Tek-Tips is the largest IT community on the Internet today!

Members share and learn making Tek-Tips Forums the best source of peer-reviewed technical information on the Internet!

  • Congratulations SkipVought on being selected by the Tek-Tips community for having the most helpful posts in the forums last week. Way to Go!

Windows Rights Management - Do Not Distribute

Status
Not open for further replies.

thabrock

MIS
Aug 31, 2006
81
0
0
US
We have an Excel document that we need to send to a client, but we want to prevent them from sending this document to anyone else. Can I do this using Windows Rights Management and assigning a "Do Not Distribute" attribute? Is that attribute carried across to people who are not users in our AD?

Will users not part of our corporate network be able to read that document?

Thanks.

Ti
 


You ought to post this question in a MS WINDOWS forum, not the MS Office forum.

Skip,
[sub]
[glasses]Just traded in my old subtlety...
for a NUANCE![tongue][/sub]
 
It is debatable as to whether Skip is fully correct in this. No, it is not really an Office question...although it sort of is. No, it is not really a Windows question either.

In any case,

"Is that attribute carried across to people who are not users in our AD?"

I think not.

"Will users not part of our corporate network be able to read that document?"

I think yes.

I believe the "increased security" of Rights Management only applies within the environment controlled by it. Outside of it, it is a regular Office file and thus essentially unsecure...or is that insecure?

I may be incorrect on this.



Ooops. I am incorrect. It appears that files created on a RMS system require a RMS-enabled application, AND any application providing access to protected content must be RMS-aware and have to implement the RMS client APIs explicitly.

Further, the RMS client is required for both creating rights-protected content as well as accessing it.

So, first of all, anyone trying to read it must have the RMS client.

Second, RMS assigns an AES private key and it is validated by RMS.

So unless I am horribly mistaken...again....while I do not think a "Do not Distribute" attribute is carried over to a non-your-RMS system (and so yes it could be forwarded) it seems that if properly locked up, it may not be able to be opened.

That being said, if it is seriously valuable, I would not seriously trust any Microsoft security.

Gerry
 
Status
Not open for further replies.

Part and Inventory Search

Sponsor

Back
Top