70-649 · Question #196
Your network contains two Active Directory forests named contoso.com and nwtraders.com. Active Directory Rights Management Services (AD RMS) is deployed in each forest. You need to ensure that users…
The correct answer is D. Add a trusted user domain to the AD RMS cluster in the contoso.com domain. A trusted user domain, often referred as a TUD, is a trust between AD RMS clusters that instructs a licensingserver to accept rights account certificates (the certificates identifying users) from another AD RMS server in adifferent Active Directory forest. An AD RMS trust is…
Question
Your network contains two Active Directory forests named contoso.com and nwtraders.com. Active Directory Rights Management Services (AD RMS) is deployed in each forest. You need to ensure that users from the nwtraders.com forest can access AD RMS protected content in the contoso.com forest. What should you do?
Options
- ACreate an external trust from nwtraders.com to contoso.com.
- BAdd a trusted user domain to the AD RMS cluster in the nwtraders.com domain.
- CCreate an external trust from contoso.com to nwtraders.com.
- DAdd a trusted user domain to the AD RMS cluster in the contoso.com domain.
How the community answered
(29 responses)- A3% (1)
- B10% (3)
- C3% (1)
- D83% (24)
Explanation
A trusted user domain, often referred as a TUD, is a trust between AD RMS clusters that instructs a licensingserver to accept rights account certificates (the certificates identifying users) from another AD RMS server in adifferent Active Directory forest. An AD RMS trust is not the same as an Active Directory trust, but it is similar inthat it refers to the ability of one environment to accept identities from another environment as valid subjects. As a TUD is a trust between AD RMS infrastructures, it requires that each forest (whether in the samecompany or in different companies) has its own AD RMS infrastructure. Using trusted user domains, AD RMS can process requests for use licenses from users whose rights accountcertificates were issued by an AD RMS installation in a different Active Directory forest; in other words, from adifferent certification cluster. Trusted user domains are added by importing the server licensor certificate, of theAD RMS installation to trust, to the trusting AD RMS installation.
Topics
Community Discussion
No community discussion yet for this question.