Run the AD RMS Upgrade wizard

Applies To: Windows Server 2003, Windows Server 2003 R2, Windows Server 2003 with SP1, Windows Server 2003 with SP2, Windows Server 2008, Windows Server 2008 R2, Windows Server 2012 R2

The AD RMS Upgrade Wizard must be completed after the operating system is upgraded to Windows Server 2008 or Windows Server 2008 R2. If you do not run the AD RMS Upgrade Wizard, your AD RMS infrastructure will not function. It is only necessary to run the AD RMS Upgrade Wizard on the first computer that you upgrade to Windows Server 2008 or Windows Server 2008 R2.

Note

If you are using a hardware security module (HSM) to protect the cluster’s private key, you must install the Windows Server 2008 or Windows Server 2008 R2 version of the HSM drivers before starting the AD RMS Upgrade Wizard.

To run the AD RMS Upgrade Wizard

  1. Log on to the RMS server that was just upgraded to Windows Server 2008 or Windows Server 2008 R2 with a user account that is a member of the local Administrators group and that is a member of the System Administrators database role, or equivalent, on the database server.

  2. Click Start, point to Administrative Tools, and then click Server Manager.

  3. Expand Roles, and then click Active Directory Rights Management Services.

  4. In the results pane, click Complete Installation of Active Directory Rights Management Services.

  5. On the Upgrading Active Directory Rights Management Services page, click Next.

  6. If your RMS cluster was configured to use the local SYSTEM account as the service account for the cluster, select a domain user account to use as the service account for the AD RMS cluster instead.

  7. Type the service account password in the Password and Confirm password boxes, and then click Next.

  8. If RMS is managing the cluster’s private key, on the RMS Private key Password page, type the RMS private key password in the Password and Confirm password boxes, and then click Next.

  9. On the Confirm Installation Options page, click Next.

  10. After the installation has finished, click Close.

  11. You must log off of the computer and then log back in with the user account used in Step 1 of this procedure for the security token to update with your new group memberships.

Note

Doing this adds the AD RMS Enterprise Admins group to your security token. You will not be able to use the Active Directory Rights Management Services console until you log off and log back on to the server.