Re: file access/permissions problem...

From: Karl Levinson [x y] MVP (levinson_k@excite.com)
Date: 10/21/02


From: "Karl Levinson [x y] MVP" <levinson_k@excite.com>
Date: Mon, 21 Oct 2002 09:12:30 -0400


"Greg" <gregkh@optonline.net> wrote in message
news:8d7c01c278f6$e64d2aa0$3bef2ecf@TKMSFTNGXA10...

> taking ownership of the folder, I tried
> unchecking "Encrypt documents to secure data" and I get an
> error message, "an error occured while applying attributes
> to this file: <gives the pathway> Access is denied." I

If these files were encrypted, see below:

Using any form of file encryption is a good way to lose your files forever,
unless you understand how to use the encryption and take steps BEFOREHAND to
preserve your data. Microsoft's EFS is no exception.

With EFS, you absolutely MUST back up your encryption key, or you risk
losing your data. If your PC will no longer boot into Windows, or you have
formatted the hard drive, or you reinstalled Windows, you will lose your
encryption key and your files will be unreadable, unless you have backed up
your encryption key.

Information on how to use EFS, including how to back up and restore an
encryption key [BEFORE a problem occurs] can be found here:

http://www.microsoft.com/windows2000/techinfo/planning/security/efssteps.asp
 - Implementing EFS
http://support.microsoft.com/default.aspx?scid=kb;en-us;Q255742 - Windows
2000
http://microsoft.com/windowsxp/pro/techinfo/administration/recovery/default.
asp - Windows XP

Certain conditions can cause an XP encryption key to no longer decrypt
files, such as if the administrator on a Windows XP computer resets a user's
password. Information on how to try to recover from this event can be found
here:

http://support.microsoft.com/default.aspx?scid=kb;en-us;Q290260

Information on EFS encryption / decryption methods and recommendations can
be found here:

http://support.microsoft.com/default.aspx?scid=kb;en-us;Q324897

If you did not back up the encryption key and are having problems, there are
only a few instances where you may be able to recover your files:

1. If the computer is joined to a Windows 2000 / .NET domain, the domain
Administrator account is the default EFS Recovery Agent and might be used to
recover the files. [Other accounts can be added as recovery agents.] In a
Windows 2000 or newer domain, the encryption keys are stored on the server,
so that you may be able to recover the encrypted files EVEN IF Windows has
been reinstalled on the workstation. For more information, try searching
www.google.com and/or www.microsoft.com/support for something like "EFS
recovery-agent" or "EFS recovery-agent windows-2000 recover."

2. If the computer is not joined to a Windows 2000 / .Net domain and Windows
has NOT been reinstalled, the local Administrator account is the default
recovery agent.

Note that if someone has physical access to your computer, and your computer
is not joined to a domain, that person can potentially read your encrypted
files by renaming or otherwise modifying the SAM file to gain access to the
Administrator account. With any Microsoft or non-Microsoft operating
system, there is no security without physical security.

.



Relevant Pages

  • Re: win2k file encryption problem
    ... See here for some information on EFS keys and a few things you might try to ... recover your files: ... previous version of Windows, or the computer is joined to a Windows 2000 ... while the encryption / decryption secret key used to encrypt the file is ...
    (microsoft.public.win2000.security)
  • Re: user does not have acces privileges
    ... to reinstall the windows to do that. ... ownership is the reason of the inaccessibility. ... I'm not an expert but I find out, it is not the encryption but ... "Zorro" wrote: ...
    (microsoft.public.windowsxp.accessibility)
  • Re: How to recover files encrypted with EFS by NT backup
    ... Windows 2000 image 3.0 was used to encrypt the ... Recovery Agent account to recover the files. ... windows partition and folder while Windows was running, ... With EFS and any other encryption technology, ...
    (microsoft.public.win2000.security)
  • Re: user does not have acces privileges
    ... But now at the new files I should have the right EFS key in my computer. ... That means there is something wrong with the ownership settings and that was ... Or it is only matter if the encryption is combined with the ownership change? ... to reinstall the windows to do that. ...
    (microsoft.public.windowsxp.accessibility)
  • Re: Cannot access encrypted files after reinstalling Windows XP Professional
    ... able to break the encryption in a reasonable amount of time. ... > keys are generated each time you do an install, ... > they would be related to the Windows serial key, ... >>> All data files are stored on partition D:. ...
    (microsoft.public.windowsxp.security_admin)