A way to find AD RMS protected files or migrate from Windows Server 2008?

%3CLINGO-SUB%20id%3D%22lingo-sub-215903%22%20slang%3D%22en-US%22%3EA%20way%20to%20find%20AD%20RMS%20protected%20files%20or%20migrate%20from%20Windows%20Server%202008%3F%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-215903%22%20slang%3D%22en-US%22%3E%3CP%3EWe%20still%20have%20local%20AD%20RMS%20running%20on%20Windows%20Server%202008%20(not%20R2).%20It%20is%20barely%20used%2C%20but%20there%20are%20a%20number%20of%20files%20protected%20by%20it%20in%20local%20share%20(maybe%20also%20in%20personal%20computers%2C%20but%20that's%20not%20important).%20We%20are%20not%20using%20AIP%20yet%20(as%20RMS%20was%20not%20very%20used%2C%20there%20was%20no%20interest%20in%20AIP%20either).%20But%20as%20AIP%20is%20enabled%20on%20our%20tenant%20and%20there%20will%20be%20changes%20incompatible%20with%20local%20RMS%2C%20we%20are%20looking%20into%20options%3A%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3E1)%20Is%20there%20a%20way%20to%20somehow%20identify%20all%20AD%20RMS%20protected%20documents%20in%20a%20local%20share%20(via%20search%20or%20something)%3F%20All%20i%20can%20see%20in%20RMS%20console%20is%20the%20number%20of%20times%20a%20license%20has%20been%20assigned.%20Not%20even%20users%20who%20have%20used%20it%20(we%20have%20User%20CALs).%3C%2FP%3E%3CP%3E2)%20I%20have%20read%20that%20only%20Windows%20Server%202008%20R2%20is%20supported%20for%20migration%20to%20AIP.%20Is%20there%20still%20some%20way%20to%20migrate%20from%20older%20version%3F%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-LABS%20id%3D%22lingo-labs-215903%22%20slang%3D%22en-US%22%3E%3CLINGO-LABEL%3ERights%20Management%3C%2FLINGO-LABEL%3E%3C%2FLINGO-LABS%3E%3CLINGO-SUB%20id%3D%22lingo-sub-242477%22%20slang%3D%22en-US%22%3ERe%3A%20A%20way%20to%20find%20AD%20RMS%20protected%20files%20or%20migrate%20from%20Windows%20Server%202008%3F%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-242477%22%20slang%3D%22en-US%22%3E%3CP%3EThe%20thing%20is%20that%20RMS%20didn't%20ever%20really%20took%20of%20here.%20But%20it%20was%20still%20left%20in%20place%20as%20there%20could%20be%20still%20a%20few%20files%20protected%20by%20it%20in%20the%20shares%20or%20even%20on%20users%20PCs..%20Anyway%2C%20i%20have%20already%20contacted%20our%20partners%20and%20got%20roughly%20the%20same%20answers.%20It%20is%26nbsp%3B%20added%20to%20the%20next%20year%20plans%20(though%20not%20sure%20if%20it%20will%20be%20done%20actually).%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-242449%22%20slang%3D%22en-US%22%3ERe%3A%20A%20way%20to%20find%20AD%20RMS%20protected%20files%20or%20migrate%20from%20Windows%20Server%202008%3F%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-242449%22%20slang%3D%22en-US%22%3ERegarding%20question%201%3A%3CBR%20%2F%3E%22Once%20the%20client%20has%20the%20use%20license%20no%20other%20activity%20is%20recorded%20unless%20the%20use%20license%20contains%20a%20policy%20that%20requires%20users%20to%20re-license%20the%20content%20(either%20every%20X%20days%20or%20every%20use).%20There%20is%20no%20logging%20on%20the%20client%20side%20of%20when%20and%20what%20rights%20used.%20The%20tool%20in%20the%20RMS%20Toolkit%2C%20RMSLogAnalyzer%20can%20be%20used%20to%20process%20the%20verbose%20server%20logs%20into%20a%20much%20more%20usable%20format%20that%20can%20then%20be%20used%20for%20audit%20tracked%20(though%20as%20stated%20before%20the%20server%20only%20knows%20about%20the%20license%20issued%2C%20not%20how%20many%20times%20it%20was%20used%20etc).%20The%20issuance%20license%20can%20be%20manually%20pulled%20from%20either%20the%20content%20or%20the%20RMS%20logging%20database.%20The%20tool%20in%20the%20RMS%20Toolkit%2C%20RMS%20CertAnalyzer%20can%20be%20used%20to%20decrypt%20the%20issuance%20license%20to%20view%20who%20has%20what%20rights%20to%20the%20content.%22%3CBR%20%2F%3E%3CA%20href%3D%22https%3A%2F%2Fblogs.msdn.microsoft.com%2Frms%2F2005%2F06%2F16%2Frms-logging-database-whats-collected%2F%22%20target%3D%22_blank%22%20rel%3D%22noopener%20noreferrer%22%3Ehttps%3A%2F%2Fblogs.msdn.microsoft.com%2Frms%2F2005%2F06%2F16%2Frms-logging-database-whats-collected%2F%3C%2FA%3E%3CBR%20%2F%3ERegarding%20question%202%2C%20you%20may%20need%20to%20consider%20a%20%22two%20hop%22%20migration%20and%20go%20from%202008%20to%20R2.%20here%20is%20an%20old%20thread%20that%20might%20help%20a%20little%20bit.%3CBR%20%2F%3E%3CA%20href%3D%22https%3A%2F%2Fsocial.technet.microsoft.com%2FForums%2Fie%2Fen-US%2F4f80c4fd-7b89-48cf-8bda-b3910ca81ae4%2Fad-rms-upgrade-from-server-2008-to-server-2008-r2-questions%3Fforum%3DwinserverDS%26amp%3Bforum%3DwinserverDS%22%20target%3D%22_blank%22%20rel%3D%22noopener%20noreferrer%22%3Ehttps%3A%2F%2Fsocial.technet.microsoft.com%2FForums%2Fie%2Fen-US%2F4f80c4fd-7b89-48cf-8bda-b3910ca81ae4%2Fad-rms-upgrade-from-server-2008-to-server-2008-r2-questions%3Fforum%3DwinserverDS%26amp%3Bforum%3DwinserverDS%3C%2FA%3E%3CBR%20%2F%3E%3CBR%20%2F%3EThis%20could%20be%20a%20model%20case%20study%20of%20%22technology%20debt%22%20where%20if%20you%20push%20off%20an%20upgrade%20too%20long%2C%20then%20you%20end%20up%20like%20this%2C%20with%20limited%20documentation%2C%20and%20limited%20support.%3CBR%20%2F%3E%3C%2FLINGO-BODY%3E
Super Contributor

We still have local AD RMS running on Windows Server 2008 (not R2). It is barely used, but there are a number of files protected by it in local share (maybe also in personal computers, but that's not important). We are not using AIP yet (as RMS was not very used, there was no interest in AIP either). But as AIP is enabled on our tenant and there will be changes incompatible with local RMS, we are looking into options:

 

1) Is there a way to somehow identify all AD RMS protected documents in a local share (via search or something)? All i can see in RMS console is the number of times a license has been assigned. Not even users who have used it (we have User CALs).

2) I have read that only Windows Server 2008 R2 is supported for migration to AIP. Is there still some way to migrate from older version?

2 Replies
Regarding question 1:
"Once the client has the use license no other activity is recorded unless the use license contains a policy that requires users to re-license the content (either every X days or every use). There is no logging on the client side of when and what rights used. The tool in the RMS Toolkit, RMSLogAnalyzer can be used to process the verbose server logs into a much more usable format that can then be used for audit tracked (though as stated before the server only knows about the license issued, not how many times it was used etc). The issuance license can be manually pulled from either the content or the RMS logging database. The tool in the RMS Toolkit, RMS CertAnalyzer can be used to decrypt the issuance license to view who has what rights to the content."
https://blogs.msdn.microsoft.com/rms/2005/06/16/rms-logging-database-whats-collected/
Regarding question 2, you may need to consider a "two hop" migration and go from 2008 to R2. here is an old thread that might help a little bit.
https://social.technet.microsoft.com/Forums/ie/en-US/4f80c4fd-7b89-48cf-8bda-b3910ca81ae4/ad-rms-upg...

This could be a model case study of "technology debt" where if you push off an upgrade too long, then you end up like this, with limited documentation, and limited support.

The thing is that RMS didn't ever really took of here. But it was still left in place as there could be still a few files protected by it in the shares or even on users PCs.. Anyway, i have already contacted our partners and got roughly the same answers. It is  added to the next year plans (though not sure if it will be done actually).