How to install Active Directory Rights Management Services

One of the best features of Active Directory in Windows server 2008 is a security tool called Active Directory Rights Management Services (AD RMS). AD RMS allows organizations to secure content such as word documents, excel spread sheets, email’s and even can be integrated in SharePoint. A user would need to be authenticated before they could access the data from any of those content sources. I know this topic has been covered before but I wanted to post the steps from my deployment of AD RMS.

A Windows Server 2008 domain is required before you begin.

On the server you will deploy AD RMS on:

  • Open Server manager
  • Expand Roles
  • Right click and select Add New Roles
  • Click Next
  • Select AD Rights management Services and click next


The following roles will need to be added as well.

  • Click Add Required Role Services.


  • Click Next

You can explore more about AD RMS on the next window by clicking any of the links. When done click next.


Here you have an option to add Identify Federation Support. You can add this now if you will use it or come back in and add it later.

  • Click next when ready.


Now create the new AD RMS Cluster. If you already had AD RMS you would be adding to an existing cluster.

  • Click next to continue.


Now you need to select where to store the AD RMS databases. This can be on an internal windows database or a SQL instance. I typically put mine on a SQL instance. This gives me better control over performance and better ability to backup.

NOTE: you have to click Validate before you are able to click next.


Now you need to specify a domain account that will be AD RMS.


I created a dedicated account for this and use it for RMS only.

  • Select how you want to store the cluster key and click next.


  • Specify a cluster key password and click next.

NOTE: Document this password somewhere.


Now you need to select an IIS website to host your RMS.

  • Select the default site and click next.


Now you need to chose to use SSL or non SSL.

NOTE: The purpose of RMS is security so the best option here is to select SSL. I don’t know why you wouldn’t want that here.

Put in your RMS’s URL. Don’t forget to add the DNS for this if it is not the same as your computer name.

  • Click Validate after inputting the URL.
  • Click next to continue.


You have multiple options here.; you can create a self signed certificate, choose the certificate later or import the certificate now. If one is already loaded on the server It will show up in this window as one to be selected.

  • Select a certificate to use and click next.


  • This will default to the servers name. I change this to RMS. Click next to continue.


  • Register the AD RMS Connection Point in Active Directory. Click next to continue.


  • You will then see a screen with an intro to IIS. Click the links to learn more or click next to move on.


  • On the next screen add any more IIS components that you may need and click next.

NOTE: The required components for AD RMS will automatically be selected for you.

You will then see the confirmation screen. These are all the settings you just went through. I would recommend clicking that link and saving this information.


  • Click Install to finish the deployment.

That is it. The install is pretty straight forward and you should be able to start using RMS protection. There is more to configuring additional functionality and managing RMS. Here are some good resources to get started on this.

(AD RMS Installation Best Practices –

Print Friendly, PDF & Email

Leave a Comment