<?xml version="1.0" encoding="UTF-8" ?>
<?xml-stylesheet type="text/xsl" href="http://blogs.msdn.com/utility/FeedStylesheets/rss.xsl" media="screen"?><rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:slash="http://purl.org/rss/1.0/modules/slash/" xmlns:wfw="http://wellformedweb.org/CommentAPI/"><channel><title>Active Directory Rights Management Services - AD RMS : Windows Server R2 features</title><link>http://blogs.msdn.com/rms/archive/tags/Windows+Server+R2+features/default.aspx</link><description>Tags: Windows Server R2 features</description><dc:language>en-US</dc:language><generator>CommunityServer 2.1 SP1 (Build: 61025.2)</generator><item><title>Group Expansion for Federated Users</title><link>http://blogs.msdn.com/rms/archive/2009/06/09/group-expansion-for-federated-users.aspx</link><pubDate>Tue, 09 Jun 2009 20:56:00 GMT</pubDate><guid isPermaLink="false">91d46819-8472-40ad-a661-2c78acb4018c:9716799</guid><dc:creator>tonytri</dc:creator><slash:comments>0</slash:comments><comments>http://blogs.msdn.com/rms/comments/9716799.aspx</comments><wfw:commentRss>http://blogs.msdn.com/rms/commentrss.aspx?PostID=9716799</wfw:commentRss><wfw:comment>http://blogs.msdn.com/rms/rsscomments.aspx?PostID=9716799</wfw:comment><description>&lt;P&gt;[&lt;STRONG&gt;Note -&lt;/STRONG&gt;&amp;nbsp;This post assumes the reader is familiar with terms such as &lt;A href="http://msdn.microsoft.com/en-us/library/cc530453(VS.85).aspx" mce_href="http://msdn.microsoft.com/en-us/library/cc530453(VS.85).aspx"&gt;issuance license&lt;/A&gt;, &lt;A href="http://technet.microsoft.com/en-us/library/cc731599(WS.10).aspx" mce_href="http://technet.microsoft.com/en-us/library/cc731599(WS.10).aspx"&gt;rights-policy templates&lt;/A&gt;, and &lt;A href="http://technet.microsoft.com/en-us/library/cc755156(WS.10).aspx" mce_href="http://technet.microsoft.com/en-us/library/cc755156(WS.10).aspx"&gt;AD RMS trust policies&lt;/A&gt; (federated trust).&amp;nbsp; In summary, an issuance license represents the usage policy for a piece of content and contains a list of authorized users and usage rights assigned to each&amp;nbsp;user. Rights-policy templates are used to control the rights that a user or group has on a particular piece of rights-protected content.&amp;nbsp;Federated trust refers to using Active Directory Federation Services to establish trust between two forests.&lt;/P&gt;
&lt;P&gt;This blog post references Windows Server 2008 R2. The release candidate for Windows Server 2008 R2 can be downloaded at &lt;A href="http://www.microsoft.com/"&gt;www.microsoft.com&lt;/A&gt;. Please see the &lt;A href="http://technet.microsoft.com/en-us/library/cc771425(WS.10).aspx" mce_href="http://technet.microsoft.com/en-us/library/cc771425(WS.10).aspx"&gt;AD RMS with AD FS Identity Federation Step-by-Step Guide&lt;/A&gt; to&amp;nbsp;learn how to configure an AD RMS server to work with &lt;A href="http://technet.microsoft.com/en-us/library/dd391937(WS.10).aspx" mce_href="http://technet.microsoft.com/en-us/library/dd391937(WS.10).aspx"&gt;Active Directory Federation Services (ADFS)&lt;/A&gt;.]&lt;/P&gt;
&lt;P&gt;AD RMS in Windows Server 2008 R2 can support groups that contain external, federated users. In Windows Server 2008, federated users&amp;nbsp;had to be individually named in the issuance license or individually added to an AD RMS rights-policy template. Now, because group expansion for federated users is supported, it is possible to add&amp;nbsp;federated users to a group and create protected content specifically for the group. This can be accomplished by creating a contact object for the federated users in Active Directory,&amp;nbsp;in the forest where&amp;nbsp;the AD RMS server is located, and adding that contact object to the group where you want to include the federated users. &lt;/P&gt;
&lt;P&gt;Here’s an example:&lt;BR&gt;Contoso&amp;nbsp;has AD RMS and a group called TopSecretProj@Contoso.com.&amp;nbsp;Contoso has decided to collaborate with Fabrikam. Usr01@Fabrikam.com&amp;nbsp;must&amp;nbsp;access all content that is shared&amp;nbsp;with&amp;nbsp;the TopSecretProj@Contoso.com group.&amp;nbsp; The IT administrator in&amp;nbsp;Contoso can create a contact object for Usr01@Fabrikam.com in Active Directory&amp;nbsp;and add the new contact object as a member of TopSecretProj@Contoso.com.&amp;nbsp; &lt;BR&gt;As long as you have identity federation support configured and enabled between the two companies, &lt;A href="mailto:Usr01@Fabrikam.com"&gt;Usr01@Fabrikam.com&lt;/A&gt;&amp;nbsp;has access to all the content published for &lt;A href="mailto:TopSecretProj@Contoso.com"&gt;TopSecretProj@Contoso.com&lt;/A&gt;.&lt;/P&gt;
&lt;P&gt;&lt;IMG style="WIDTH: 718px; HEIGHT: 590px" src="http://7hcazq.blu.livefilestore.com/y1pjn0lR52a-7cUauqLpkAMN4X0r7B27g3JOWgLBfatMVjWfiLBt9GvnoeNmbtNV837cKOr2Pr3nH4DAz3jKkyvrQVV8u7ebGCK/sunitha_graphic.jpg" width=718 height=590 mce_src="http://7hcazq.blu.livefilestore.com/y1pjn0lR52a-7cUauqLpkAMN4X0r7B27g3JOWgLBfatMVjWfiLBt9GvnoeNmbtNV837cKOr2Pr3nH4DAz3jKkyvrQVV8u7ebGCK/sunitha_graphic.jpg"&gt;&lt;/P&gt;
&lt;P&gt;Sunitha Samuel,&amp;nbsp;Lead Software Design Engineer in Test&lt;/P&gt;
&lt;P mce_keep="true"&gt;&amp;nbsp;&lt;/P&gt;&lt;img src="http://blogs.msdn.com/aggbug.aspx?PostID=9716799" width="1" height="1"&gt;</description><category domain="http://blogs.msdn.com/rms/archive/tags/AD+RMS/default.aspx">AD RMS</category><category domain="http://blogs.msdn.com/rms/archive/tags/Windows+Server+R2+features/default.aspx">Windows Server R2 features</category></item></channel></rss>