070-649 Free Dumps Study Materials
Question 15: Your network contains two Active Directory forests named contoso.com and nwtraders.com.
Active Directory Rights Management Services (AD RMS) is deployed in each forest.
You need to ensure that users from the nwtraders.com forest can access AD RMS protected content
in the contoso.com forest.
What should you do?
A. Create an external trust from nwtraders.com to contoso.com.
B. Add a trusted user domain to the AD RMS cluster in the nwtraders.com domain.
C. Create an external trust from contoso.com to nwtraders.com.
D. Add a trusted user domain to the AD RMS cluster in the contoso.com domain.
Correct Answer: D
Explanation:
A trusted user domain, often referred as a TUD, is a trust between AD RMS clusters that instructs a
licensing server to accept rights account certificates (the certificates identifying users) from another
AD RMS server in a different Active Directory forest. An AD RMS trust is not the same as an Active
Directory trust, but it is similar in that it refers to the ability of one environment to accept identities
from another environment as valid subjects. As a TUD is a trust between AD RMS infrastructures, it
requires that each forest (whether in the same company or in different companies) has its own AD
RMS infrastructure. Using trusted user domains, AD RMS can process requests for use licenses from
users whose rights account certificates were issued by an AD RMS installation in a different Active
Directory forest; in other words, from a different certification cluster. Trusted user domains are
added by importing the server licensor certificate, of the AD RMS installation to trust, to the trusting
AD RMS installation.