Docs deployment for Active Directory Rights Management Services support
- On the computer that hosts BEMS, install the Rights Management Services Client 2.1. To download the client, visit www.microsoft.com/downloads and search for ID=38396.
- If using self-signed certificates in AD RMS server, add the SSL certificate for https://<AD RMS server URL> to the trusted CA list.
- In a browser, add https://<AD RMS server URL> to the Local Intranet site list.
- Install the Docs service with the Good Technology Common Services service running as a domain user. If you installed BEMS using the service account, you can change the BEMS service account. For more information, see KB 58463.
- If a super users group is not already configured in AD RMS server, configure one. Then add BEMS process user (Good Technology Common Services service user) to this AD RMS super users group.
-
On the AD RMS server, find the file %systemdrive%\Inetpub\wwwroot\_wmcs\Certification\ServerCertification.asmx and add Read and Read & Execute permissions for the following:
- the AD RMS Service Group.
The AD RMS Service Group is a local group and not a domain group.
- the computer account for each of the BEMS servers.
- The Good Technology Common Services service user.
- the AD RMS Service Group.