powerpoint presentationdownload.microsoft.com/documents/hk/technet... · slc to fabrikam 2)...

164

Upload: others

Post on 13-Jun-2020

3 views

Category:

Documents


0 download

TRANSCRIPT

Page 1: PowerPoint Presentationdownload.microsoft.com/documents/hk/technet... · SLC to Fabrikam 2) Fabrikam imports SLC 3) John@fabrikam.com sends RM content to Monica@adventure.com 4) Monica@adventure.com
Page 2: PowerPoint Presentationdownload.microsoft.com/documents/hk/technet... · SLC to Fabrikam 2) Fabrikam imports SLC 3) John@fabrikam.com sends RM content to Monica@adventure.com 4) Monica@adventure.com
Page 3: PowerPoint Presentationdownload.microsoft.com/documents/hk/technet... · SLC to Fabrikam 2) Fabrikam imports SLC 3) John@fabrikam.com sends RM content to Monica@adventure.com 4) Monica@adventure.com
Page 4: PowerPoint Presentationdownload.microsoft.com/documents/hk/technet... · SLC to Fabrikam 2) Fabrikam imports SLC 3) John@fabrikam.com sends RM content to Monica@adventure.com 4) Monica@adventure.com
Page 5: PowerPoint Presentationdownload.microsoft.com/documents/hk/technet... · SLC to Fabrikam 2) Fabrikam imports SLC 3) John@fabrikam.com sends RM content to Monica@adventure.com 4) Monica@adventure.com
Page 6: PowerPoint Presentationdownload.microsoft.com/documents/hk/technet... · SLC to Fabrikam 2) Fabrikam imports SLC 3) John@fabrikam.com sends RM content to Monica@adventure.com 4) Monica@adventure.com
Page 7: PowerPoint Presentationdownload.microsoft.com/documents/hk/technet... · SLC to Fabrikam 2) Fabrikam imports SLC 3) John@fabrikam.com sends RM content to Monica@adventure.com 4) Monica@adventure.com

AD RMS Key Concepts

Deploying AD RMS in complex Scenarios

Multiple forests

Logically isolated environments

Physically isolated environments

Centralized licensing

Integrating Partners

Extranet

Page 8: PowerPoint Presentationdownload.microsoft.com/documents/hk/technet... · SLC to Fabrikam 2) Fabrikam imports SLC 3) John@fabrikam.com sends RM content to Monica@adventure.com 4) Monica@adventure.com
Page 9: PowerPoint Presentationdownload.microsoft.com/documents/hk/technet... · SLC to Fabrikam 2) Fabrikam imports SLC 3) John@fabrikam.com sends RM content to Monica@adventure.com 4) Monica@adventure.com

AD RMS Server Active Directory SQL

Protection Consumption

Page 10: PowerPoint Presentationdownload.microsoft.com/documents/hk/technet... · SLC to Fabrikam 2) Fabrikam imports SLC 3) John@fabrikam.com sends RM content to Monica@adventure.com 4) Monica@adventure.com

AD RMS Server Active Directory SQL

Protection Consumption

Page 11: PowerPoint Presentationdownload.microsoft.com/documents/hk/technet... · SLC to Fabrikam 2) Fabrikam imports SLC 3) John@fabrikam.com sends RM content to Monica@adventure.com 4) Monica@adventure.com

AD RMS Server Active Directory SQL

CLC

Protection Consumption

Page 12: PowerPoint Presentationdownload.microsoft.com/documents/hk/technet... · SLC to Fabrikam 2) Fabrikam imports SLC 3) John@fabrikam.com sends RM content to Monica@adventure.com 4) Monica@adventure.com

AD RMS Server Active Directory SQL

1 Protection Consumption

CLC

Page 13: PowerPoint Presentationdownload.microsoft.com/documents/hk/technet... · SLC to Fabrikam 2) Fabrikam imports SLC 3) John@fabrikam.com sends RM content to Monica@adventure.com 4) Monica@adventure.com

AD RMS Server Active Directory SQL

1

2 CLC

Protection Consumption

Page 14: PowerPoint Presentationdownload.microsoft.com/documents/hk/technet... · SLC to Fabrikam 2) Fabrikam imports SLC 3) John@fabrikam.com sends RM content to Monica@adventure.com 4) Monica@adventure.com

AD RMS Server Active Directory SQL

1

2 CLC

Protection Consumption 3

Page 15: PowerPoint Presentationdownload.microsoft.com/documents/hk/technet... · SLC to Fabrikam 2) Fabrikam imports SLC 3) John@fabrikam.com sends RM content to Monica@adventure.com 4) Monica@adventure.com

AD RMS Server Active Directory SQL

1

2 CLC

Protection Consumption

4

3

Page 16: PowerPoint Presentationdownload.microsoft.com/documents/hk/technet... · SLC to Fabrikam 2) Fabrikam imports SLC 3) John@fabrikam.com sends RM content to Monica@adventure.com 4) Monica@adventure.com

AD RMS Server Active Directory SQL

1

2 CLC

Protection Consumption

4

5 3

Page 17: PowerPoint Presentationdownload.microsoft.com/documents/hk/technet... · SLC to Fabrikam 2) Fabrikam imports SLC 3) John@fabrikam.com sends RM content to Monica@adventure.com 4) Monica@adventure.com

AD RMS Server Active Directory SQL

1

2 CLC

Protection Consumption

4

5 6

3

Page 18: PowerPoint Presentationdownload.microsoft.com/documents/hk/technet... · SLC to Fabrikam 2) Fabrikam imports SLC 3) John@fabrikam.com sends RM content to Monica@adventure.com 4) Monica@adventure.com

AD RMS Server Active Directory SQL

1

2 CLC

Protection Consumption

4

5 6

7

3

Page 19: PowerPoint Presentationdownload.microsoft.com/documents/hk/technet... · SLC to Fabrikam 2) Fabrikam imports SLC 3) John@fabrikam.com sends RM content to Monica@adventure.com 4) Monica@adventure.com

AD RMS Server Active Directory SQL

1

2 CLC

Protection Consumption

4

5 6

7

8

3

Page 20: PowerPoint Presentationdownload.microsoft.com/documents/hk/technet... · SLC to Fabrikam 2) Fabrikam imports SLC 3) John@fabrikam.com sends RM content to Monica@adventure.com 4) Monica@adventure.com

AD RMS Server Active Directory SQL

1

2 CLC

Protection Consumption

4

5 6

7

8

9

3

Page 21: PowerPoint Presentationdownload.microsoft.com/documents/hk/technet... · SLC to Fabrikam 2) Fabrikam imports SLC 3) John@fabrikam.com sends RM content to Monica@adventure.com 4) Monica@adventure.com

AD RMS Server Terminology Certification server (or cluster)

First AD RMS server (cluster) in the enterprise

Provides certification and licensing capabilities

Licensing server (optional)

Provides licensing services only

Relies on a certification server for certification of users

Cluster

Group of equivalent AD RMS servers sharing the same database

Not to be confused with Windows Server Clustering Services

Page 22: PowerPoint Presentationdownload.microsoft.com/documents/hk/technet... · SLC to Fabrikam 2) Fabrikam imports SLC 3) John@fabrikam.com sends RM content to Monica@adventure.com 4) Monica@adventure.com

AD RMS Server

Mobile devices

(Windows Mobile 6.0)

RMS Client

RM-enabled application

AD RMS Infrastructure Components

Page 23: PowerPoint Presentationdownload.microsoft.com/documents/hk/technet... · SLC to Fabrikam 2) Fabrikam imports SLC 3) John@fabrikam.com sends RM content to Monica@adventure.com 4) Monica@adventure.com

AD RMS Server

Active Directory

Mobile devices

(Windows Mobile 6.0)

RMS Client

RM-enabled application

AD RMS Infrastructure Components

Page 24: PowerPoint Presentationdownload.microsoft.com/documents/hk/technet... · SLC to Fabrikam 2) Fabrikam imports SLC 3) John@fabrikam.com sends RM content to Monica@adventure.com 4) Monica@adventure.com

AD RMS Server

Active Directory

Mobile devices

(Windows Mobile 6.0)

RMS Client

RM-enabled application

AD RMS Infrastructure Components

SQL

Page 25: PowerPoint Presentationdownload.microsoft.com/documents/hk/technet... · SLC to Fabrikam 2) Fabrikam imports SLC 3) John@fabrikam.com sends RM content to Monica@adventure.com 4) Monica@adventure.com

AD RMS Server

Active Directory

Mobile devices

(Windows Mobile 6.0)

RMS Client

RM-enabled application

AD RMS Infrastructure Components

SQL

MOSS 2007

Page 26: PowerPoint Presentationdownload.microsoft.com/documents/hk/technet... · SLC to Fabrikam 2) Fabrikam imports SLC 3) John@fabrikam.com sends RM content to Monica@adventure.com 4) Monica@adventure.com

AD RMS Server

Active Directory

SQL

MOSS 2007

Exchange Server 2007 SP1

Mobile devices

(Windows Mobile 6.0)

RMS Client

RM-enabled application

AD RMS Infrastructure Components

Page 27: PowerPoint Presentationdownload.microsoft.com/documents/hk/technet... · SLC to Fabrikam 2) Fabrikam imports SLC 3) John@fabrikam.com sends RM content to Monica@adventure.com 4) Monica@adventure.com

AD RMS Topology

AD RMS

Root Server Database

Page 28: PowerPoint Presentationdownload.microsoft.com/documents/hk/technet... · SLC to Fabrikam 2) Fabrikam imports SLC 3) John@fabrikam.com sends RM content to Monica@adventure.com 4) Monica@adventure.com

AD RMS Topology

Database

AD RMS

Certification

Cluster

Page 29: PowerPoint Presentationdownload.microsoft.com/documents/hk/technet... · SLC to Fabrikam 2) Fabrikam imports SLC 3) John@fabrikam.com sends RM content to Monica@adventure.com 4) Monica@adventure.com

AD RMS Topology

Database

AD RMS

Certification

Cluster

Database

License-only Server

Page 30: PowerPoint Presentationdownload.microsoft.com/documents/hk/technet... · SLC to Fabrikam 2) Fabrikam imports SLC 3) John@fabrikam.com sends RM content to Monica@adventure.com 4) Monica@adventure.com

AD RMS Topology

Database

AD RMS

Certification

Cluster

Database

License-only Server

Database

License-only Server Cluster

Page 31: PowerPoint Presentationdownload.microsoft.com/documents/hk/technet... · SLC to Fabrikam 2) Fabrikam imports SLC 3) John@fabrikam.com sends RM content to Monica@adventure.com 4) Monica@adventure.com

AD RMS Server

AD RMS Server

Runs on Windows Server 2008 inside IIS

It’s a web service!

Typically runs over SSL

Requires IIS with ASP.NET

Stateless

Uses (before Windows 8) Microsoft Message Queuing

Responsible for transactions to be applied to SQL database

Provides tolerance when connectivity is lost between ADRMS server and SQL Server

Page 32: PowerPoint Presentationdownload.microsoft.com/documents/hk/technet... · SLC to Fabrikam 2) Fabrikam imports SLC 3) John@fabrikam.com sends RM content to Monica@adventure.com 4) Monica@adventure.com

AD RMS Databases

AD RMS web services are stateless

All persistent information is stored in SQL Server

Three separate databases

Configuration: hosts configuration data, cluster and user keys

Caching: caches AD identities and group membership

Logging: stores logs of licensing operations

Most operations are performed asynchronously

Data is written to MSMQ, flushed to the DB when possible

If DB not available, AD RMS continues to work “almost” normally

Page 33: PowerPoint Presentationdownload.microsoft.com/documents/hk/technet... · SLC to Fabrikam 2) Fabrikam imports SLC 3) John@fabrikam.com sends RM content to Monica@adventure.com 4) Monica@adventure.com

Active Directory

Provides authentication

All accounts related to AD RMS must have an email account

Provides Service Connection Point (SCP) for service location

Determines recipient group membership

Active Directory should be in native mode for group propagation

One AD RMS root cluster per forest

AD RMS certification is limited to users in the AD forest

Active Directory

Page 34: PowerPoint Presentationdownload.microsoft.com/documents/hk/technet... · SLC to Fabrikam 2) Fabrikam imports SLC 3) John@fabrikam.com sends RM content to Monica@adventure.com 4) Monica@adventure.com

What’s in a Certificate

AD RMS uses certificates for identity and licenses

AD RMS does not use X.509 certificates!

It uses XrML certs instead

Similar to X.509 but with room for policy

Identity certificate: “this is User X and her email is…”

There are also machine and server certificates

Page 35: PowerPoint Presentationdownload.microsoft.com/documents/hk/technet... · SLC to Fabrikam 2) Fabrikam imports SLC 3) John@fabrikam.com sends RM content to Monica@adventure.com 4) Monica@adventure.com

What’s in a license An IRM protected document has an embedded

“Publishing License”

List of rights (like an ACL)

Subjects of rights are email addresses Groups or users

Rights are operations View

Edit

Copy

Print

Forward

Page 36: PowerPoint Presentationdownload.microsoft.com/documents/hk/technet... · SLC to Fabrikam 2) Fabrikam imports SLC 3) John@fabrikam.com sends RM content to Monica@adventure.com 4) Monica@adventure.com

AD RMS Certificates and Licenses

Page 37: PowerPoint Presentationdownload.microsoft.com/documents/hk/technet... · SLC to Fabrikam 2) Fabrikam imports SLC 3) John@fabrikam.com sends RM content to Monica@adventure.com 4) Monica@adventure.com

AD RMS Certificates and Licenses

Page 38: PowerPoint Presentationdownload.microsoft.com/documents/hk/technet... · SLC to Fabrikam 2) Fabrikam imports SLC 3) John@fabrikam.com sends RM content to Monica@adventure.com 4) Monica@adventure.com

AD RMS Certificates and Licenses

Page 39: PowerPoint Presentationdownload.microsoft.com/documents/hk/technet... · SLC to Fabrikam 2) Fabrikam imports SLC 3) John@fabrikam.com sends RM content to Monica@adventure.com 4) Monica@adventure.com

AD RMS Certificates and Licenses

Page 40: PowerPoint Presentationdownload.microsoft.com/documents/hk/technet... · SLC to Fabrikam 2) Fabrikam imports SLC 3) John@fabrikam.com sends RM content to Monica@adventure.com 4) Monica@adventure.com

AD RMS Certificates and Licenses

Page 41: PowerPoint Presentationdownload.microsoft.com/documents/hk/technet... · SLC to Fabrikam 2) Fabrikam imports SLC 3) John@fabrikam.com sends RM content to Monica@adventure.com 4) Monica@adventure.com

AD RMS Certificates and Licenses SLC:

Server

Licensor

Certificate

Identifies

an AD RMS

cluster.

Page 42: PowerPoint Presentationdownload.microsoft.com/documents/hk/technet... · SLC to Fabrikam 2) Fabrikam imports SLC 3) John@fabrikam.com sends RM content to Monica@adventure.com 4) Monica@adventure.com

AD RMS Certificates and Licenses

SPC:

Security

Processor

Certificate:

Identifies a

client

machine

Page 43: PowerPoint Presentationdownload.microsoft.com/documents/hk/technet... · SLC to Fabrikam 2) Fabrikam imports SLC 3) John@fabrikam.com sends RM content to Monica@adventure.com 4) Monica@adventure.com

AD RMS Certificates and Licenses

RAC:

Rights

Account

Certificate

Identifies

an AD RMS

user

Page 44: PowerPoint Presentationdownload.microsoft.com/documents/hk/technet... · SLC to Fabrikam 2) Fabrikam imports SLC 3) John@fabrikam.com sends RM content to Monica@adventure.com 4) Monica@adventure.com

AD RMS Certificates and Licenses

CLC:

Client Licensor

Certificate

Identifies an author

in AD RMS

Page 45: PowerPoint Presentationdownload.microsoft.com/documents/hk/technet... · SLC to Fabrikam 2) Fabrikam imports SLC 3) John@fabrikam.com sends RM content to Monica@adventure.com 4) Monica@adventure.com

AD RMS Certificates and Licenses

PL:

Publishing

License

Identifies a

protected

document

and its policy

Page 46: PowerPoint Presentationdownload.microsoft.com/documents/hk/technet... · SLC to Fabrikam 2) Fabrikam imports SLC 3) John@fabrikam.com sends RM content to Monica@adventure.com 4) Monica@adventure.com

AD RMS Certificates and Licenses

PL:

Publishing

License

Identifies a

protected

document

and its policy

Page 47: PowerPoint Presentationdownload.microsoft.com/documents/hk/technet... · SLC to Fabrikam 2) Fabrikam imports SLC 3) John@fabrikam.com sends RM content to Monica@adventure.com 4) Monica@adventure.com

AD RMS Certificates and Licenses

UL:

Use

License

Grants

rights over

a

document

Page 48: PowerPoint Presentationdownload.microsoft.com/documents/hk/technet... · SLC to Fabrikam 2) Fabrikam imports SLC 3) John@fabrikam.com sends RM content to Monica@adventure.com 4) Monica@adventure.com

AD RMS Certificates and Licenses

UL:

Use

License

Grants

rights over

a

document

Page 49: PowerPoint Presentationdownload.microsoft.com/documents/hk/technet... · SLC to Fabrikam 2) Fabrikam imports SLC 3) John@fabrikam.com sends RM content to Monica@adventure.com 4) Monica@adventure.com
Page 50: PowerPoint Presentationdownload.microsoft.com/documents/hk/technet... · SLC to Fabrikam 2) Fabrikam imports SLC 3) John@fabrikam.com sends RM content to Monica@adventure.com 4) Monica@adventure.com

Fabrikam

Page 51: PowerPoint Presentationdownload.microsoft.com/documents/hk/technet... · SLC to Fabrikam 2) Fabrikam imports SLC 3) John@fabrikam.com sends RM content to Monica@adventure.com 4) Monica@adventure.com

Fabrikam Adventure

Page 52: PowerPoint Presentationdownload.microsoft.com/documents/hk/technet... · SLC to Fabrikam 2) Fabrikam imports SLC 3) John@fabrikam.com sends RM content to Monica@adventure.com 4) Monica@adventure.com

Fabrikam Adventure

Page 53: PowerPoint Presentationdownload.microsoft.com/documents/hk/technet... · SLC to Fabrikam 2) Fabrikam imports SLC 3) John@fabrikam.com sends RM content to Monica@adventure.com 4) Monica@adventure.com

Fabrikam Adventure

[email protected]

sends RM content to

[email protected]

Page 54: PowerPoint Presentationdownload.microsoft.com/documents/hk/technet... · SLC to Fabrikam 2) Fabrikam imports SLC 3) John@fabrikam.com sends RM content to Monica@adventure.com 4) Monica@adventure.com

Fabrikam Adventure

[email protected]

sends RM content to

[email protected]

Page 55: PowerPoint Presentationdownload.microsoft.com/documents/hk/technet... · SLC to Fabrikam 2) Fabrikam imports SLC 3) John@fabrikam.com sends RM content to Monica@adventure.com 4) Monica@adventure.com

Fabrikam Adventure

[email protected]

sends RM content to

[email protected]

[email protected] sends

PL and RAC with request for

UL from Fabrikam

Page 56: PowerPoint Presentationdownload.microsoft.com/documents/hk/technet... · SLC to Fabrikam 2) Fabrikam imports SLC 3) John@fabrikam.com sends RM content to Monica@adventure.com 4) Monica@adventure.com

Fabrikam Adventure

[email protected]

sends RM content to

[email protected]

[email protected] sends

PL and RAC with request for

UL from Fabrikam

(FAIL)

Page 57: PowerPoint Presentationdownload.microsoft.com/documents/hk/technet... · SLC to Fabrikam 2) Fabrikam imports SLC 3) John@fabrikam.com sends RM content to Monica@adventure.com 4) Monica@adventure.com
Page 58: PowerPoint Presentationdownload.microsoft.com/documents/hk/technet... · SLC to Fabrikam 2) Fabrikam imports SLC 3) John@fabrikam.com sends RM content to Monica@adventure.com 4) Monica@adventure.com

Fabrikam

Page 59: PowerPoint Presentationdownload.microsoft.com/documents/hk/technet... · SLC to Fabrikam 2) Fabrikam imports SLC 3) John@fabrikam.com sends RM content to Monica@adventure.com 4) Monica@adventure.com

Fabrikam Adventure

Page 60: PowerPoint Presentationdownload.microsoft.com/documents/hk/technet... · SLC to Fabrikam 2) Fabrikam imports SLC 3) John@fabrikam.com sends RM content to Monica@adventure.com 4) Monica@adventure.com

Fabrikam Adventure

1) Adventure sends

SLC to Fabrikam

Page 61: PowerPoint Presentationdownload.microsoft.com/documents/hk/technet... · SLC to Fabrikam 2) Fabrikam imports SLC 3) John@fabrikam.com sends RM content to Monica@adventure.com 4) Monica@adventure.com

Fabrikam Adventure

1) Adventure sends

SLC to Fabrikam

Page 62: PowerPoint Presentationdownload.microsoft.com/documents/hk/technet... · SLC to Fabrikam 2) Fabrikam imports SLC 3) John@fabrikam.com sends RM content to Monica@adventure.com 4) Monica@adventure.com

Fabrikam Adventure

1) Adventure sends

SLC to Fabrikam

Page 63: PowerPoint Presentationdownload.microsoft.com/documents/hk/technet... · SLC to Fabrikam 2) Fabrikam imports SLC 3) John@fabrikam.com sends RM content to Monica@adventure.com 4) Monica@adventure.com

Fabrikam Adventure

1) Adventure sends

SLC to Fabrikam 2) Fabrikam

imports SLC

Page 64: PowerPoint Presentationdownload.microsoft.com/documents/hk/technet... · SLC to Fabrikam 2) Fabrikam imports SLC 3) John@fabrikam.com sends RM content to Monica@adventure.com 4) Monica@adventure.com

Fabrikam Adventure

1) Adventure sends

SLC to Fabrikam 2) Fabrikam

imports SLC

Page 65: PowerPoint Presentationdownload.microsoft.com/documents/hk/technet... · SLC to Fabrikam 2) Fabrikam imports SLC 3) John@fabrikam.com sends RM content to Monica@adventure.com 4) Monica@adventure.com

Fabrikam Adventure

1) Adventure sends

SLC to Fabrikam 2) Fabrikam

imports SLC

3) [email protected]

sends RM content to

[email protected]

Page 66: PowerPoint Presentationdownload.microsoft.com/documents/hk/technet... · SLC to Fabrikam 2) Fabrikam imports SLC 3) John@fabrikam.com sends RM content to Monica@adventure.com 4) Monica@adventure.com

Fabrikam Adventure

1) Adventure sends

SLC to Fabrikam 2) Fabrikam

imports SLC

3) [email protected]

sends RM content to

[email protected]

Page 67: PowerPoint Presentationdownload.microsoft.com/documents/hk/technet... · SLC to Fabrikam 2) Fabrikam imports SLC 3) John@fabrikam.com sends RM content to Monica@adventure.com 4) Monica@adventure.com

Fabrikam Adventure

1) Adventure sends

SLC to Fabrikam 2) Fabrikam

imports SLC

3) [email protected]

sends RM content to

[email protected]

4) [email protected] sends

PL and RAC with request for

UL from Fabrikam

Page 68: PowerPoint Presentationdownload.microsoft.com/documents/hk/technet... · SLC to Fabrikam 2) Fabrikam imports SLC 3) John@fabrikam.com sends RM content to Monica@adventure.com 4) Monica@adventure.com

Fabrikam Adventure

1) Adventure sends

SLC to Fabrikam 2) Fabrikam

imports SLC

3) [email protected]

sends RM content to

[email protected]

4) [email protected] sends

PL and RAC with request for

UL from Fabrikam

5) Server uses imported SLC

to verify Monica’s RAC

and returns UL

Page 69: PowerPoint Presentationdownload.microsoft.com/documents/hk/technet... · SLC to Fabrikam 2) Fabrikam imports SLC 3) John@fabrikam.com sends RM content to Monica@adventure.com 4) Monica@adventure.com

Fabrikam Adventure

1) Adventure sends

SLC to Fabrikam 2) Fabrikam

imports SLC

3) [email protected]

sends RM content to

[email protected]

4) [email protected] sends

PL and RAC with request for

UL from Fabrikam

5) Server uses imported SLC

to verify Monica’s RAC

and returns UL

Page 70: PowerPoint Presentationdownload.microsoft.com/documents/hk/technet... · SLC to Fabrikam 2) Fabrikam imports SLC 3) John@fabrikam.com sends RM content to Monica@adventure.com 4) Monica@adventure.com

Fabrikam Adventure

1) Adventure sends

SLC to Fabrikam 2) Fabrikam

imports SLC

3) [email protected]

sends RM content to

[email protected]

4) [email protected] sends

PL and RAC with request for

UL from Fabrikam

5) Server uses imported SLC

to verify Monica’s RAC

and returns UL

Page 71: PowerPoint Presentationdownload.microsoft.com/documents/hk/technet... · SLC to Fabrikam 2) Fabrikam imports SLC 3) John@fabrikam.com sends RM content to Monica@adventure.com 4) Monica@adventure.com
Page 72: PowerPoint Presentationdownload.microsoft.com/documents/hk/technet... · SLC to Fabrikam 2) Fabrikam imports SLC 3) John@fabrikam.com sends RM content to Monica@adventure.com 4) Monica@adventure.com

Fabrikam

Page 73: PowerPoint Presentationdownload.microsoft.com/documents/hk/technet... · SLC to Fabrikam 2) Fabrikam imports SLC 3) John@fabrikam.com sends RM content to Monica@adventure.com 4) Monica@adventure.com

Fabrikam Adventure

Page 74: PowerPoint Presentationdownload.microsoft.com/documents/hk/technet... · SLC to Fabrikam 2) Fabrikam imports SLC 3) John@fabrikam.com sends RM content to Monica@adventure.com 4) Monica@adventure.com

Fabrikam Adventure

Page 75: PowerPoint Presentationdownload.microsoft.com/documents/hk/technet... · SLC to Fabrikam 2) Fabrikam imports SLC 3) John@fabrikam.com sends RM content to Monica@adventure.com 4) Monica@adventure.com

Fabrikam Adventure

[email protected]

sends ADRMS content to

[email protected]

Page 76: PowerPoint Presentationdownload.microsoft.com/documents/hk/technet... · SLC to Fabrikam 2) Fabrikam imports SLC 3) John@fabrikam.com sends RM content to Monica@adventure.com 4) Monica@adventure.com

Fabrikam Adventure

[email protected]

sends ADRMS content to

[email protected]

Page 77: PowerPoint Presentationdownload.microsoft.com/documents/hk/technet... · SLC to Fabrikam 2) Fabrikam imports SLC 3) John@fabrikam.com sends RM content to Monica@adventure.com 4) Monica@adventure.com

Fabrikam Adventure

[email protected]

sends ADRMS content to

[email protected]

[email protected] sends

PL and RAC with request for

UL from local licensing server

Page 78: PowerPoint Presentationdownload.microsoft.com/documents/hk/technet... · SLC to Fabrikam 2) Fabrikam imports SLC 3) John@fabrikam.com sends RM content to Monica@adventure.com 4) Monica@adventure.com

Fabrikam Adventure

[email protected]

sends ADRMS content to

[email protected]

[email protected] sends

PL and RAC with request for

UL from local licensing server

Page 79: PowerPoint Presentationdownload.microsoft.com/documents/hk/technet... · SLC to Fabrikam 2) Fabrikam imports SLC 3) John@fabrikam.com sends RM content to Monica@adventure.com 4) Monica@adventure.com

Fabrikam Adventure

[email protected]

sends ADRMS content to

[email protected]

[email protected] sends

PL and RAC with request for

UL from local licensing server

(FAIL)

Page 80: PowerPoint Presentationdownload.microsoft.com/documents/hk/technet... · SLC to Fabrikam 2) Fabrikam imports SLC 3) John@fabrikam.com sends RM content to Monica@adventure.com 4) Monica@adventure.com
Page 81: PowerPoint Presentationdownload.microsoft.com/documents/hk/technet... · SLC to Fabrikam 2) Fabrikam imports SLC 3) John@fabrikam.com sends RM content to Monica@adventure.com 4) Monica@adventure.com

Fabrikam

Page 82: PowerPoint Presentationdownload.microsoft.com/documents/hk/technet... · SLC to Fabrikam 2) Fabrikam imports SLC 3) John@fabrikam.com sends RM content to Monica@adventure.com 4) Monica@adventure.com

Fabrikam Adventure

Page 83: PowerPoint Presentationdownload.microsoft.com/documents/hk/technet... · SLC to Fabrikam 2) Fabrikam imports SLC 3) John@fabrikam.com sends RM content to Monica@adventure.com 4) Monica@adventure.com

Fabrikam Adventure 1) Fabrikam

exports

private key

and SLC

Page 84: PowerPoint Presentationdownload.microsoft.com/documents/hk/technet... · SLC to Fabrikam 2) Fabrikam imports SLC 3) John@fabrikam.com sends RM content to Monica@adventure.com 4) Monica@adventure.com

Fabrikam Adventure 1) Fabrikam

exports

private key

and SLC

2) Adventure

imports private

key and SLC

Page 85: PowerPoint Presentationdownload.microsoft.com/documents/hk/technet... · SLC to Fabrikam 2) Fabrikam imports SLC 3) John@fabrikam.com sends RM content to Monica@adventure.com 4) Monica@adventure.com

Fabrikam Adventure 1) Fabrikam

exports

private key

and SLC

2) Adventure

imports private

key and SLC

Page 86: PowerPoint Presentationdownload.microsoft.com/documents/hk/technet... · SLC to Fabrikam 2) Fabrikam imports SLC 3) John@fabrikam.com sends RM content to Monica@adventure.com 4) Monica@adventure.com

Fabrikam Adventure 1) Fabrikam

exports

private key

and SLC

2) Adventure

imports private

key and SLC

Page 87: PowerPoint Presentationdownload.microsoft.com/documents/hk/technet... · SLC to Fabrikam 2) Fabrikam imports SLC 3) John@fabrikam.com sends RM content to Monica@adventure.com 4) Monica@adventure.com

Fabrikam Adventure 1) Fabrikam

exports

private key

and SLC

2) Adventure

imports private

key and SLC

3) [email protected]

sends ADRMS content to

[email protected]

Page 88: PowerPoint Presentationdownload.microsoft.com/documents/hk/technet... · SLC to Fabrikam 2) Fabrikam imports SLC 3) John@fabrikam.com sends RM content to Monica@adventure.com 4) Monica@adventure.com

Fabrikam Adventure 1) Fabrikam

exports

private key

and SLC

2) Adventure

imports private

key and SLC

3) [email protected]

sends ADRMS content to

[email protected]

Page 89: PowerPoint Presentationdownload.microsoft.com/documents/hk/technet... · SLC to Fabrikam 2) Fabrikam imports SLC 3) John@fabrikam.com sends RM content to Monica@adventure.com 4) Monica@adventure.com

Fabrikam Adventure 1) Fabrikam

exports

private key

and SLC

2) Adventure

imports private

key and SLC

3) [email protected]

sends ADRMS content to

[email protected]

4) [email protected] sends

PL and RAC with request for

UL from local licensing server

Page 90: PowerPoint Presentationdownload.microsoft.com/documents/hk/technet... · SLC to Fabrikam 2) Fabrikam imports SLC 3) John@fabrikam.com sends RM content to Monica@adventure.com 4) Monica@adventure.com

Fabrikam Adventure 1) Fabrikam

exports

private key

and SLC

2) Adventure

imports private

key and SLC

3) [email protected]

sends ADRMS content to

[email protected]

4) [email protected] sends

PL and RAC with request for

UL from local licensing server

Page 91: PowerPoint Presentationdownload.microsoft.com/documents/hk/technet... · SLC to Fabrikam 2) Fabrikam imports SLC 3) John@fabrikam.com sends RM content to Monica@adventure.com 4) Monica@adventure.com

Fabrikam Adventure 1) Fabrikam

exports

private key

and SLC

2) Adventure

imports private

key and SLC

3) [email protected]

sends ADRMS content to

[email protected]

4) [email protected] sends

PL and RAC with request for

UL from local licensing server

5) Adventure uses imported

private key to decrypt PL

and issues UL

Page 92: PowerPoint Presentationdownload.microsoft.com/documents/hk/technet... · SLC to Fabrikam 2) Fabrikam imports SLC 3) John@fabrikam.com sends RM content to Monica@adventure.com 4) Monica@adventure.com

Fabrikam Adventure 1) Fabrikam

exports

private key

and SLC

2) Adventure

imports private

key and SLC

3) [email protected]

sends ADRMS content to

[email protected]

4) [email protected] sends

PL and RAC with request for

UL from local licensing server

5) Adventure uses imported

private key to decrypt PL

and issues UL

Page 93: PowerPoint Presentationdownload.microsoft.com/documents/hk/technet... · SLC to Fabrikam 2) Fabrikam imports SLC 3) John@fabrikam.com sends RM content to Monica@adventure.com 4) Monica@adventure.com

Fabrikam Adventure 1) Fabrikam

exports

private key

and SLC

2) Adventure

imports private

key and SLC

3) [email protected]

sends ADRMS content to

[email protected]

4) [email protected] sends

PL and RAC with request for

UL from local licensing server

5) Adventure uses imported

private key to decrypt PL

and issues UL

Page 94: PowerPoint Presentationdownload.microsoft.com/documents/hk/technet... · SLC to Fabrikam 2) Fabrikam imports SLC 3) John@fabrikam.com sends RM content to Monica@adventure.com 4) Monica@adventure.com
Page 95: PowerPoint Presentationdownload.microsoft.com/documents/hk/technet... · SLC to Fabrikam 2) Fabrikam imports SLC 3) John@fabrikam.com sends RM content to Monica@adventure.com 4) Monica@adventure.com

Fabrikam Adventure

AD RMS

FS-A FS-R

ISA

Page 96: PowerPoint Presentationdownload.microsoft.com/documents/hk/technet... · SLC to Fabrikam 2) Fabrikam imports SLC 3) John@fabrikam.com sends RM content to Monica@adventure.com 4) Monica@adventure.com

Fabrikam Adventure

AD RMS

FS-A FS-R

ISA

1. Assume author is already bootstrapped

Page 97: PowerPoint Presentationdownload.microsoft.com/documents/hk/technet... · SLC to Fabrikam 2) Fabrikam imports SLC 3) John@fabrikam.com sends RM content to Monica@adventure.com 4) Monica@adventure.com

Fabrikam Adventure

AD RMS

FS-A FS-R

ISA

1. Assume author is already bootstrapped

2. Author sends protected email to recipient at Adventure

PL

2

Page 98: PowerPoint Presentationdownload.microsoft.com/documents/hk/technet... · SLC to Fabrikam 2) Fabrikam imports SLC 3) John@fabrikam.com sends RM content to Monica@adventure.com 4) Monica@adventure.com

Fabrikam Adventure

AD RMS

FS-A FS-R

ISA

1. Assume author is already bootstrapped

2. Author sends protected email to recipient at Adventure

3. Recipient contacts published Fabrikam AD RMS server to get bootstrapped

PL

2

3

Page 99: PowerPoint Presentationdownload.microsoft.com/documents/hk/technet... · SLC to Fabrikam 2) Fabrikam imports SLC 3) John@fabrikam.com sends RM content to Monica@adventure.com 4) Monica@adventure.com

Fabrikam Adventure

AD RMS

FS-A FS-R

ISA

1. Assume author is already bootstrapped

2. Author sends protected email to recipient at Adventure

3. Recipient contacts published Fabrikam AD RMS server to get bootstrapped

4. WebSSO agent intercepts request

PL

2

3

4

Page 100: PowerPoint Presentationdownload.microsoft.com/documents/hk/technet... · SLC to Fabrikam 2) Fabrikam imports SLC 3) John@fabrikam.com sends RM content to Monica@adventure.com 4) Monica@adventure.com

Fabrikam Adventure

AD RMS

FS-A FS-R

ISA

1. Assume author is already bootstrapped

2. Author sends protected email to recipient at Adventure

3. Recipient contacts published Fabrikam AD RMS server to get bootstrapped

4. WebSSO agent intercepts request

PL

2

3

4

Page 101: PowerPoint Presentationdownload.microsoft.com/documents/hk/technet... · SLC to Fabrikam 2) Fabrikam imports SLC 3) John@fabrikam.com sends RM content to Monica@adventure.com 4) Monica@adventure.com

Fabrikam Adventure

AD RMS

FS-A FS-R

ISA

1. Assume author is already bootstrapped

2. Author sends protected email to recipient at Adventure

3. Recipient contacts published Fabrikam AD RMS server to get bootstrapped

4. WebSSO agent intercepts request

5. AD RMS client is redirected to Federation Server (FS)-R for home realm discovery through ISA Server

PL

2

3

4

5

Page 102: PowerPoint Presentationdownload.microsoft.com/documents/hk/technet... · SLC to Fabrikam 2) Fabrikam imports SLC 3) John@fabrikam.com sends RM content to Monica@adventure.com 4) Monica@adventure.com

Fabrikam Adventure

AD RMS

FS-A FS-R

ISA

1. Assume author is already bootstrapped

2. Author sends protected email to recipient at Adventure

3. Recipient contacts published Fabrikam AD RMS server to get bootstrapped

4. WebSSO agent intercepts request

5. AD RMS client is redirected to Federation Server (FS)-R for home realm discovery through ISA Server

6. AD RMS client is redirected to FS-A for authentication

PL

2

3

4

5

6

Page 103: PowerPoint Presentationdownload.microsoft.com/documents/hk/technet... · SLC to Fabrikam 2) Fabrikam imports SLC 3) John@fabrikam.com sends RM content to Monica@adventure.com 4) Monica@adventure.com

Fabrikam Adventure

AD RMS

FS-A FS-R

ISA

1. Assume author is already bootstrapped

2. Author sends protected email to recipient at Adventure

3. Recipient contacts published Fabrikam AD RMS server to get bootstrapped

4. WebSSO agent intercepts request

5. AD RMS client is redirected to Federation Server (FS)-R for home realm discovery through ISA Server

6. AD RMS client is redirected to FS-A for authentication

7. AD RMS client is redirected back to FS-R for authentication

PL

2

3

4

5

6

7

Page 104: PowerPoint Presentationdownload.microsoft.com/documents/hk/technet... · SLC to Fabrikam 2) Fabrikam imports SLC 3) John@fabrikam.com sends RM content to Monica@adventure.com 4) Monica@adventure.com

Fabrikam Adventure

AD RMS

FS-A FS-R

ISA

1. Assume author is already bootstrapped

2. Author sends protected email to recipient at Adventure

3. Recipient contacts published Fabrikam AD RMS server to get bootstrapped

4. WebSSO agent intercepts request

5. AD RMS client is redirected to Federation Server (FS)-R for home realm discovery through ISA Server

6. AD RMS client is redirected to FS-A for authentication

7. AD RMS client is redirected back to FS-R for authentication

8. AD RMS client makes request to AD RMS server for bootstrapping

PL

2

3

4

5

6

7

8

Page 105: PowerPoint Presentationdownload.microsoft.com/documents/hk/technet... · SLC to Fabrikam 2) Fabrikam imports SLC 3) John@fabrikam.com sends RM content to Monica@adventure.com 4) Monica@adventure.com

Fabrikam Adventure

AD RMS

FS-A FS-R

ISA

1. Assume author is already bootstrapped

2. Author sends protected email to recipient at Adventure

3. Recipient contacts published Fabrikam AD RMS server to get bootstrapped

4. WebSSO agent intercepts request

5. AD RMS client is redirected to Federation Server (FS)-R for home realm discovery through ISA Server

6. AD RMS client is redirected to FS-A for authentication

7. AD RMS client is redirected back to FS-R for authentication

8. AD RMS client makes request to AD RMS server for bootstrapping

9. WebSSO agent intercepts request, checks authentication, and sends request to AD RMS server

PL

2

3

4

5

6

7

8

9

Page 106: PowerPoint Presentationdownload.microsoft.com/documents/hk/technet... · SLC to Fabrikam 2) Fabrikam imports SLC 3) John@fabrikam.com sends RM content to Monica@adventure.com 4) Monica@adventure.com

Fabrikam Adventure

AD RMS

FS-A FS-R

ISA

1. Assume author is already bootstrapped

2. Author sends protected email to recipient at Adventure

3. Recipient contacts published Fabrikam AD RMS server to get bootstrapped

4. WebSSO agent intercepts request

5. AD RMS client is redirected to Federation Server (FS)-R for home realm discovery through ISA Server

6. AD RMS client is redirected to FS-A for authentication

7. AD RMS client is redirected back to FS-R for authentication

8. AD RMS client makes request to AD RMS server for bootstrapping

9. WebSSO agent intercepts request, checks authentication, and sends request to AD RMS server

10. AD RMS server returns bootstrapping certificates to recipient

PL

2

3

4

5

6

7

8

9

RAC CLC

10

Page 107: PowerPoint Presentationdownload.microsoft.com/documents/hk/technet... · SLC to Fabrikam 2) Fabrikam imports SLC 3) John@fabrikam.com sends RM content to Monica@adventure.com 4) Monica@adventure.com

Fabrikam Adventure

AD RMS

FS-A FS-R

ISA

1. Assume author is already bootstrapped

2. Author sends protected email to recipient at Adventure

3. Recipient contacts published Fabrikam AD RMS server to get bootstrapped

4. WebSSO agent intercepts request

5. AD RMS client is redirected to Federation Server (FS)-R for home realm discovery through ISA Server

6. AD RMS client is redirected to FS-A for authentication

7. AD RMS client is redirected back to FS-R for authentication

8. AD RMS client makes request to AD RMS server for bootstrapping

9. WebSSO agent intercepts request, checks authentication, and sends request to AD RMS server

10. AD RMS server returns bootstrapping certificates to recipient

11. AD RMS server returns use license to recipient

PL

2

3

4

5

6

7

8

9

RAC CLC

10

UL 11

Page 108: PowerPoint Presentationdownload.microsoft.com/documents/hk/technet... · SLC to Fabrikam 2) Fabrikam imports SLC 3) John@fabrikam.com sends RM content to Monica@adventure.com 4) Monica@adventure.com

Fabrikam Adventure

AD RMS

FS-A FS-R

ISA

1. Assume author is already bootstrapped

2. Author sends protected email to recipient at Adventure

3. Recipient contacts published Fabrikam AD RMS server to get bootstrapped

4. WebSSO agent intercepts request

5. AD RMS client is redirected to Federation Server (FS)-R for home realm discovery through ISA Server

6. AD RMS client is redirected to FS-A for authentication

7. AD RMS client is redirected back to FS-R for authentication

8. AD RMS client makes request to AD RMS server for bootstrapping

9. WebSSO agent intercepts request, checks authentication, and sends request to AD RMS server

10. AD RMS server returns bootstrapping certificates to recipient

11. AD RMS server returns use license to recipient

12. Recipient accesses protected content

PL

2

3

4

5

6

7

8

9

RAC CLC

10

UL 11

12

Page 109: PowerPoint Presentationdownload.microsoft.com/documents/hk/technet... · SLC to Fabrikam 2) Fabrikam imports SLC 3) John@fabrikam.com sends RM content to Monica@adventure.com 4) Monica@adventure.com
Page 110: PowerPoint Presentationdownload.microsoft.com/documents/hk/technet... · SLC to Fabrikam 2) Fabrikam imports SLC 3) John@fabrikam.com sends RM content to Monica@adventure.com 4) Monica@adventure.com
Page 111: PowerPoint Presentationdownload.microsoft.com/documents/hk/technet... · SLC to Fabrikam 2) Fabrikam imports SLC 3) John@fabrikam.com sends RM content to Monica@adventure.com 4) Monica@adventure.com

Cross-Forest Group Expansion

Another forest (contosocorp.com)User’s Domain (contosobranch.com)

DC DC

Outlook or other

client

AD RMSAD RMS

SCP:

ADRMS.contosobranch.com

Page 112: PowerPoint Presentationdownload.microsoft.com/documents/hk/technet... · SLC to Fabrikam 2) Fabrikam imports SLC 3) John@fabrikam.com sends RM content to Monica@adventure.com 4) Monica@adventure.com

Cross-Forest Group Expansion

Another forest (contosocorp.com)User’s Domain (contosobranch.com)

DC DC

Outlook or other

client

AD RMSAD RMS

SCP:

ADRMS.contosobranch.com

Hi, I’m John. Can I get a

license for this

document?

Page 113: PowerPoint Presentationdownload.microsoft.com/documents/hk/technet... · SLC to Fabrikam 2) Fabrikam imports SLC 3) John@fabrikam.com sends RM content to Monica@adventure.com 4) Monica@adventure.com

Cross-Forest Group Expansion

Another forest (contosocorp.com)User’s Domain (contosobranch.com)

DC DC

Outlook or other

client

AD RMSAD RMS

SCP:

ADRMS.contosobranch.com

Content is protected for

[email protected],

who’s that?

Page 114: PowerPoint Presentationdownload.microsoft.com/documents/hk/technet... · SLC to Fabrikam 2) Fabrikam imports SLC 3) John@fabrikam.com sends RM content to Monica@adventure.com 4) Monica@adventure.com

Cross-Forest Group Expansion

Another forest (contosocorp.com)User’s Domain (contosobranch.com)

DC DC

Outlook or other

client

AD RMSAD RMS

SCP:

ADRMS.contosobranch.com

I have a contact for

[email protected],

and it points to domain

contosobranch.com (duh!)

Page 115: PowerPoint Presentationdownload.microsoft.com/documents/hk/technet... · SLC to Fabrikam 2) Fabrikam imports SLC 3) John@fabrikam.com sends RM content to Monica@adventure.com 4) Monica@adventure.com

Cross-Forest Group Expansion

Another forest (contosocorp.com)User’s Domain (contosobranch.com)

DC DC

Outlook or other

client

AD RMSAD RMS

SCP:

ADRMS.contosobranch.com

Hey, what’s your RMS

SCP?

Page 116: PowerPoint Presentationdownload.microsoft.com/documents/hk/technet... · SLC to Fabrikam 2) Fabrikam imports SLC 3) John@fabrikam.com sends RM content to Monica@adventure.com 4) Monica@adventure.com

Cross-Forest Group Expansion

Another forest (contosocorp.com)User’s Domain (contosobranch.com)

DC DC

Outlook or other

client

AD RMSAD RMS

SCP:

ADRMS.contosobranch.com

It’s adrms.contosobranch.com

Page 117: PowerPoint Presentationdownload.microsoft.com/documents/hk/technet... · SLC to Fabrikam 2) Fabrikam imports SLC 3) John@fabrikam.com sends RM content to Monica@adventure.com 4) Monica@adventure.com

Cross-Forest Group Expansion

Another forest (contosocorp.com)User’s Domain (contosobranch.com)

DC DC

Outlook or other

client

AD RMSAD RMS

SCP:

ADRMS.contosobranch.com

Hey,

adrms.contosobranch.com/.../

groupexpansion.asmx, is John a

member of the marketing group?

Page 118: PowerPoint Presentationdownload.microsoft.com/documents/hk/technet... · SLC to Fabrikam 2) Fabrikam imports SLC 3) John@fabrikam.com sends RM content to Monica@adventure.com 4) Monica@adventure.com

Cross-Forest Group Expansion

Another forest (contosocorp.com)User’s Domain (contosobranch.com)

DC DC

Outlook or other

client

AD RMSAD RMS

SCP:

ADRMS.contosobranch.com

Give me

Marketing

group’s

members

Page 119: PowerPoint Presentationdownload.microsoft.com/documents/hk/technet... · SLC to Fabrikam 2) Fabrikam imports SLC 3) John@fabrikam.com sends RM content to Monica@adventure.com 4) Monica@adventure.com

Cross-Forest Group Expansion

Another forest (contosocorp.com)User’s Domain (contosobranch.com)

DC DC

Outlook or other

client

AD RMSAD RMS

SCP:

ADRMS.contosobranch.com

It’s John,

Peter and

Susan

Page 120: PowerPoint Presentationdownload.microsoft.com/documents/hk/technet... · SLC to Fabrikam 2) Fabrikam imports SLC 3) John@fabrikam.com sends RM content to Monica@adventure.com 4) Monica@adventure.com

Cross-Forest Group Expansion

Another forest (contosocorp.com)User’s Domain (contosobranch.com)

DC DC

Outlook or other

client

AD RMSAD RMS

SCP:

ADRMS.contosobranch.com

He is, indeed.

Page 121: PowerPoint Presentationdownload.microsoft.com/documents/hk/technet... · SLC to Fabrikam 2) Fabrikam imports SLC 3) John@fabrikam.com sends RM content to Monica@adventure.com 4) Monica@adventure.com

Cross-Forest Group Expansion

Another forest (contosocorp.com)User’s Domain (contosobranch.com)

DC DC

Outlook or other

client

AD RMSAD RMS

SCP:

ADRMS.contosobranch.com

Here’s your license!

Page 122: PowerPoint Presentationdownload.microsoft.com/documents/hk/technet... · SLC to Fabrikam 2) Fabrikam imports SLC 3) John@fabrikam.com sends RM content to Monica@adventure.com 4) Monica@adventure.com

Cross-Forest Group Expansion

Another forest (contosocorp.com)User’s Domain (contosobranch.com)

DC DC

Outlook or other

client

AD RMSAD RMS

SCP:

ADRMS.contosobranch.com

Page 123: PowerPoint Presentationdownload.microsoft.com/documents/hk/technet... · SLC to Fabrikam 2) Fabrikam imports SLC 3) John@fabrikam.com sends RM content to Monica@adventure.com 4) Monica@adventure.com
Page 124: PowerPoint Presentationdownload.microsoft.com/documents/hk/technet... · SLC to Fabrikam 2) Fabrikam imports SLC 3) John@fabrikam.com sends RM content to Monica@adventure.com 4) Monica@adventure.com
Page 125: PowerPoint Presentationdownload.microsoft.com/documents/hk/technet... · SLC to Fabrikam 2) Fabrikam imports SLC 3) John@fabrikam.com sends RM content to Monica@adventure.com 4) Monica@adventure.com
Page 126: PowerPoint Presentationdownload.microsoft.com/documents/hk/technet... · SLC to Fabrikam 2) Fabrikam imports SLC 3) John@fabrikam.com sends RM content to Monica@adventure.com 4) Monica@adventure.com
Page 127: PowerPoint Presentationdownload.microsoft.com/documents/hk/technet... · SLC to Fabrikam 2) Fabrikam imports SLC 3) John@fabrikam.com sends RM content to Monica@adventure.com 4) Monica@adventure.com

Certification ClusterSQL Server (Cluster)

Multi Region

ForestCore forest

Other

forests

TUD

Certification

Licensing

Page 128: PowerPoint Presentationdownload.microsoft.com/documents/hk/technet... · SLC to Fabrikam 2) Fabrikam imports SLC 3) John@fabrikam.com sends RM content to Monica@adventure.com 4) Monica@adventure.com

Certification ClusterSQL Server (Cluster)

Multi Region

ForestCore forest

Other

forests

TUD

Certification

Licensing

Page 129: PowerPoint Presentationdownload.microsoft.com/documents/hk/technet... · SLC to Fabrikam 2) Fabrikam imports SLC 3) John@fabrikam.com sends RM content to Monica@adventure.com 4) Monica@adventure.com

Certification ClusterSQL Server (Cluster)

Multi Region

ForestCore forest

Other

forests

TUD

Certification

Licensing

Page 130: PowerPoint Presentationdownload.microsoft.com/documents/hk/technet... · SLC to Fabrikam 2) Fabrikam imports SLC 3) John@fabrikam.com sends RM content to Monica@adventure.com 4) Monica@adventure.com

Certification ClusterSQL Server (Cluster)

Multi Region

ForestCore forest

Other

forests

TUD

Certification

Licensing

Page 131: PowerPoint Presentationdownload.microsoft.com/documents/hk/technet... · SLC to Fabrikam 2) Fabrikam imports SLC 3) John@fabrikam.com sends RM content to Monica@adventure.com 4) Monica@adventure.com
Page 132: PowerPoint Presentationdownload.microsoft.com/documents/hk/technet... · SLC to Fabrikam 2) Fabrikam imports SLC 3) John@fabrikam.com sends RM content to Monica@adventure.com 4) Monica@adventure.com
Page 133: PowerPoint Presentationdownload.microsoft.com/documents/hk/technet... · SLC to Fabrikam 2) Fabrikam imports SLC 3) John@fabrikam.com sends RM content to Monica@adventure.com 4) Monica@adventure.com
Page 134: PowerPoint Presentationdownload.microsoft.com/documents/hk/technet... · SLC to Fabrikam 2) Fabrikam imports SLC 3) John@fabrikam.com sends RM content to Monica@adventure.com 4) Monica@adventure.com
Page 135: PowerPoint Presentationdownload.microsoft.com/documents/hk/technet... · SLC to Fabrikam 2) Fabrikam imports SLC 3) John@fabrikam.com sends RM content to Monica@adventure.com 4) Monica@adventure.com

Certification ClusterSQL Server (Cluster)

Multi Region

ForestCore forest

Other

forests

TUD

Certification

Licensing

Licensing-only Cluster

Page 136: PowerPoint Presentationdownload.microsoft.com/documents/hk/technet... · SLC to Fabrikam 2) Fabrikam imports SLC 3) John@fabrikam.com sends RM content to Monica@adventure.com 4) Monica@adventure.com

Certification ClusterSQL Server (Cluster)

Multi Region

ForestCore forest

Other

forests

TUD

Certification

Licensing

Licensing-only Cluster

Page 137: PowerPoint Presentationdownload.microsoft.com/documents/hk/technet... · SLC to Fabrikam 2) Fabrikam imports SLC 3) John@fabrikam.com sends RM content to Monica@adventure.com 4) Monica@adventure.com

Certification ClusterSQL Server (Cluster)

Multi Region

ForestCore forest

Other

forests

TUD

Certification

Licensing

Page 138: PowerPoint Presentationdownload.microsoft.com/documents/hk/technet... · SLC to Fabrikam 2) Fabrikam imports SLC 3) John@fabrikam.com sends RM content to Monica@adventure.com 4) Monica@adventure.com
Page 139: PowerPoint Presentationdownload.microsoft.com/documents/hk/technet... · SLC to Fabrikam 2) Fabrikam imports SLC 3) John@fabrikam.com sends RM content to Monica@adventure.com 4) Monica@adventure.com
Page 140: PowerPoint Presentationdownload.microsoft.com/documents/hk/technet... · SLC to Fabrikam 2) Fabrikam imports SLC 3) John@fabrikam.com sends RM content to Monica@adventure.com 4) Monica@adventure.com
Page 141: PowerPoint Presentationdownload.microsoft.com/documents/hk/technet... · SLC to Fabrikam 2) Fabrikam imports SLC 3) John@fabrikam.com sends RM content to Monica@adventure.com 4) Monica@adventure.com

Certification ClusterSQL Server (Cluster)

Multi Region

ForestCore forest

Other

forests

TUD

Certification

Licensing

Licensing-only Cluster

Users in

isolated

sub-org.

Page 142: PowerPoint Presentationdownload.microsoft.com/documents/hk/technet... · SLC to Fabrikam 2) Fabrikam imports SLC 3) John@fabrikam.com sends RM content to Monica@adventure.com 4) Monica@adventure.com

Certification ClusterSQL Server (Cluster)

Multi Region

ForestCore forest

Other

forests

TUD

Certification

Licensing

Licensing-only Cluster

Users in

isolated

sub-org.

Page 143: PowerPoint Presentationdownload.microsoft.com/documents/hk/technet... · SLC to Fabrikam 2) Fabrikam imports SLC 3) John@fabrikam.com sends RM content to Monica@adventure.com 4) Monica@adventure.com

Certification ClusterSQL Server (Cluster)

Multi Region

ForestCore forest

Other

forests

TUD

Certification

Licensing

Licensing-only Cluster

Users in

isolated

sub-org.

Page 144: PowerPoint Presentationdownload.microsoft.com/documents/hk/technet... · SLC to Fabrikam 2) Fabrikam imports SLC 3) John@fabrikam.com sends RM content to Monica@adventure.com 4) Monica@adventure.com

Certification ClusterSQL Server (Cluster)

Multi Region

ForestCore forest

Other

forests

TUD

Certification

Licensing

Users in

isolated

sub-org.

Licensing-Only Cluster

Page 145: PowerPoint Presentationdownload.microsoft.com/documents/hk/technet... · SLC to Fabrikam 2) Fabrikam imports SLC 3) John@fabrikam.com sends RM content to Monica@adventure.com 4) Monica@adventure.com
Page 146: PowerPoint Presentationdownload.microsoft.com/documents/hk/technet... · SLC to Fabrikam 2) Fabrikam imports SLC 3) John@fabrikam.com sends RM content to Monica@adventure.com 4) Monica@adventure.com
Page 147: PowerPoint Presentationdownload.microsoft.com/documents/hk/technet... · SLC to Fabrikam 2) Fabrikam imports SLC 3) John@fabrikam.com sends RM content to Monica@adventure.com 4) Monica@adventure.com

Certification ClusterSQL Server (Cluster)

Multi Region

ForestCore forest

Other

forests

TUD

Certification

Licensing

Licensing-only Cluster

Users in

isolated

sub-org.

Page 148: PowerPoint Presentationdownload.microsoft.com/documents/hk/technet... · SLC to Fabrikam 2) Fabrikam imports SLC 3) John@fabrikam.com sends RM content to Monica@adventure.com 4) Monica@adventure.com

Certification ClusterSQL Server (Cluster)

Multi Region

ForestCore forest

Other

forests

TUD

Certification

Licensing

Licensing-only Cluster

Users in

isolated

sub-org.

TPD

Page 149: PowerPoint Presentationdownload.microsoft.com/documents/hk/technet... · SLC to Fabrikam 2) Fabrikam imports SLC 3) John@fabrikam.com sends RM content to Monica@adventure.com 4) Monica@adventure.com
Page 150: PowerPoint Presentationdownload.microsoft.com/documents/hk/technet... · SLC to Fabrikam 2) Fabrikam imports SLC 3) John@fabrikam.com sends RM content to Monica@adventure.com 4) Monica@adventure.com
Page 151: PowerPoint Presentationdownload.microsoft.com/documents/hk/technet... · SLC to Fabrikam 2) Fabrikam imports SLC 3) John@fabrikam.com sends RM content to Monica@adventure.com 4) Monica@adventure.com
Page 152: PowerPoint Presentationdownload.microsoft.com/documents/hk/technet... · SLC to Fabrikam 2) Fabrikam imports SLC 3) John@fabrikam.com sends RM content to Monica@adventure.com 4) Monica@adventure.com
Page 153: PowerPoint Presentationdownload.microsoft.com/documents/hk/technet... · SLC to Fabrikam 2) Fabrikam imports SLC 3) John@fabrikam.com sends RM content to Monica@adventure.com 4) Monica@adventure.com
Page 154: PowerPoint Presentationdownload.microsoft.com/documents/hk/technet... · SLC to Fabrikam 2) Fabrikam imports SLC 3) John@fabrikam.com sends RM content to Monica@adventure.com 4) Monica@adventure.com

Certification ClusterSQL Server (Cluster)

Multi Region

ForestCore forest

Other

forests

Users in

isolated

sub-org.

TUD

Certification

Licensing

External

Organization or

Isolated forest

(with TUD)

Licensing-Only Cluster

External

Organization

(with AD FS)

AD FS trust

Page 155: PowerPoint Presentationdownload.microsoft.com/documents/hk/technet... · SLC to Fabrikam 2) Fabrikam imports SLC 3) John@fabrikam.com sends RM content to Monica@adventure.com 4) Monica@adventure.com

Certification ClusterSQL Server (Cluster)

Multi Region

ForestCore forest

Other

forests

Users in

isolated

sub-org.

TUD

Certification

Licensing

External

Organization or

Isolated forest

(with TUD)

Licensing-Only Cluster

External

Organization

(with AD FS)

AD FS trust

Page 156: PowerPoint Presentationdownload.microsoft.com/documents/hk/technet... · SLC to Fabrikam 2) Fabrikam imports SLC 3) John@fabrikam.com sends RM content to Monica@adventure.com 4) Monica@adventure.com

Certification ClusterSQL Server (Cluster)

Multi Region

ForestCore forest

Other

forests

Users in

isolated

sub-org.

TUD

Certification

Licensing

External

Organization or

Isolated forest

(with TUD)

Licensing-Only Cluster

External

Organization

(with AD FS)

AD FS trust

Page 157: PowerPoint Presentationdownload.microsoft.com/documents/hk/technet... · SLC to Fabrikam 2) Fabrikam imports SLC 3) John@fabrikam.com sends RM content to Monica@adventure.com 4) Monica@adventure.com
Page 158: PowerPoint Presentationdownload.microsoft.com/documents/hk/technet... · SLC to Fabrikam 2) Fabrikam imports SLC 3) John@fabrikam.com sends RM content to Monica@adventure.com 4) Monica@adventure.com
Page 159: PowerPoint Presentationdownload.microsoft.com/documents/hk/technet... · SLC to Fabrikam 2) Fabrikam imports SLC 3) John@fabrikam.com sends RM content to Monica@adventure.com 4) Monica@adventure.com

Mobile

internal user

Home user

Customer

Internet

Inside

Firewall

Internal users

Outside FirewallHTTP 80/tcp

HTTPS 443/tcp

HTTP 80/tcp

Kerberos 88/tcp, 88/udp

NTP 123/tcp

DCE RPC 135/tcp

NetBIOS 137 – 139 tcp and udp

LDAP 389/tcp

HTTPS 443/tcp

SMB 445/tcp

LDAP GC 3268/tcp

Dynamic DCE RPC ports

Domain Controller and

Global Catalog

AD RMS

ServerSQL Server

Page 160: PowerPoint Presentationdownload.microsoft.com/documents/hk/technet... · SLC to Fabrikam 2) Fabrikam imports SLC 3) John@fabrikam.com sends RM content to Monica@adventure.com 4) Monica@adventure.com

Mobile

Internal User

Home user

Customer

Internet

Internal

Firewall

Internal users

External FirewallHTTP 80/tcp

HTTPS 443/tcp

HTTP 80/tcp

Kerberos 88/tcp, 88/udp

NTP 123/tcp

DCE RPC 135/tcp

NetBIOS 137 – 139 tcp and udp

LDAP 389/tcp

HTTPS 443/tcp

SMB 445/tcp

LDAP GC 3268/tcp

Dynamic DCE RPC ports

Domain Controller and

Global Catalog

AD RMS

Licensing

Server

SQL Server

AD RMS

Certification

Server

SQL Server

Page 161: PowerPoint Presentationdownload.microsoft.com/documents/hk/technet... · SLC to Fabrikam 2) Fabrikam imports SLC 3) John@fabrikam.com sends RM content to Monica@adventure.com 4) Monica@adventure.com

Mobile

internal user

Home user

Customer

Internet

Internal users

FirewallHTTP 80/tcp

HTTPS 443/tcp

AD RMS

Server

SQL Server

Domain Controller and

Global Catalog

Page 162: PowerPoint Presentationdownload.microsoft.com/documents/hk/technet... · SLC to Fabrikam 2) Fabrikam imports SLC 3) John@fabrikam.com sends RM content to Monica@adventure.com 4) Monica@adventure.com
Page 163: PowerPoint Presentationdownload.microsoft.com/documents/hk/technet... · SLC to Fabrikam 2) Fabrikam imports SLC 3) John@fabrikam.com sends RM content to Monica@adventure.com 4) Monica@adventure.com
Page 164: PowerPoint Presentationdownload.microsoft.com/documents/hk/technet... · SLC to Fabrikam 2) Fabrikam imports SLC 3) John@fabrikam.com sends RM content to Monica@adventure.com 4) Monica@adventure.com