Cannot decrypt about 5% of encrypted files



Here's my problem. I very recently (three weeks ago) started moving
my user "My Documents" folders to a server using a GPO. This GPO also
set automatic encryption on the folders. Bunches of problems cropped
up, and I'm trying to move the folders back to the local desktops.

However, about 5% of the files (that's a guesstimate) just won't move
back. The copy says the user doesn't have rights to the suspect
files, even though the NTFS permissions say otherwise. Every one of
the suspect files is encrypted (as are the one that aren't causing any
problems). But when I try to decrypt them, it says I don't have
permissions to do that.

It doesn't matter how I log into the server; as the domain admin, the
local admin, or with the user account. I get the same error. The
other 95% of the files, which were copied over at the same time, under
the same user accounts, and (one presumes) the same encryption keys,
decrypt just fine.

I am completely at a loss to understand this behavior. Before I
started moving user data, I tested this all with a small group of
users, and I was able (as the domain admin), to encrypt and decrypt
files at will. Does anyone have any step-by-step procedures I could
try to recover these files. I'm not a noobie, but right this moment
I'd prefer some detailed, hand-holding instructions on this.

.



Relevant Pages

  • Re: Folder Redirection GPO - Issues after the SBS2008 migration
    ... The SBS2003 server had a GPO configured to redirect %appdata% ... folders to the SBS2003 server using the UNC ... GPO was modified during the migration to ...
    (microsoft.public.windows.server.sbs)
  • Re: Folder Redirection GPO - Issues after the SBS2008 migration
    ... The SBS2003 server had a GPO configured to redirect %appdata% ... folders to the SBS2003 server using the UNC ... GPO was modified during the migration to ...
    (microsoft.public.windows.server.sbs)
  • Re: Cannot decrypt about 5% of encrypted files
    ... my user "My Documents" folders to a server using a GPO. ... set automatic encryption on the folders. ... But when I try to decrypt them, ... It doesn't matter how I log into the server; ...
    (microsoft.public.security)
  • Re: Cannot decrypt about 5% of encrypted files
    ... my user "My Documents" folders to a server using a GPO. ... set automatic encryption on the folders. ... But when I try to decrypt them, ... It doesn't matter how I log into the server; ...
    (microsoft.public.security)
  • Re: Network Shared Files/UNC
    ... Windows Server MVP ... > issues regarding our network security. ... GPO settings are not inherited from the domain GPO ... > folders of our servers by just running Notepad and going ...
    (microsoft.public.win2000.active_directory)