Re: Access denied- encryption

From: Torgeir Bakken (Torgeir.Bakken-spam@hydro.com)
Date: 09/10/02


From: Torgeir Bakken <Torgeir.Bakken-spam@hydro.com>
Date: Tue, 10 Sep 2002 02:16:00 +0200


Manuel Fernandes wrote:

> I am tired of Windows 2000 encrypting users files and then preventing them
> for accessing their own data. How does I stop this mess????

>From "Encrypting File System in Windows XP and Windows .NET Server" found at
http://www.microsoft.com/WINDOWSXP/pro/techinfo/administration/recovery/default.asp:

Empty recovery policy. When an administrator deletes all recovery agents and
their public-key certificates, an empty recovery policy is in effect. An empty
recovery policy means that no recovery agent exists, and if the client operating
system is Windows 2000, EFS is disabled in this configuration. The Windows XP
client allows EFS to operate with an empty DRA policy.

Disabling EFS
Disabling EFS is now possible using Windows XP if you want to block certain
computers from allowing users within a specific domain or OU in the Active
Directory from encrypting data. In a domain environment, EFS may be disabled on
computers by using Group Policy.

--
torgeir


Relevant Pages

  • Re: Access denied- encryption
    ... > From "Encrypting File System in Windows XP and Windows .NET Server" found ... an empty recovery policy is in effect. ... EFS is disabled in this configuration. ...
    (microsoft.public.win2000.security)
  • RE: Re[2]: Encryption on Laptops?
    ... attack that Bart described is indeed possible - but only on Windows 2000 ... I don't see any reason to conclude that EFS is inherently a weak solution. ... to facilitate one-on-one interaction with one of our expert instructors. ... Attend a course taught by an expert instructor with years of in-the-field ...
    (Security-Basics)
  • Re: Passwords on Folders
    ... > you to use passwords on folders? ... Windows NT/2000/XP do not natively let you set passwords on folders. ... Windows under which those permissions were defined. ... use NTFS on your hard drives so you can then EFS ...
    (microsoft.public.win2000.security)
  • Re: EFS Decryption Problem
    ... hard drive is running the old instance of Windows under which the EFS ... Or did you install a new instance of Windows ... The username is irrelevant to EFS. ... the EFS certificate and save it on removable media (floppy, CD, thumb ...
    (microsoft.public.windowsxp.security_admin)
  • Re: EFS Certificate Needed
    ... Backup and save on non-degrading media the EFS DRA .pfx file ... Foe sure I will follow "Windows Recommendations". ... that recovery agent will only have ... Best practices for the Encrypting File System ...
    (microsoft.public.security)