Skip to content

Tristan Watkins on IT Infrastructure

Technical guidance for Microsoft security technologies, Windows, SharePoint, and other generally useful findings

Tag: Global Catalogue

RMS AD Caching for SharePoint 2010 Users

As this series of posts about SharePoint 2010 with Rights Management moves on, it moves further from SharePoint. In this post I’m describing the final steps in the RMS protection process, where RMS authenticates the requesting user and authorises actions with RMS-protected content.

In most configurations, RMS will rely on its internal AD Cache to reduce the number of LDAP queries for user attributes or Active Directory group membership. RMS typically queries this cache when users request a license. If RMS finds a matching e-mail address for a user, the allowed rights will be granted in a Use License, which will persist inside a document or on a user’s machine until the rights expire. LDAP queries are only issued if cached values don’t exist or if they have expired. After an LDAP query is issued, the response is used to process the immediate request and the values are stored in the AD Cache for later use.

Although this caching process should “just work” initially, there are a number of tiers where user information can fall out of sync. First and foremost, does the signed-on user have an e-mail address in Active Directory that matches the SharePoint User Information List? What happens if this e-mail address changes, or if it didn’t match initially? How can we invalidate stale AD Cache values? How long does the AD Cache persist? What’s in it? What needs to be considered when turning it off? In many cases the default AD Cache values will be suitable, but operational processes should be orchestrated with AD Cache settings in mind, whatever they may be. Cache invalidation processes should also be understood before they need to be invoked. I will explore these considerations in more detail here.

Continue reading “RMS AD Caching for SharePoint 2010 Users”

Author Tristan WatkinsPosted on May 20, 2013May 20, 2013Categories Authentication, Performance, Security, SharePoint, WindowsTags Active Directory, Cache, Global Catalogue, Information Rights Management, IRM, LDAP, RMS, SharePoint 2010, User Information, User Profile2 Comments on RMS AD Caching for SharePoint 2010 Users

Inspecting an AD RMS Request from SharePoint 2010

In this series of posts on SharePoint with RMS, I’ve mostly focused on the ways things might go wrong if Active Directory data, User Profiles and User Information Lists are misaligned. Now, assuming SharePoint has a reliable Work E-mail value for a user, there are still a number of things that happen between the initiation of a request for RMS-protected content and interaction with it. In this post I will inspect a successful request for RMS-protected content from SharePoint 2010.

Continue reading “Inspecting an AD RMS Request from SharePoint 2010”

Author Tristan WatkinsPosted on February 5, 2013May 20, 2013Categories Authentication, Security, SharePoint, WindowsTags Active Directory, Cache, Global Catalogue, Information Rights Management, IRM, LDAP, RMS, SharePoint 2010, User Information, User ProfileLeave a comment on Inspecting an AD RMS Request from SharePoint 2010

How SharePoint 2010 Authentication Provider Types Alter the Initial Population of Work E-mail Address Values

Continuing this series about the SharePoint 2010 IRM implementation, in this post I’ll keep looking at the Work E-mail Address attribute in the User Information List, but focus specifically on how the initial value in that field gets populated from different sources for different Authentication Provider Types. As with the fuller picture considered in the last post, this is a lot more complicated than anyone would expect at a glance, but it’s really the lynchpin of this functionality – thus the depth here.

Continue reading “How SharePoint 2010 Authentication Provider Types Alter the Initial Population of Work E-mail Address Values”

Author Tristan WatkinsPosted on January 29, 2013May 20, 2013Categories Authentication, Security, SharePoint, WindowsTags Active Directory, Claims, Global Catalogue, Information Rights Management, IRM, LDAP, RMS, SAML, SharePoint 2010, Trusted Identity Provider, User Information, User ProfileLeave a comment on How SharePoint 2010 Authentication Provider Types Alter the Initial Population of Work E-mail Address Values

On Twitter

My Tweets

Recent Comments

  • ADFS 2.0 time out and relation between Freshness Value,TokenLifetime and WebSSOLifetime parameters on Office 365 Single Sign Out with ISA or TMG as the ADFS Proxy
  • Reduslim prezzo in farmacia on DCOM Security for SharePoint Administrators
  • Ye Zejun on No Lossless Audio With Zune
  • Tristan Watkins on Start using Claims X-Ray with Azure AD
  • Robin on Start using Claims X-Ray with Azure AD

Categories

  • Administrivia (1)
  • Authentication (21)
  • Business Continuity (3)
  • Client applications (20)
  • Consultancy and Design (21)
  • Hardware (9)
  • IT Management (14)
  • Miscellaneous (5)
  • Mobile (4)
  • Networking (18)
  • Office 365 Grid (5)
  • Performance (26)
  • Power (2)
  • Security (35)
  • SharePoint (81)
  • Unified Communications (4)
  • Virtualisation (30)
  • Windows (62)

Tags

  • Active Directory
  • AD FS
  • administration
  • Amazon Web Services
  • ASUS
  • Azure AD
  • certificates
  • Claims
  • Cloud
  • DCOM
  • Dell
  • development
  • DNS
  • EC2
  • FIM
  • Graphics
  • Hyper-V
  • IaaS
  • ICS
  • IIS
  • Information Rights Management
  • Intel
  • IRM
  • LDAP
  • Lync
  • Office 365
  • PowerShell
  • RMS
  • SAML
  • Search
  • SharePoint
  • SharePoint 2007
  • SharePoint 2010
  • SLAT
  • SSL
  • Token
  • User Information
  • User Profile
  • Virtual Machine
  • VMWare
  • w3wp
  • Windows 7
  • Windows Deployment Services
  • Windows Server 2008 R2
  • Workgroup

Archives by Month

Tristan Watkins on IT Infrastructure Proudly powered by WordPress