Re: Implementing EFS for select users

From: Steven L Umbach (n9rou_at_nospam-comcast.net)
Date: 10/26/05


Date: Wed, 26 Oct 2005 12:59:38 -0500

It depends on if the workstations are Windows 2000 or XP Pro. For Windows
2000 you need to create a policy with an empty list of Recovery Agents for
the computers you want to disable it on and for Windows XP you need to
uncheck the box that allows EFS to be used. What you could do is disable it
on all computers at the domain level via Group Policy and then add the four
computers you want it enabled on into their own OU with a GPO linked to it
and configured where they will have it enabled. The links below explain more
on how to do this with Group Policy. Be VERY careful with EFS as it is easy
to lose permanent access to your data if best practices are not followed
such as using a Recovery Agent and having users baking up their EFS
certificate AND private key to password protected .pfx files. Note that you
can manage EFS by computer - not user. --- Steve

http://support.microsoft.com/default.aspx?scid=kb;en-us;222022&sd=tech ---
Group Policy EFS for Windows 2000
http://www.petri.co.il/disable_efs_in_windows_xp_2003.htm --- Group Policy
EFS Windows XP/2003
http://support.microsoft.com/default.aspx?scid=kb;EN-US;223316 --- EFS
best practices

"CYACOMINI (ILG)" <CYACOMINIILG@discussions.microsoft.com> wrote in message
news:87499B95-3675-4978-8E3A-9446A7A6F759@microsoft.com...
> Hello - here's a good one..
>
> We have our finance team and their workstations located on the same floor
> as
> a 3rd party company. As a result, we want to apply EFS to the finance
> workstations which connect to our banks etc. Problem is, I can't seem to
> work
> it all out !
>
> To explain, we have a total of 50 workstations in the finance team - only
> 4
> of which we want to apply EFS to (select folders). These machines are all
> in
> Active Directory and are used by multiple users at different times.
>
> Can anyone explain what i should be doing here, or even point me in the
> right direction ? I've got the Microsoft guides but they just dont seem to
> help - keep getting errors about the selected users not having the
> appropriate certificates.
>
> thanks in advance !
>
>



Relevant Pages

  • Re: Workstations looking for Old Policy
    ... You might be better off getting a Windows XP client with GPMC ... find the offending policy and delete all the links that it has. ... >> Hi Russ ... >>> Our Windows XP Pro workstations are looking for an old policy that was ...
    (microsoft.public.win2000.group_policy)
  • Re: Strong Password Group Policy not working
    ... It sometimes gives you a little more info on why a gpo wasn't applied. ... >I have one Windows 2003 Active Directory domain with Windows XP and Windows ... the policy is not applied to any of the workstations. ...
    (microsoft.public.win2000.active_directory)
  • Re: AutoLogoff via Time Restrictions...
    ... and not on the workstations. ... >>You then enable the policy to force logoff when logon ... I think I remember testing this for windows 2000 ... >>>Automatically log off users when logon time expires ...
    (microsoft.public.win2000.security)
  • Re: Enable EFS --- GPO Problem
    ... Please visit the experts in the Group Policy newsgroup ... Windows - Shell/User ... | applied a GPO that is supposed to allow users to use EFS on the ...
    (microsoft.public.windowsxp.security_admin)
  • Strong Password Group Policy not working
    ... I have one Windows 2003 Active Directory domain with Windows XP and Windows ... passwords according to the instructions at ... the policy is not applied to any of the workstations. ...
    (microsoft.public.win2000.active_directory)