Windows IT Pro is the leading independent community for IT professionals deploying Microsoft Windows server and client applications and technologies.
  
  
  Advanced Search 


December 09, 2003

Protecting Sensitive Documents with Windows Rights Management Services

RSS
Subscribe to Windows IT Pro | See More Security Articles Here | Reprints | Or get the Monthly Online Pass—only $5.95 a month!

A little more than 2 months ago, I received my first introduction to Microsoft's new Windows Rights Management Services (RMS) for Windows Server 2003, one of the many out-of-band (OOB) updates the company planned for its latest Windows Server version. Microsoft describes Windows RMS as "information-protection technology that works with RMS-enabled applications to help safeguard digital information from unauthorized use--both online and offline, inside and outside of the firewall," and that description is fairly accurate, if a bit sterile. In effect, Windows RMS provides an additional layer of security for sensitive documents and email whose distribution you'd like to limit in some way. Windows RMS is a premium service for all Windows 2003 versions. Every user who creates or views rights-protected content through an RMS server will need a Client Access License (CAL--which costs $29 to $37 per CAL), and if you're deploying the service in a large enterprise with numerous external users, you can purchase an external connector for $14,000 to $18,000. This connector provides unlimited access to the Windows RMS server without the need to purchase individual CALs for each external user.

About 2 years ago, Microsoft began talking to its enterprise and government customers about intellectual property theft, the fastest growing white-collar crime. You might be familiar with the Web site http://www.f#$%edcompany.com (replace the special characters with the appropriate letters to get the real URL), which has made a business out of publishing private internal memos from large companies. This information is precisely what most companies don't want publicized, and the amount of money that companies can lose to such theft is staggering, especially when large companies are in the middle of a complex merger and a malicious user steals and publishes legal documents or sales forecasts. With the click of a button, companies can lose their competitive advantage.

"We had this notion in our heads," Microsoft Security Business Unit Lead Product Manager Scott Hanan told me, "of a technology that was like [Digital Rights Management (DRM)], but not DRM. Enterprises have a lot of information they want to protect and a need for great levels of protection. Today, they take reasonable steps to protect that information. But once a recipient receives the information, you've lost control. Another problem is that while companies typically do have a formal document policy that defines what 'confidential' is, they overwhelmingly are unable to enforce it. This is the type of thing financial institutions put a huge amount of effort towards. How many times have you seen the 'please don't forward' text at the top of an email message or document? It's like an invitation to forward it."

In short, companies that work with sensitive data need a document usage policy that stays with the documents, defining how long recipients can read the document; whether the recipients can print it, forward it, edit it, extract its content, and save it in a nonprotected manner; and perform other tasks. The usage policy needs to be template-based so that companies can easily define custom policies, and it needs to be seamlessly integrated into the products the companies already use.

Responding to these needs, Microsoft worked up its Windows RMS technology, which it released early last month. Like many recent Microsoft products, Windows RMS comes with a host of requirements, most of which necessitate that your enterprise be fairly Microsoft-centric. For example, Windows RMS runs only on Windows 2003 and requires Microsoft SQL Server 2000 Service Pack 3 (SP3) or later (or SQL Server 2000 Desktop Engine SP3 or later). You must be running an Active Directory (AD)-based domain, and the Windows RMS servers must be running the Microsoft Message Queuing, Microsoft Internet Information Services (IIS) 6.0, and ASP.NET services. Supported clients--Windows 2003, Windows XP, Windows 2000 SP3, and Windows Me--must install the Windows Rights Management (RM) client, which you can deploy through Group Policy. And for enterprises looking to use this functionality in their custom applications, a set of Windows RM client software development kits (SDKs) is also available.

But Windows RMS is a platform-level service that any application can use to provide policy-based rights for any document types. Most documents support constructs such as "read only" and "print," and if you want to set permissions on application-specific tasks (such as graphics resizing in a graphics application), you can customize your policy templates so that "Company Confidential" (or similar name) is defined in one place and any RMS-enabled application can enforce the policy without you needing to create application-specific templates. You can also integrate Windows RMS into your own applications, and the poster child for that capability is, of course, Microsoft Office 2003, which includes a new Information Rights Management (IRM) feature in its Office Word 2003, Office Excel 2003, Office PowerPoint 2003, and Office Outlook 2003 applications. By using Windows RMS policies and these Office 2003 applications, you can control which users can open, copy, print, or forward email, Word documents, Excel spreadsheets, and PowerPoint presentations. Microsoft also ships a Rights Management Add-on for Internet Explorer that lets you share a protected Office document with users on previous Office versions. In the latest Word, Excel, and PowerPoint version, or in the Outlook 2003 New Mail window, IRM shows up as a Permission icon in the Standard toolbar; when you select this option, you can choose to restrict the permissions on the current document by using a simple UI to explicitly select the domain users and groups that can access the document, their exact permissions, and the expiration date of the document, if desired (after which point no one can read it).

IRM and Windows RMS won't protect you against all digital theft. You can't prevent a worker from reading the contents of a protected document over the phone, for example, although I've joked that the next generation of Microsoft Smartphone software will eliminate that problem as well. And although the technology can prevent screen captures, certain applications that bypass Windows' standard screen-capture functionality have successfully captured shots of Windows RMS-protected windows. But Windows RMS is quite a bit better than nothing, and it should be able to thwart most casual document theft.

Next week, I'll explore the process of installing, configuring, and managing Windows RMS. In the meantime, drop me a note if you're interested in knowing whether this intriguing product includes a certain feature or functionality you'd find valuable. I'll try to address all these queries next week.

Links

Windows RMS
http://www.microsoft.com/downloads/details.aspx?familyid=be7fae0c-2db2-4f7f-8aa1-416fe1b04fb1&displaylang=en

Windows RM client
http://www.microsoft.com/downloads/details.aspx?familyid=3115a374-116d-4a6f-beb2-d6eb6fa66eec&displaylang=en

Windows RMS SDK
http://www.microsoft.com/downloads/details.aspx?familyid=2dfcafb9-3e7b-4f70-b6d3-aecc965cd598&displaylang=en

Windows RM client SDK
http://www.microsoft.com/downloads/details.aspx?familyid=863dadce-d648-4d50-9392-b4faca34a0a8&displaylang=en

Rights Management Add-on for Internet Explorer
http://www.microsoft.com/windows/ie/downloads/addon

====================

End of Article



Reader Comments
This is not a comment rather a cry for help: I completely lost my Menu and Toolbar on MICROSOFT WORD efforts to retrieve them went in vain, i consulted a Microsoft Office book I have inorder to rectify it but to no avail. It is preventint me from doing my reports. Would you Please help me

Emmanuel N'Dow December 11, 2003


Hi,
I was actually looking out for the implementation procedure in my domain.
It would be of great help if you could provide me that.

Thanks,


Suresh Babu December 16, 2003


Good general information. I'm interested in 2 additional items: (1) are there any analysis reporting capabilities with IRM (or RMS) like to whom and how many times access to a document was granted, and (2) in granting rights to individuals and/or groups, is it also possible to grant read-only (or dated) rights to anonymous users? I haven't located any info on these 2 topics yet.

Ron Funk April 13, 2004


Can this technology be intergrated with a commercial world wide enterprise that is serving documents via the web? We are looking for an RMS technology that will manage licencing and usage of commercial documents to users buying via the internet. Users need only be authenticated once but the restrictions, print, copy, forward, etc. need to be enforced at all times.

Duane Boudreau April 23, 2004


re: Web Protection Question. The RMS technology can be used to protect documents being served by the web (provided an IIS server is used). The implementation is tricky, but Microsoft ISV partners sell affordable out-of-the-box solutions.

Doug Johnson June 15, 2004


Where can I find information about the External Connector(EC) deployment? I am looking for decent "How To" information and if i only have a few external recipients can a just use individual CALs or do I have to purchase the
$18K EC?

Michael Pacheco July 06, 2004


How well RMS integrates with SPS when it uses MS Search ? The problem that I am trying to figure out is when MS Search indexes the files it should be decrypted ? Do you know solutions that can override this problem ?

YuvalEldar December 01, 2004 (Article Rating: )


You must be a registered user or online subscriber to comment on this article. Please log on before posting a comment. Are you a new visitor? Register now




Top Viewed ArticlesView all articles
Command Prompt Tricks

One reader shares his tip for setting up the command prompt to reflect a remote path. ...

2009 Windows IT Pro Editors' Best and Community Choice Awards

Picking a favorite product from an impressive crowd of competitive offerings is never an easy task, and such was the case with our Editors' Best and Community Choice awards this year. ...

WinInfo Short Takes: Week of November 23, 2009

An often irreverent look at some of the week's other news, including some post-PDC some soul searching, a Google Chrome OS announcement and a Microsoft response, Windows 7 off to a supposedly strong start, the Jonas Brothers and Xbox 360, and so much more ...


Security Whitepapers Reducing the Costs and Risks of Branch Office Data Protection

Solving Desktop Management Challenges in Healthcare

Solving Desktop Management Challenges in Education

Related Events Deep Dive into Windows Server 2008 R2 presented by John Savill

Introduction to Identity Lifecycle Manager "2"

Don't Miss Windows Server 2008 Virtual Event

Check out our list of Free Email Newsletters!

Security eBooks Spam Fighting and Email Security for the 21st Century

Understanding and Leveraging Code Signing Technologies

A Guide to Windows Certification and Public Keys

Related Security Resources Introducing Left-Brain.com, the online IT bookstore
Looking for books, CDs, toolkits, eBooks? Prime your mind at Left-Brain.com

Discover Windows IT Pro eLearning Series!
Clear & detailed technical information and helpful how-to's, all in our trademark no-nonsense format


Windows IT Pro Home Register FAQ for Windows WinInfo News
Europe Edition About Us Contact Us/Customer Service Media Kit Affiliates / Licensing  
SQL Server Magazine Office & SharePoint Pro DevProConnections IT Job Hound
Left-Brain.com Technology Resource Directory asp.netPRO ITTV Windows SuperSite 
 
 Windows IT Pro is a Division of Penton Media Inc.
 © 2009 Penton Media, Inc. Terms of Use | Privacy Statement