Re: recovery agent

From: Steven L Umbach (n9rou_at_nospam-comcast.net)
Date: 04/05/05


Date: Tue, 5 Apr 2005 15:50:19 -0500

For Windows 2000 a RA can be configured via security policy for the domain
or Organizational Unit level. Windows 2000 [not Xp Pro] will automatically
assign a RA to a stand alone computer being the built in administrator
account when the first file is encrypted with EFS on that computer. For
domain computers, the configuration of RA is more complex. Be very careful
with EFS. It is like a gun that it can protect you or shoot yourself in the
foot [or worse] if the user is not trained properly. The link below is about
EFS best practices including the need to ALWAYS backup your EFS private key
to a password protected .pfx file.. --- Steve

http://support.microsoft.com/default.aspx?scid=kb;EN-US;223316

"arian" <arian@discussions.microsoft.com> wrote in message
news:E323CDF8-AEF2-401A-AC70-CF7F3EF4BAF5@microsoft.com...
> hi,
> I need useful information about Recovery Agent(for example,How I can use a
> certificate when choosing a user as a recovery agent).
> I also would like to know how I can use recovery agent in a single
> computer.
> Thanks
> arian



Relevant Pages

  • Re: EFS Certificate Needed
    ... Backup and save on non-degrading media the EFS DRA .pfx file ... Foe sure I will follow "Windows Recommendations". ... that recovery agent will only have ... Best practices for the Encrypting File System ...
    (microsoft.public.security)
  • Re: Passwords on Folders
    ... domain computer [there is also a recovery agent for a domain]. ... > Windows under which those permissions were defined. ... use NTFS on your hard drives so you can then EFS ...
    (microsoft.public.win2000.security)
  • Re: EFS Certificate Needed
    ... a backup and restore of an EFS ... not load some of them because the encrypted files were still present. ... Foe sure I will follow "Windows Recommendations". ... that recovery agent will only have ...
    (microsoft.public.security)
  • Re: recovering documents from old hardrive please help
    ... If they are encrypted with EFS, then no, unless you saved a copy of the encryption certificate and/or designated a recovery agent. ... How to back up the recovery agent Encrypting File System private key in Windows Server 2003, in Windows 2000, and in Windows XP ...
    (microsoft.public.windowsxp.general)
  • RE: Re[2]: Encryption on Laptops?
    ... attack that Bart described is indeed possible - but only on Windows 2000 ... I don't see any reason to conclude that EFS is inherently a weak solution. ... to facilitate one-on-one interaction with one of our expert instructors. ... Attend a course taught by an expert instructor with years of in-the-field ...
    (Security-Basics)