AD RMS and Active Directory Objects
Applies To: Windows Server 2008, Windows Server 2008 R2
Microsoft Active Directory Domain Services (AD DS) is a Windows-based directory service. AD DS stores information about objects on a network and makes this information available to users and network administrators. For example, these objects can include user and computer accounts. AD DS is a requirement for installing and implementing AD RMS.
The following table summarizes the required and optional AD DS user and computer objects for an AD RMS implementation.
| Active Directory Object | Description | Remarks |
|---|---|---|
|
AD RMS Servers Computer Accounts |
All servers in the AD RMS Certification/Licensing cluster must be Active Directory domain members |
|
|
AD RMS Admin Account |
Create a dedicated user account to administer the AD RMS architecture. |
|
|
AD RMS Service Account |
Create a dedicated user account to use as the AD RMS service account. For security reasons, it is strongly recommended that you create a special user account used exclusively as the AD RMS service account. . |
|
|
SQL Service Account |
Create a dedicated user account to use as the SQL service account. For security reasons, it is strongly recommended that a special user account be used exclusively as the SQL service account. . |
|
|
Superuser Group |
This sensitive group is used to grant access to RMS-protected documents, even though members of this group do not have explicit rights to the documents. |
|
|
Users |
AD RMS users must be members of a domain and use their domain account. |
|
|
Contacts |
AD RMS can use contacts to work properly in a multi-forest environment. |
|
|
Service Connection Point |
AD RMS uses a serviceConnectionPoint object in a forest to enable service discovery by clients. |
|
|
ADFS Admin Account (Optional) |
Create a dedicated user account to administer the AD FS component. |
|
