here are some additional details:&lt;/P&gt;
&lt;P&gt;Features&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;Simple command-line interface&lt;/LI&gt;
&lt;LI&gt;Bulk decrypt RMS supported files and items within Outlook PSTs&lt;/LI&gt;
&lt;LI&gt;Bulk encrypt RMS supported files to a custom template&lt;/LI&gt;
&lt;LI&gt;Extensible to other file formats via &lt;A href="http://msdn.microsoft.com/en-us/library/ms439253.aspx" mce_href="http://msdn.microsoft.com/en-us/library/ms439253.aspx"&gt;IRM protector&lt;/A&gt; implementation&lt;/LI&gt;&lt;/UL&gt;
&lt;P&gt;System Requirements&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;Windows XP, Windows Vista, Windows 7, and Windows Server 2008 R2&lt;/LI&gt;
&lt;LI&gt;The tool requires installation of &lt;A href="http://support.microsoft.com/?kbid=917275" mce_href="http://support.microsoft.com/?kbid=917275"&gt;RMS Client SP2&lt;/A&gt; and &lt;A href="http://www.microsoft.com/downloads/details.aspx?FamilyID=5b2c0358-915b-4eb5-9b1d-10e506da9d0f&amp;amp;displaylang=en" mce_href="http://www.microsoft.com/downloads/details.aspx?FamilyID=5b2c0358-915b-4eb5-9b1d-10e506da9d0f&amp;amp;displaylang=en"&gt;.NET Framework 2.0 SP2&lt;/A&gt; on Windows XP&lt;/LI&gt;
&lt;LI&gt;Outlook 2007 is needed for decrypting items within PST files&lt;/LI&gt;&lt;/UL&gt;
&lt;P&gt;You can refer to the AD RMS Bulk Protection Tool help file&amp;nbsp;that is included with the tool for more usage details.&lt;/P&gt;
&lt;P&gt;...and finally, we hope you enjoy the tool!&lt;/P&gt;
&lt;P&gt;Yours truly,&lt;BR&gt;Clinton Ho, Saket Kataruka, and Adeel Zaidi&lt;BR&gt;The AD RMS Bulk Protection Tool Team&lt;/P&gt;&lt;img src="http://blogs.msdn.com/aggbug.aspx?PostID=9915404" width="1" height="1"&gt;</description><category domain="http://blogs.msdn.com/rms/archive/tags/AD+RMS/default.aspx">AD RMS</category><category domain="http://blogs.msdn.com/rms/archive/tags/classification/default.aspx">classification</category></item><item><title>AD RMS and PowerShell</title><link>http://blogs.msdn.com/rms/archive/2009/10/19/ad-rms-and-powershell.aspx</link><pubDate>Mon, 19 Oct 2009 18:45:00 GMT</pubDate><guid isPermaLink="false">91d46819-8472-40ad-a661-2c78acb4018c:9909318</guid><dc:creator>tonytri</dc:creator><slash:comments>0</slash:comments><comments>http://blogs.msdn.com/rms/comments/9909318.aspx</comments><wfw:commentRss>http://blogs.msdn.com/rms/commentrss.aspx?PostID=9909318</wfw:commentRss><wfw:comment>http://blogs.msdn.com/rms/rsscomments.aspx?PostID=9909318</wfw:comment><description>&lt;P&gt;&lt;A href="http://www.microsoft.com/windowsserver2008/en/us/server-management.aspx" mce_href="http://www.microsoft.com/windowsserver2008/en/us/server-management.aspx"&gt;PowerShell has been included in Windows Server 2008 R2&lt;/A&gt;. If you haven’t heard of it, it’s “a command-line shell and scripting language that helps IT professionals achieve greater productivity and control system administration more easily.” You can learn more about it at the &lt;A href="http://www.microsoft.com/windowsserver2003/technologies/management/powershell/default.mspx" mce_href="http://www.microsoft.com/windowsserver2003/technologies/management/powershell/default.mspx"&gt;PowerShell Website&lt;/A&gt; or at the &lt;A href="http://blogs.msdn.com/PowerShell/" mce_href="http://blogs.msdn.com/PowerShell/"&gt;PowerShell team’s blog&lt;/A&gt;.&lt;/P&gt;
&lt;P&gt;The AD RMS team recently release a guide called &lt;A href="http://technet.microsoft.com/en-us/library/ee221065(WS.10).aspx" mce_href="http://technet.microsoft.com/en-us/library/ee221065(WS.10).aspx"&gt;Using Windows PowerShell with AD RMS&lt;/A&gt;:&lt;/P&gt;
&lt;P&gt;&lt;EM&gt;This guide explains how to use the Windows PowerShell cmdlets that enable you to install, configure, and administer the AD RMS server role on a computer running Windows Server 2008 R2. It introduces the Windows PowerShell providers that implement AD RMS-specific cmdlets, describes the namespace that these cmdlets work in, and also shows how to use general-purpose cmdlets, such as &lt;STRONG&gt;Set-Itemproperty&lt;/STRONG&gt;, to manipulate items in these namespaces that represent AD RMS settings.&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;If you need more information, you can also visit the &lt;A href="http://technet.microsoft.com/en-us/library/ee617271.aspx" mce_href="http://technet.microsoft.com/en-us/library/ee617271.aspx"&gt;reference documentation for the AD RMS cmdlets&lt;/A&gt;.&lt;BR&gt;&amp;nbsp;&lt;/P&gt;&lt;img src="http://blogs.msdn.com/aggbug.aspx?PostID=9909318" width="1" height="1"&gt;</description><category domain="http://blogs.msdn.com/rms/archive/tags/AD+RMS/default.aspx">AD RMS</category><category domain="http://blogs.msdn.com/rms/archive/tags/PowerShell/default.aspx">PowerShell</category></item><item><title>AD RMS and Group Expansion</title><link>http://blogs.msdn.com/rms/archive/2009/09/16/ad-rms-and-group-expansion.aspx</link><pubDate>Wed, 16 Sep 2009 21:57:00 GMT</pubDate><guid isPermaLink="false">91d46819-8472-40ad-a661-2c78acb4018c:9895996</guid><dc:creator>tonytri</dc:creator><slash:comments>0</slash:comments><comments>http://blogs.msdn.com/rms/comments/9895996.aspx</comments><wfw:commentRss>http://blogs.msdn.com/rms/commentrss.aspx?PostID=9895996</wfw:commentRss><wfw:comment>http://blogs.msdn.com/rms/rsscomments.aspx?PostID=9895996</wfw:comment><description>&lt;P&gt;We get occasional questions from customers about AD RMS and group expansion across forests. The following are a few links that can help answer your questions concerning group expansion:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;The topic &lt;A href="http://technet.microsoft.com/en-us/library/cc747685(WS.10).aspx" mce_href="http://technet.microsoft.com/en-us/library/cc747685(WS.10).aspx"&gt;Deploying RMS Across Forests&lt;/A&gt; contains a thorough explanation of how AD RMS works in a multiple-forest environment: “RMS uses Active Directory to identify users and distribution groups. When an organization’s Active Directory deployment includes multiple forests, RMS uses contact objects to obtain the identities of users and groups that are part of a different forest than the RMS server.”&lt;/LI&gt;
&lt;LI&gt;The topic &lt;A href="http://technet.microsoft.com/en-us/library/cc747637(WS.10).aspx#BKMK_CIF1" mce_href="http://technet.microsoft.com/en-us/library/cc747637(WS.10).aspx#BKMK_CIF1"&gt;Release Notes for Windows Rights Management Services with Service Pack 2&lt;/A&gt; contains a brief description of the group expansion functionality available in Windows RMS SP2: “…group expansion across forests facilitates the ability for RMS to expand Active Directory Universal group membership in a different forest where group memberships are not replicated between two forests…”&lt;/LI&gt;
&lt;LI&gt;Jason Tyler, a senior support engineer, has a post on his blog called &lt;A href="http://blogs.technet.com/rmssupp/archive/2007/05/11/troubleshooting-your-rms-server-and-group-membership.aspx" mce_href="http://blogs.technet.com/rmssupp/archive/2007/05/11/troubleshooting-your-rms-server-and-group-membership.aspx"&gt;Troubleshooting your RMS Server and Group Membership&lt;/A&gt;: “The only time that I usually will get on an RMS server to track things down (once it is setup and provisioned), is when I get a call from someone who says 'I am sending this RMS/IRM protected message to a group, and people in the group cannot open the message'.”&lt;/LI&gt;&lt;/UL&gt;&lt;img src="http://blogs.msdn.com/aggbug.aspx?PostID=9895996" width="1" height="1"&gt;</description><category domain="http://blogs.msdn.com/rms/archive/tags/AD+RMS/default.aspx">AD RMS</category><category domain="http://blogs.msdn.com/rms/archive/tags/Troubleshooting/default.aspx">Troubleshooting</category></item><item><title>Information Protection in Exchange 2010</title><link>http://blogs.msdn.com/rms/archive/2009/09/08/information-protection-in-exchange-2010.aspx</link><pubDate>Tue, 08 Sep 2009 20:37:00 GMT</pubDate><guid isPermaLink="false">91d46819-8472-40ad-a661-2c78acb4018c:9892705</guid><dc:creator>tonytri</dc:creator><slash:comments>0</slash:comments><comments>http://blogs.msdn.com/rms/comments/9892705.aspx</comments><wfw:commentRss>http://blogs.msdn.com/rms/commentrss.aspx?PostID=9892705</wfw:commentRss><wfw:comment>http://blogs.msdn.com/rms/rsscomments.aspx?PostID=9892705</wfw:comment><description>
&lt;p&gt;We are excited about the features being built into &lt;a href="http://www.microsoft.com/exchange/2010/en/us/default.aspx" mce_href="http://www.microsoft.com/exchange/2010/en/us/default.aspx"&gt;Exchange 2010&lt;/a&gt; that use AD Rights Management Services technology to ensure that sensitive information is protected. Ed Banti, a Microsoft program manager, recently presented an overview of these features, which we have made available on &lt;a href="http://edge.technet.com/" mce_href="http://edge.technet.com/"&gt;TechNet Edge&lt;/a&gt; as a &lt;a href="http://edge.technet.com/Tags/RMS/" mce_href="http://edge.technet.com/Tags/RMS/"&gt;series of short videos&lt;/a&gt;.&lt;br&gt;&lt;br&gt;In the following video, Ed discusses how end users can benefit from the information protection features in Exchange 2010, which include Outlook Web Access support and full-text search on protected messages:&lt;/p&gt;
&lt;p&gt;&amp;nbsp;&lt;/p&gt;
&lt;object data="data:application/x-silverlight-2," type="application/x-silverlight-2" width="320" height="240"&gt;
&lt;param name="source" value="http://edge.technet.com/App_Themes/default/vp09_06_22.xap"&gt;
&lt;param name="initParams" value="m=mms://mschnlnine.wmod.llnwd.net/a1809/d1/edge/6/5/4/5/RMSenduser_s_edge.wmv,autostart=false,autohide=true,showembed=true, thumbnail=http://ecn.channel9.msdn.com/o9/edge/6/5/4/5/RMSenduser_320_edge.png, postid=5456"&gt;
&lt;param name="background" value="#00FFFFFF"&gt;
&lt;a href="http://go.microsoft.com/fwlink/?LinkID=124807" style="text-decoration: none;"&gt;
&lt;img src="http://go.microsoft.com/fwlink/?LinkId=108181" alt="Get Microsoft Silverlight" style="border-style: none;"&gt;
&lt;/a&gt;
&lt;/object&gt;
&lt;img src="http://blogs.msdn.com/aggbug.aspx?PostID=9892705" width="1" height="1"&gt;</description><category domain="http://blogs.msdn.com/rms/archive/tags/AD+RMS/default.aspx">AD RMS</category><category domain="http://blogs.msdn.com/rms/archive/tags/Exchange/default.aspx">Exchange</category></item><item><title>Microsoft’s AD RMS Rights Policy Templates</title><link>http://blogs.msdn.com/rms/archive/2009/07/23/microsoft-s-ad-rms-rights-policy-templates.aspx</link><pubDate>Thu, 23 Jul 2009 21:41:00 GMT</pubDate><guid isPermaLink="false">91d46819-8472-40ad-a661-2c78acb4018c:9846680</guid><dc:creator>tonytri</dc:creator><slash:comments>0</slash:comments><comments>http://blogs.msdn.com/rms/comments/9846680.aspx</comments><wfw:commentRss>http://blogs.msdn.com/rms/commentrss.aspx?PostID=9846680</wfw:commentRss><wfw:comment>http://blogs.msdn.com/rms/rsscomments.aspx?PostID=9846680</wfw:comment><description>&lt;P&gt;Organizations using AD RMS often take advantage of &lt;A href="http://msdn.microsoft.com/en-us/library/cc542543(VS.85).aspx" mce_href="http://msdn.microsoft.com/en-us/library/cc542543(VS.85).aspx"&gt;rights policy templates&lt;/A&gt; to enable users to protect information according to a predefined set of rights. Many customers are asking us, what specific policy templates are used by the IT organization at Microsoft? Following are examples of the policy templates used by Microsoft’s IT organization: &lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;&lt;STRONG&gt;Microsoft Confidential&amp;nbsp;-&lt;/STRONG&gt; This template uses the Microsoft All Staff distribution group.&amp;nbsp; This group includes all Microsoft full-time employees (FTEs), contractors, and vendor staff.&amp;nbsp; Any person not included in this distribution group, such as people outside the company, cannot open content protected through this template. This template provides the following rights: View, Reply, Reply All, Save, Edit, and Forward.&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;Microsoft Confidential Read Only&lt;/STRONG&gt;&amp;nbsp;- This template uses the Microsoft All Staff distribution group.&amp;nbsp; This group includes all Microsoft full time employees (FTEs), contractors, and vendor staff.&amp;nbsp; Any person not included in this distribution group, such as people outside the company, cannot open content protected through this template.&amp;nbsp; This template provides the following rights: View.&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;Microsoft FTE Confidential &lt;/STRONG&gt;- This template uses the Microsoft All FTE distribution group.&amp;nbsp; This group includes only Microsoft full-time employees (FTEs).&amp;nbsp; Any person not included in this distribution group, such as contractors, vendors, and people outside the company, cannot open content protected through this template.&amp;nbsp; This template provides the following rights: View, Reply, Reply All, Save, Edit, and Forward.&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;Microsoft FTE Confidential Read Only &lt;/STRONG&gt;- This template uses the Microsoft All FTE distribution group.&amp;nbsp; This group includes only Microsoft full-time employees (FTEs).&amp;nbsp; Any person not included in this distribution group, such as contractors, vendors, and people outside the company cannot open content protected through this template.&amp;nbsp; This template provides the following rights: View.&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;Do Not Reply All &lt;/STRONG&gt;– This template simply restricts recipients from using the Reply All function.&amp;nbsp; This prevents large volumes of response traffic to messages sent to many recipients.&lt;/LI&gt;&lt;/UL&gt;
&lt;P&gt;An end user can specify a rights policy template when&amp;nbsp;she creates new content.&amp;nbsp;This helps to ensure that&amp;nbsp;she can easily comply with&amp;nbsp;her organization’s information security policy. Rights policy templates are an important and commonly-used feature of AD RMS. &lt;/P&gt;
&lt;P&gt;You can learn more about rights policy templates in the Microsoft &lt;A href="http://www.technet.com/" mce_href="http://www.technet.com/"&gt;TechNet&lt;/A&gt; topic, &lt;A href="http://technet.microsoft.com/en-us/library/dd996658(WS.10).aspx" mce_href="http://technet.microsoft.com/en-us/library/dd996658(WS.10).aspx"&gt;AD RMS Policy Template Considerations&lt;/A&gt;. This topic provides an overview of the technical considerations you must make when using AD RMS rights policy templates. It includes details about specific rights, template location, template distribution, scripting, and other information.&lt;/P&gt;
&lt;P mce_keep="true"&gt;&amp;nbsp;&lt;/P&gt;&lt;img src="http://blogs.msdn.com/aggbug.aspx?PostID=9846680" width="1" height="1"&gt;</description><category domain="http://blogs.msdn.com/rms/archive/tags/new+content/default.aspx">new content</category></item><item><title>New Technical White Paper: Deploying AD RMS at Microsoft</title><link>http://blogs.msdn.com/rms/archive/2009/07/23/new-technical-white-paper-deploying-ad-rms-at-microsoft.aspx</link><pubDate>Thu, 23 Jul 2009 21:26:00 GMT</pubDate><guid isPermaLink="false">91d46819-8472-40ad-a661-2c78acb4018c:9846671</guid><dc:creator>tonytri</dc:creator><slash:comments>0</slash:comments><comments>http://blogs.msdn.com/rms/comments/9846671.aspx</comments><wfw:commentRss>http://blogs.msdn.com/rms/commentrss.aspx?PostID=9846671</wfw:commentRss><wfw:comment>http://blogs.msdn.com/rms/rsscomments.aspx?PostID=9846671</wfw:comment><description>&lt;P&gt;A technical white paper, &lt;A href="http://technet.microsoft.com/en-us/library/ee156482.aspx" mce_href="http://technet.microsoft.com/en-us/library/ee156482.aspx"&gt;Deploying Active Directory Rights Management Services at Microsoft&lt;/A&gt;, has recently been made available on &lt;A href="http://technet.microsoft.com/en-us/default.aspx" mce_href="http://technet.microsoft.com/en-us/default.aspx"&gt;TechNet&lt;/A&gt;. This white paper is the result of the collaborative effort of Microsoft’s consulting,&amp;nbsp; user assistance, and internal IT organizations. Its purpose is to give you some visibility into the &lt;A href="http://technet.microsoft.com/en-us/library/cc771924(WS.10).aspx" mce_href="http://technet.microsoft.com/en-us/library/cc771924(WS.10).aspx"&gt;AD RMS&lt;/A&gt; deployment process and to help you learn from Microsoft’s own deployment experience.&lt;/P&gt;
&lt;P&gt;The following brief excerpt summarizes the subjects covered:&lt;BR&gt;Since the worldwide implementation of AD RMS at Microsoft, each day, an average of approximately 5,000 documents and e-mail messages are protected to be consumed by 80,000 unique users. These numbers continually grow as an increasing number of users adopt AD RMS technologies as their preferred means of helping to protect their confidential e-mail and documents.&lt;/P&gt;
&lt;P&gt;This paper discusses the need that &lt;A href="http://technet.microsoft.com/en-us/library/bb687766.aspx" mce_href="http://technet.microsoft.com/en-us/library/bb687766.aspx"&gt;Microsoft IT&lt;/A&gt; had for protecting confidential business data, the reasons for deploying RMS over other possible solutions, and how AD RMS works. This paper also offers detailed lessons learned and best practices derived from the RMS server and client deployment and usage experience of Microsoft IT.&lt;/P&gt;&lt;img src="http://blogs.msdn.com/aggbug.aspx?PostID=9846671" width="1" height="1"&gt;</description><category domain="http://blogs.msdn.com/rms/archive/tags/new+content/default.aspx">new content</category></item><item><title>Meet the Team: Matthew Lucas</title><link>http://blogs.msdn.com/rms/archive/2009/07/15/meet-the-team-matthew-lucas.aspx</link><pubDate>Thu, 16 Jul 2009 01:52:00 GMT</pubDate><guid isPermaLink="false">91d46819-8472-40ad-a661-2c78acb4018c:9834758</guid><dc:creator>tonytri</dc:creator><slash:comments>1</slash:comments><comments>http://blogs.msdn.com/rms/comments/9834758.aspx</comments><wfw:commentRss>http://blogs.msdn.com/rms/commentrss.aspx?PostID=9834758</wfw:commentRss><wfw:comment>http://blogs.msdn.com/rms/rsscomments.aspx?PostID=9834758</wfw:comment><description>&lt;P&gt;&lt;STRONG&gt;What is your education and work background?&lt;BR&gt;&lt;/STRONG&gt;I was a college hire from the University of Illinois at Urbana-Champaign.&amp;nbsp; I’ve been at Microsoft for&amp;nbsp;over a year now.&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;How did you come to be a part of the AD RMS team? How long have you worked with the team?&lt;/STRONG&gt; &lt;BR&gt;In college I did my senior project in digital privacy and built a prototypical web-based secure messaging application.&amp;nbsp; I followed my interest in privacy protection and encryption onto this team.&amp;nbsp; I’ve been on this team since I started as a full-timer.&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;What is your role?&lt;/STRONG&gt;&lt;BR&gt;I am the Program Manager handling our Mobile story – prioritizing customer demands, writing functional specifications for new features, coordinating work with partner teams, scheduling work items within our own team, and serving as a primary point-of-contact within the product group for the existing products.&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;What is your favorite aspect of the technology?&lt;/STRONG&gt;&lt;BR&gt;We have better integration with Outlook than any other secure messaging product I’ve seen.&amp;nbsp; That Outlook turns functionalities off in order to enforce the rights schemes dictated by our platform is really cool.&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Any last words?&lt;BR&gt;&lt;/STRONG&gt;If you have an interest in privacy, compliance, or encryption, please let our team know!&lt;/P&gt;&lt;img src="http://blogs.msdn.com/aggbug.aspx?PostID=9834758" width="1" height="1"&gt;</description><category domain="http://blogs.msdn.com/rms/archive/tags/meet+the+team/default.aspx">meet the team</category></item><item><title>More New Content: AD RMS Technical Reference</title><link>http://blogs.msdn.com/rms/archive/2009/07/14/new-content-more-ad-rms-technical-reference.aspx</link><pubDate>Tue, 14 Jul 2009 21:31:00 GMT</pubDate><guid isPermaLink="false">91d46819-8472-40ad-a661-2c78acb4018c:9833385</guid><dc:creator>tonytri</dc:creator><slash:comments>0</slash:comments><comments>http://blogs.msdn.com/rms/comments/9833385.aspx</comments><wfw:commentRss>http://blogs.msdn.com/rms/commentrss.aspx?PostID=9833385</wfw:commentRss><wfw:comment>http://blogs.msdn.com/rms/rsscomments.aspx?PostID=9833385</wfw:comment><description>&lt;P&gt;The team has recently released the following new content to help you use AD RMS:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;&lt;A href="http://technet.microsoft.com/en-us/library/dd772753(WS.10).aspx" mce_href="http://technet.microsoft.com/en-us/library/dd772753(WS.10).aspx"&gt;AD RMS Client Requirements&lt;/A&gt; – Provides important information about the AD RMS client in a format that you can quickly scan and reference. It includes a section that covers requirements for various versions of the client, and a section on AD RMS service discovery.&lt;/LI&gt;
&lt;LI&gt;&lt;A href="http://technet.microsoft.com/en-us/library/dd772651(WS.10).aspx" mce_href="http://technet.microsoft.com/en-us/library/dd772651(WS.10).aspx"&gt;AD RMS and AD FS Considerations&lt;/A&gt; – Provides a brief overview of requirements and configuration options for using AD RMS with Active Directory Federation Services (AD FS).&lt;/LI&gt;
&lt;LI&gt;&lt;A href="http://technet.microsoft.com/en-us/library/dd772670(WS.10).aspx" mce_href="http://technet.microsoft.com/en-us/library/dd772670(WS.10).aspx"&gt;AD RMS Business-To-Business Requirements for Trusted User Domains&lt;/A&gt; – Details the requirements for adding a trusted user domain, which allows the AD RMS root cluster to process requests for client licensor certificates or use licenses from users whose rights account certificates (RACs) were issued by a different AD RMS root cluster.&lt;/LI&gt;&lt;/UL&gt;&lt;img src="http://blogs.msdn.com/aggbug.aspx?PostID=9833385" width="1" height="1"&gt;</description><category domain="http://blogs.msdn.com/rms/archive/tags/new+content/default.aspx">new content</category></item><item><title>New Content: AD RMS Technical Reference</title><link>http://blogs.msdn.com/rms/archive/2009/07/07/new-content-ad-rms-technical-reference.aspx</link><pubDate>Wed, 08 Jul 2009 03:35:00 GMT</pubDate><guid isPermaLink="false">91d46819-8472-40ad-a661-2c78acb4018c:9823289</guid><dc:creator>tonytri</dc:creator><slash:comments>0</slash:comments><comments>http://blogs.msdn.com/rms/comments/9823289.aspx</comments><wfw:commentRss>http://blogs.msdn.com/rms/commentrss.aspx?PostID=9823289</wfw:commentRss><wfw:comment>http://blogs.msdn.com/rms/rsscomments.aspx?PostID=9823289</wfw:comment><description>&lt;P&gt;The AD RMS team has recently published new content that details requirements and prerequisites for your AD RMS environment. They are the following:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;&lt;A href="http://technet.microsoft.com/en-us/library/dd772659(WS.10).aspx" mce_href="http://technet.microsoft.com/en-us/library/dd772659(WS.10).aspx"&gt;AD RMS Prerequisites&lt;/A&gt; – Provides requirements and recommendations for setting up and configuring AD RMS in your environment. It includes information about certificates, DNS, hardware requirements, software requirements, and other topics.&lt;/LI&gt;
&lt;LI&gt;&lt;A href="http://technet.microsoft.com/en-us/library/dd772673(WS.10).aspx" mce_href="http://technet.microsoft.com/en-us/library/dd772673(WS.10).aspx"&gt;AD RMS SQL Server Requirements&lt;/A&gt; – Provides a brief overview of the SQL Server databases used by AD RMS, hardware requirements for the database server, and software requirements for the database server.&lt;/LI&gt;
&lt;LI&gt;&lt;A href="http://technet.microsoft.com/en-us/library/dd941596(WS.10).aspx" mce_href="http://technet.microsoft.com/en-us/library/dd941596(WS.10).aspx"&gt;AD RMS Firewall Considerations&lt;/A&gt; – Details how to configure your firewall for use with AD RMS.&lt;/LI&gt;&lt;/UL&gt;
&lt;P&gt;We hope these guidelines prove to be valuable as you use them to plan for, deploy and configure AD RMS in your environment.&lt;/P&gt;&lt;img src="http://blogs.msdn.com/aggbug.aspx?PostID=9823289" width="1" height="1"&gt;</description><category domain="http://blogs.msdn.com/rms/archive/tags/new+content/default.aspx">new content</category></item><item><title>Templates, Distribution, and Why You Should Care</title><link>http://blogs.msdn.com/rms/archive/2009/06/30/templates-distribution-and-why-you-should-care.aspx</link><pubDate>Wed, 01 Jul 2009 02:41:00 GMT</pubDate><guid isPermaLink="false">91d46819-8472-40ad-a661-2c78acb4018c:9810173</guid><dc:creator>tonytri</dc:creator><slash:comments>0</slash:comments><comments>http://blogs.msdn.com/rms/comments/9810173.aspx</comments><wfw:commentRss>http://blogs.msdn.com/rms/commentrss.aspx?PostID=9810173</wfw:commentRss><wfw:comment>http://blogs.msdn.com/rms/rsscomments.aspx?PostID=9810173</wfw:comment><description>&lt;P&gt;One of the great features of Active Directory Rights Management Services (AD RMS) is rights-policy templates.&amp;nbsp;A template is something that an AD RMS administrator designs that provides a set of users, and/or groups, with a predefined set of rights. These templates are then used by AD RMS-enabled applications to enforce policies.&amp;nbsp;You can read much more about AD RMS templates on TechNet &lt;A href="http://technet.microsoft.com/en-us/library/cc731599(WS.10).aspx" mce_href="http://technet.microsoft.com/en-us/library/cc731599(WS.10).aspx"&gt;here&lt;/A&gt;.&lt;/P&gt;
&lt;P&gt;One of the big problems that IT administrators encounter with rights-policy templates is how to distribute them to end users. If the end user does not have the template, they can’t use the predefined policies. In previous versions of AD RMS (Windows Rights Management Services v1.0 SP&lt;EM&gt;x&lt;/EM&gt;), Group Policy objects (GPO) were used as the primary&amp;nbsp;means&amp;nbsp;for template distribution. The AD RMS administrator would post the template .xml files to a UNC share and use GPO to push them to clients. There was no built-in way for the client to fetch templates.&lt;/P&gt;
&lt;P&gt;Another problem with templates&amp;nbsp;pertained to&amp;nbsp;AD RMS-enabled applications and their developers. Applications that utilize templates typically allow the user to select which template they’d like to use to protect their content. This poses a problem for the application because there is no centralized location where the RM client stores templates, and no built-in way to discover them programmatically. The application was responsible for locating them in&amp;nbsp;its own way (usually&amp;nbsp;by way of&amp;nbsp;registry key overrides). This resulted in different applications that would look for templates in different locations. This was problematic, to say the least.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Enter&amp;nbsp;Template Distribution. So what is template distribution and, ultimately, why should you care? Starting with Windows Vista Service Pack 1, the AD RMS client is able to fetch templates (this requires the AD RMS server to be at least Windows Server 2008) and store them in a centralized location. How? Through scheduled tasks and API’s, that’s how.&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;Scheduled Tasks -&amp;nbsp;There are two scheduled tasks: one manual, and one automated. The automated task runs silently in the background and suppresses authentication prompts (choosing to fail instead). The manual task is the same as the automated task, except that it&amp;nbsp;does not suppress authentication prompts (as opposed to fail silently). When the task executes, it first makes a request to the server&amp;nbsp;to get its template information.&amp;nbsp;From the information returned, the client can determine that it a) has the correct templates and b) has the most up-to-date version of them. If either of these conditions are not met, the client acquires (or re-acquires) the templates from the server.&lt;/LI&gt;
&lt;LI&gt;Client API -&amp;nbsp;In addition to scheduled tasks, the AD RMS client provides developers with an API that can be used to discover and acquire templates for their application. You can read more about that &lt;A href="http://msdn.microsoft.com/en-us/library/bb380775(VS.85).aspx" mce_href="http://msdn.microsoft.com/en-us/library/bb380775(VS.85).aspx"&gt;here&lt;/A&gt;.&amp;nbsp; &lt;/LI&gt;&lt;/UL&gt;
&lt;P&gt;&lt;STRONG&gt;Note:&lt;/STRONG&gt; It is important to point out that archived templates&amp;nbsp;are not distributed to clients. This process applies only&amp;nbsp;to distributed templates, hence the name.&lt;/P&gt;
&lt;P&gt;Sounds great, right? But I’m sure you have some questions. So here’s an FAQ:&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Q. Why are there two tasks, automated and manual?&lt;/STRONG&gt;&lt;BR&gt;A. There are two tasks because the end-user shouldn’t ever have to see a random credential UI for something that runs in the background and, even worse, for something they have no clue what it’s for. The automated task is designed to fail in this case, for this specific reason. The manual task can be invoked at any time by the user.&lt;BR&gt;&lt;STRONG&gt;Q. How often will the automated task run once it’s enabled?&lt;/STRONG&gt;&lt;BR&gt;A. Once the task is enabled, the client will fetch templates (assuming it has never done this before). Afterwards, it creates the following registry key and populates it with the current time: HKCU\Software\Microsoft\MSDRM\TemplateManagement\lastUpdatedTime. Moving forward, the task checks the current time against the value in this registry key. If the date is off by 30 days or more, the client&amp;nbsp;attempts&amp;nbsp;to fetch templates again and the lastUpdatedTime&amp;nbsp;is refreshed with the new date.&lt;BR&gt;&lt;STRONG&gt;Q. So the default period is 30 days – can I change it?&lt;BR&gt;&lt;/STRONG&gt;A. Yes, this can be configured by setting the following registry key: HKCU\Software\Microsoft\MSDRM\TemplateManagement\updateFrequency (DWORD).&lt;BR&gt;&lt;STRONG&gt;Q. Won’t all of the clients make requests at the same time and start a DoS attack?&lt;/STRONG&gt;&lt;BR&gt;A. No. When the client determines that it needs to fetch new templates, it will pick a random time&amp;nbsp;within the next hour.&amp;nbsp;This is to stagger the requests for enabling the scheduled task broadly in a large organization.&lt;BR&gt;&lt;STRONG&gt;Q.&amp;nbsp;Are the templates contained in TPD’s distributed?&lt;/STRONG&gt;&lt;BR&gt;A. No, templates contained in trusted publishing domains (TPD)&amp;nbsp;are not&amp;nbsp;distributed.&lt;BR&gt;&lt;STRONG&gt;Q. Why aren’t my archived templates being distributed?&lt;/STRONG&gt;&lt;BR&gt;A. Wasn’t this answered already? Alright, here goes again. No, only distributed templates will be distributed to clients via template distribution.&lt;BR&gt;&lt;STRONG&gt;Q. Is the automated task enabled out-of-the-box?&lt;/STRONG&gt;&lt;BR&gt;A. No, the automated task is not enabled when Windows is installed, since the majority of Windows users are not in&amp;nbsp;an enterprise.&amp;nbsp; &lt;BR&gt;&lt;STRONG&gt;Q. Where does the client store the templates?&lt;BR&gt;&lt;/STRONG&gt;A. The client stores&amp;nbsp;templates here: %userprofile%\AppData\Local\Microsoft\DRM\templates.&lt;BR&gt;&lt;STRONG&gt;Q. Is this functionality available on Windows XP, Windows Server 2003, or Windows Vista RTM?&lt;/STRONG&gt;&lt;BR&gt;A. No, this functionality is provided only on Vista SP1 and above.&lt;BR&gt;&lt;STRONG&gt;Q. Is this functionality available for Windows Rights Management Services v1.0 SP&lt;EM&gt;x&lt;/EM&gt; on Windows Server 2003?&lt;BR&gt;&lt;/STRONG&gt;A. No, this functionality is available only on Windows Server 2008 and above.&lt;/P&gt;
&lt;P&gt;And there you have it – template distribution made easy.&lt;/P&gt;
&lt;P&gt;Jody Hendrix, Lead Software Design Engineer in Test&lt;BR&gt;&lt;/P&gt;&lt;img src="http://blogs.msdn.com/aggbug.aspx?PostID=9810173" width="1" height="1"&gt;</description><category domain="http://blogs.msdn.com/rms/archive/tags/R2+Features/default.aspx">R2 Features</category></item><item><title>New Content: AD RMS and Active Directory Objects</title><link>http://blogs.msdn.com/rms/archive/2009/06/29/new-content-ad-rms-and-active-directory-objects.aspx</link><pubDate>Mon, 29 Jun 2009 20:58:00 GMT</pubDate><guid isPermaLink="false">91d46819-8472-40ad-a661-2c78acb4018c:9808790</guid><dc:creator>tonytri</dc:creator><slash:comments>0</slash:comments><comments>http://blogs.msdn.com/rms/comments/9808790.aspx</comments><wfw:commentRss>http://blogs.msdn.com/rms/commentrss.aspx?PostID=9808790</wfw:commentRss><wfw:comment>http://blogs.msdn.com/rms/rsscomments.aspx?PostID=9808790</wfw:comment><description>&lt;P&gt;The AD RMS team has recently published &lt;A href="http://technet.microsoft.com/en-us/library/dd772638(WS.10).aspx" mce_href="http://technet.microsoft.com/en-us/library/dd772638(WS.10).aspx"&gt;new content&lt;/A&gt; that summarizes the required and optional AD DS user and computer objects for an AD RMS implementation.&lt;/P&gt;
&lt;P&gt;The following abstract provides some details:&lt;BR&gt;&lt;EM&gt;Microsoft Active Directory Domain Services (AD DS) is a Windows-based directory service. AD DS stores information about objects on a network and makes this information available to users and network administrators. For example, these objects can include user and computer accounts. AD DS is a requirement for installing and implementing AD RMS.&lt;/EM&gt;&lt;/P&gt;
&lt;P mce_keep="true"&gt;&amp;nbsp;&lt;/P&gt;&lt;img src="http://blogs.msdn.com/aggbug.aspx?PostID=9808790" width="1" height="1"&gt;</description><category domain="http://blogs.msdn.com/rms/archive/tags/AD+RMS/default.aspx">AD RMS</category><category domain="http://blogs.msdn.com/rms/archive/tags/new+content/default.aspx">new content</category></item><item><title>New Content: AD RMS Performance and Logging Best Practices</title><link>http://blogs.msdn.com/rms/archive/2009/06/29/new-content-ad-rms-performance-and-logging-best-practices.aspx</link><pubDate>Mon, 29 Jun 2009 20:56:00 GMT</pubDate><guid isPermaLink="false">91d46819-8472-40ad-a661-2c78acb4018c:9808787</guid><dc:creator>tonytri</dc:creator><slash:comments>0</slash:comments><comments>http://blogs.msdn.com/rms/comments/9808787.aspx</comments><wfw:commentRss>http://blogs.msdn.com/rms/commentrss.aspx?PostID=9808787</wfw:commentRss><wfw:comment>http://blogs.msdn.com/rms/rsscomments.aspx?PostID=9808787</wfw:comment><description>&lt;P&gt;The AD RMS team has recently published &lt;A href="http://technet.microsoft.com/en-us/library/dd941633(WS.10).aspx" mce_href="http://technet.microsoft.com/en-us/library/dd941633(WS.10).aspx"&gt;new content&lt;/A&gt; that details best practices for properly scaling and managing your AD RMS infrastructure.&lt;/P&gt;
&lt;P&gt;The following abstract details the contents of this documentation:&lt;BR&gt;&lt;EM&gt;Here we describe the scaling scheme for an AD RMS infrastructure, we define sizing parameters for the server roles in an AD RMS infrastructure, and we describe logging characteristics of AD RMS that enable adequate performance monitoring. We also present real-world data regarding Microsoft’s own production implementation of AD RMS in order to enable you to perform preliminary sizing estimates for your own infrastructure.&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;We hope these guidelines prove to be helpful to you as you configure your AD RMS environment.&lt;/P&gt;
&lt;P mce_keep="true"&gt;&amp;nbsp;&lt;/P&gt;&lt;img src="http://blogs.msdn.com/aggbug.aspx?PostID=9808787" width="1" height="1"&gt;</description><category domain="http://blogs.msdn.com/rms/archive/tags/AD+RMS/default.aspx">AD RMS</category><category domain="http://blogs.msdn.com/rms/archive/tags/new+content/default.aspx">new content</category></item><item><title>New Content: AD RMS Client Deployment and Usage Considerations</title><link>http://blogs.msdn.com/rms/archive/2009/06/29/new-content-ad-rms-client-deployment-and-usage-considerations.aspx</link><pubDate>Mon, 29 Jun 2009 20:43:00 GMT</pubDate><guid isPermaLink="false">91d46819-8472-40ad-a661-2c78acb4018c:9808782</guid><dc:creator>tonytri</dc:creator><slash:comments>0</slash:comments><comments>http://blogs.msdn.com/rms/comments/9808782.aspx</comments><wfw:commentRss>http://blogs.msdn.com/rms/commentrss.aspx?PostID=9808782</wfw:commentRss><wfw:comment>http://blogs.msdn.com/rms/rsscomments.aspx?PostID=9808782</wfw:comment><description>&lt;P&gt;The AD RMS team has recently published &lt;A href="http://technet.microsoft.com/en-us/library/dd772718(WS.10).aspx" mce_href="http://technet.microsoft.com/en-us/library/dd772718(WS.10).aspx"&gt;new documentation&lt;/A&gt; that discuss best practices for managing your AD RMS client deployment. &lt;/P&gt;
&lt;P&gt;The following abstract provides some details about the content:&lt;BR&gt;&lt;EM&gt;Active Directory Rights Management Services (AD RMS) is an information protection technology that works with enabled applications to help safeguard digital information from unauthorized use. Content owners can define exactly how a recipient can use the information, such as who can open, modify, print, forward, or take other actions on the information.&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;&lt;EM&gt;AD RMS includes server-side technologies as well as client-side technologies. On the client, an RMS client must be in place, RMS enabled applications must be deployed and information protection policies and templates must be delivered.&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;&lt;EM&gt;In this paper we describe the best practices for safely and efficiently getting all those components in place on the client, as well as options for configuring the client in different scenarios.&lt;/EM&gt;&lt;/P&gt;
&lt;P mce_keep="true"&gt;&amp;nbsp;&lt;/P&gt;&lt;img src="http://blogs.msdn.com/aggbug.aspx?PostID=9808782" width="1" height="1"&gt;</description><category domain="http://blogs.msdn.com/rms/archive/tags/AD+RMS/default.aspx">AD RMS</category><category domain="http://blogs.msdn.com/rms/archive/tags/new+content/default.aspx">new content</category></item><item><title>New Content: Information-Rights-Management Architecture and Design Guidance for AD RMS Application Developers</title><link>http://blogs.msdn.com/rms/archive/2009/06/18/new-content-information-rights-management-architecture-and-design-guidance-for-ad-rms-application-developers.aspx</link><pubDate>Thu, 18 Jun 2009 23:40:00 GMT</pubDate><guid isPermaLink="false">91d46819-8472-40ad-a661-2c78acb4018c:9777431</guid><dc:creator>tonytri</dc:creator><slash:comments>0</slash:comments><comments>http://blogs.msdn.com/rms/comments/9777431.aspx</comments><wfw:commentRss>http://blogs.msdn.com/rms/commentrss.aspx?PostID=9777431</wfw:commentRss><wfw:comment>http://blogs.msdn.com/rms/rsscomments.aspx?PostID=9777431</wfw:comment><description>&lt;P&gt;Bhushan Nene and Trent Swanson, architects on our Global Partner team, recently published a &lt;A href="http://www.microsoft.com/downloads/details.aspx?FamilyID=033f654b-bd98-4e75-8d21-d0b50c0b89fd&amp;amp;displaylang=en" mce_href="http://www.microsoft.com/downloads/details.aspx?FamilyID=033f654b-bd98-4e75-8d21-d0b50c0b89fd&amp;amp;displaylang=en"&gt;white paper&lt;/A&gt; that can give you insight into building applications that use AD RMS information rights management technology.&lt;/P&gt;
&lt;P&gt;The following abstract details the contents of the document:&lt;BR&gt;&lt;EM&gt;This white paper provides architecture and design guidance for building an Information Rights Management (IRM)-aware application using Microsoft Active Directory Rights Management Services (AD RMS).&amp;nbsp; It presents a number of application patterns as well as best practices that you can use for developing IRM-aware applications. It covers basic consume and publish scenarios as well as complex federated scenarios that make use of Active Directory Federation Services (AD FS). It makes extensive reference to the &lt;/EM&gt;&lt;A href="http://code.msdn.microsoft.com/irmapplnpatterns" mce_href="http://code.msdn.microsoft.com/irmapplnpatterns"&gt;&lt;EM&gt;IRM Application Patterns Reference Implementation&lt;/EM&gt;&lt;/A&gt;&lt;EM&gt; available for download at the MSDN Code Gallery.&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;We hope you find it to be helpful.&lt;/P&gt;
&lt;P mce_keep="true"&gt;&amp;nbsp;&lt;/P&gt;&lt;img src="http://blogs.msdn.com/aggbug.aspx?PostID=9777431" width="1" height="1"&gt;</description><category domain="http://blogs.msdn.com/rms/archive/tags/new+content/default.aspx">new content</category></item></channel></rss>