Skip to content

Tristan Watkins on IT Infrastructure

Technical guidance for Microsoft security technologies, Windows, SharePoint, and other generally useful findings

Tag: STS

RMS Use Licenses, Offline Access and Rights Revocation with SharePoint 2010

After a brief diversion, I’m returning to my series on SharePoint with RMS. This post finishes off the baseline considerations, although there’s a lot more to say. But at last, in this post, we’ve reached the point where we know that RMS thinks I’m cool – so now what? Or if you prefer, I’m taking a look at the RMS Use License that is typically embedded in Microsoft Office documents, or in other cases might be associated with a client’s machine.

The Use License that RMS issues acts like an offline enforcer of allowed rights. The rights granted by RMS and the duration they persist define what a user can do with their offline copy of RMS-protected content and how long they can continue to take those actions before they need to re-visit SharePoint and the RMS infrastructure in order to claim fresh rights. Since rights persistence is defined by the owner(s) of a SharePoint list, the impact of those settings should be well understood by any users that have this control.This post focuses on what a user can do offline once RMS has done its job, and the user’s experience once those rights expire, bringing the tension between valid offline access versus timely rights revocation to the fore.

You will notice I’m talking about offline access a lot here. When I say “offline” in reference to RMS-protected content, I mean the documents that have already been encrypted by RMS and decrypted/opened by a user. I say the files are offline because the original unencrypted content still resides in the SharePoint content database. Any edits that RMS allows a user to make to the offline content need to be saved back to SharePoint if they will persist over time. Continue reading “RMS Use Licenses, Offline Access and Rights Revocation with SharePoint 2010”

Author Tristan WatkinsPosted on July 15, 2013July 16, 2013Categories Authentication, Client applications, Security, SharePoint, WindowsTags Active Directory, authentication, authorisation, Cache, expiration, Information Rights Management, IRM, license, Offline, Protection Policies, revocation, RMS, SharePoint 2010, STS, STSADM, Token, User Information, User Profile5 Comments on RMS Use Licenses, Offline Access and Rights Revocation with SharePoint 2010

On Twitter

My Tweets

Recent Comments

  • ADFS 2.0 time out and relation between Freshness Value,TokenLifetime and WebSSOLifetime parameters on Office 365 Single Sign Out with ISA or TMG as the ADFS Proxy
  • Reduslim prezzo in farmacia on DCOM Security for SharePoint Administrators
  • Ye Zejun on No Lossless Audio With Zune
  • Tristan Watkins on Start using Claims X-Ray with Azure AD
  • Robin on Start using Claims X-Ray with Azure AD

Categories

  • Administrivia (1)
  • Authentication (21)
  • Business Continuity (3)
  • Client applications (20)
  • Consultancy and Design (21)
  • Hardware (9)
  • IT Management (14)
  • Miscellaneous (5)
  • Mobile (4)
  • Networking (18)
  • Office 365 Grid (5)
  • Performance (26)
  • Power (2)
  • Security (35)
  • SharePoint (81)
  • Unified Communications (4)
  • Virtualisation (30)
  • Windows (62)

Tags

  • Active Directory
  • AD FS
  • administration
  • Amazon Web Services
  • ASUS
  • Azure AD
  • certificates
  • Claims
  • Cloud
  • DCOM
  • Dell
  • development
  • DNS
  • EC2
  • FIM
  • Graphics
  • Hyper-V
  • IaaS
  • ICS
  • IIS
  • Information Rights Management
  • Intel
  • IRM
  • LDAP
  • Lync
  • Office 365
  • PowerShell
  • RMS
  • SAML
  • Search
  • SharePoint
  • SharePoint 2007
  • SharePoint 2010
  • SLAT
  • SSL
  • Token
  • User Information
  • User Profile
  • Virtual Machine
  • VMWare
  • w3wp
  • Windows 7
  • Windows Deployment Services
  • Windows Server 2008 R2
  • Workgroup

Archives by Month

Tristan Watkins on IT Infrastructure Proudly powered by WordPress