KMS Server limited to an OU

Posted on 2012-08-23
Last Modified: 2012-08-26

We're using a big domain with many OU inside. Till now, I was the only one using KMS to activate my Windows and Office.

But now, there is another OU which want to do the same.
I don't want them to use my KMS because of licence key (we have separate contrat from microsoft).
So my question, is it possible to limit a KMS to an OU ?
Or should I publis multiple KMS and limit "view" by restriciting access-list on my firewall ?

Any suggestions will be appreciate.
Thx in advance.
Question by:Sybux
    LVL 35

    Expert Comment

    by:Ernie Beek
    I think the latter would be the way to go. KMS doesn't really integrate into AD (only uses DNS which technically is a part of AD).
    So you can't limit it to an OU but need to address this on a network level.
    LVL 2

    Expert Comment

    Have a look at this:
    and this

    though yes you can just add them both then limit the ports on the firewall. It picks them at random until it finds one that works. see "client discovery" section
    LVL 4

    Accepted Solution

    KMS does not require Domain authentication so there is no way to select witch clients have access to licensing keys. Blocking that traffic is one way but I would explore how to set KMS to only give licensing keys to selected subnets.

    Featured Post

    How to run any project with ease

    Manage projects of all sizes how you want. Great for personal to-do lists, project milestones, team priorities and launch plans.
    - Combine task lists, docs, spreadsheets, and chat in one
    - View and edit from mobile/offline
    - Cut down on emails

    Join & Write a Comment

    When I went to try to install Office 2007 and Office 2010 ADMX Group Policy administrative templates on my new Windows Server 2008 R2, I couldn't find any straightforward guidance on how to do it.  I muddled my way through it, but I thought I'd shar…
    Normally after a failure of Domain Controller, when promoting new DC the DC is renamed, we will discuss the options in Dcpromo to re-create the DC with the same name. Scenario: You are a small IT shop with two Domain Controllers (Domain Contr…
    This tutorial will walk an individual through the steps necessary to install and configure the Windows Server Backup Utility. Directly connect an external storage device such as a USB drive, or CD\DVD burner: If the device is a USB drive, ensure i…
    This tutorial will walk an individual through the steps necessary to join and promote the first Windows Server 2012 domain controller into an Active Directory environment running on Windows Server 2008. Determine the location of the FSMO roles by lo…

    729 members asked questions and received personalized solutions in the past 7 days.

    Join the community of 500,000 technology professionals and ask your questions.

    Join & Ask a Question

    Need Help in Real-Time?

    Connect with top rated Experts

    18 Experts available now in Live!

    Get 1:1 Help Now