News

Microsoft Issues Hotfix for AD Rights Management

IT shops using Microsoft's Active Directory rights management services (AD RMS) will need to install an update before Feb. 22 to avoid expiring permission certificates.

Organizations typically use AD RMS to protect sensitive data in application files. The service enables file-level encryption control by IT pros and lets them specify rights and restrictions, such as making files read-only and preventing the forwarding of files in e-mails.

The AD RMS update, released on Tuesday, removes a legacy feature in the service that was designed to prevent users from using older unpatched applications. The update applies to most Windows versions and can be downloaded at Microsoft's Windows Update page or at the Microsoft Support page here.

If a system using AD RMS is left unpatched, users "will not be able to create or access protected content" on Feb. 22 when certificates expire, according to the Microsoft Forefront team blog.

Any Web-based application using this service will be affected, but it particularly affects Microsoft's Internet Explorer browser. In addition, users will have problems accessing or creating protected content using Microsoft Outlook (versions 2000, 2003 or 2007) and Web viewers for Excel, PowerPoint and Word.

Microsoft explained that this new hotfix is being rolled out as a follow-up to an information rights management certificate problem discovered in Office 2003. In December, Microsoft issued hotfixes for an Office 2003 information rights management problem and subsequently published a support description.

The new AD RMS hotfix removes the application manifest expiry feature of the service. Instead of that relying on that legacy feature, IT pros can use "application exclusion" and "Windows software restrictions policies" in AD RMS to control policies, according to the Forefront team blog. Microsoft claims that this change to AD RMS provides greater control for customers using the service.

About the Author

Kurt Mackie is senior news producer for the 1105 Enterprise Computing Group.

Featured

  • RAMBleed Side-Channel Attack Method Disclosed by Researchers

    Academic researchers this week published information about another side-channel attack method, called "RAMBleed," that can expose information from memory chips, including encryption key information.

  • Penguin

    Windows 10 Preview Build 18917 Shows Off New Linux Integration

    Microsoft's latest Windows 10 "fast-ring" preview release is showcasing a coming Delivery Optimization enhancement, along with the ability to try the newly emerged Windows Subsystem for Linux version 2.

  • Customizing Microsoft Office 365

    While the overall look and feel of Office 365 is pretty standard across organizations, there are several ways to personalize it and make it fit better with your company's specific needs.

  • Microsoft 365 Business Tenants Getting Conditional Access and Trouble-Ticket Features

    Microsoft added its conditional access security service to Microsoft 365 Business subscriptions, according to a Wednesday announcement, and it also added new trouble-ticket features for Microsoft 365 administrators.

comments powered by Disqus

Office 365 Watch

Sign up for our newsletter.

Terms and Privacy Policy consent

I agree to this site's Privacy Policy.