> For the complete documentation index, see [llms.txt](https://docs.lithnet.io/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://docs.lithnet.io/ams/v2.0/help-and-support/app-pages/security-page.md).

# Security page

![](https://2384577883-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FGiL0iwWnyPOkaGqdhRTp%2Fuploads%2Fgit-blob-5b8009ad4e1c9909ecbee2a5d720930bb2f8fe61%2Fui-page-security.png?alt=media)

## Service administration

### AMS administrators group

The AMS administrators group are able to manage the AMS service. They are able to edit configuration using the UI, as well as connect and execute PowerShell commands against the server.

### Encryption support

This section shows if DPAPI-NG encryption is supported on this server and in this domain. DPAPI-NG encryption support is mandatory for environments with multiple servers in a farm.

DPAPI-NG support requires at least one domain controller in the domain running Windows Server 2012 R2, and a [KDS root key](https://docs.microsoft.com/en-us/windows-server/security/group-managed-service-accounts/create-the-key-distribution-services-kds-root-key) must have been generated in the domain.

### Master key recovery password

All secrets in the database are protected by the AMS server master key. This is used to encrypt server-side secrets and private keys. Without the master key, AMS will be unable to decode settings and stored passwords, and will fail to start. A master key recovery password allows you to recover the master key in the event the server is unable to decrypt it on its own. Generate a recovery password, and store it in a safe place.

Note, that each time you generate a new recovery password, you invalidate the previous password. Only one recovery password can be active at a time.

If the server is unable to access it's master key, and no recovery password is available, there are no recovery options for the server. You will need to rebuild the environment from scratch.


---

# Agent Instructions
This documentation is published with GitBook. GitBook is the documentation platform designed so that both humans and AI agents can read, navigate, and reason over technical content effectively. Learn more at gitbook.com.

## Querying This Documentation
If you need additional information that is not directly available in this page, you can query the documentation dynamically by asking a question.

Perform an HTTP GET request on the current page URL with the `ask` query parameter, and the optional `goal` query parameter:

```
GET https://docs.lithnet.io/ams/v2.0/help-and-support/app-pages/security-page.md?ask=<question>&goal=<endgoal>
```

`ask` is the immediate question: it should be specific, self-contained, and written in natural language.
`goal` is optional and describes the broader end goal you are ultimately trying to accomplish on behalf of the user. GitBook uses it to tailor the answer towards what is most useful for that goal.

The response will contain a direct answer to the question and relevant excerpts and sources from the documentation.

Use this mechanism when the answer is not explicitly present in the current page, you need clarification or additional context, or you want to retrieve related documentation sections.
