Re: Re: EFS Issue

From: Mouse4440 (DoNotEmail_at_WindowsForumz.com)
Date: 04/29/05


Date: 29 Apr 2005 09:34:10 -0500


"Jupiter Jones MVP" wrote:
> Was there a Designated Recovery Agent on the domain?
> If not, the data is most likely gone for good.
>
> See the bottom of this page for ways to help prevent data loss
> with EFS in
> the future:
> http://www3.telus.net/dandemar/encrypt.htm
>
> --
> Jupiter Jones [MVP]
> http://www3.telus.net/dandemar
> In memory of our dear friend, MVP Alex Nichol
> http://www.dts-l.org
>
>
> "Mouse4440" <UseLinkToEmail@WindowsForumz.com> wrote in
> message
> news:3_1177687_c7f35c781fba764475392afee945baeb@windowsforumz.com...
> > Recently I used RIS (Remote Installation Service) to
> reinstall a
> > clients workstation because it had been upgraded and had
> different
> > versions of Office installed and just generally had issues,
> but what I
> > didn't know is that the user had Encrypted files on another
> drive (USB
> > External Hard Drive) so after I reinstalled the OS the
> Computer
> > account is not the same as before and he can no longer
> access the
> > files that were on the other drive. I have tried several of
> the free
> > downloadable recovery packages Advanced EFS recovery and
> others but
> > have had no luck, the recovery agent displays that no user
> is able to
> > decrypt the files and the user account has not changed
> because the
> > user is in a domain. I have tried logging in as local admin,
> domain
> > admin, but still no luck. anyone know of anything I can do.
> and no
> > the user didn't export the keys.
> >
> > --
> > Posted using the http://www.windowsforumz.com interface, at author's
> > request
> > Articles individually checked for conformance to usenet
> standards
> > Topic URL:
> > http://www.windowsforumz.com/Security-Admin-EFS-Issue-ftopict365344.html
> > Visit Topic URL to contact author (reg. req'd). Report
> abuse:
> > http://www.windowsforumz.com/eform.php?p=1177687

I’m not sure, I logged in as admin on the local machine and as the
domain admin and the windows recovery thing display no recovery agent
present. is this something that user had to setup or is an automatic
thing?

 Posted Via Usenet.com Premium Usenet Newsgroup Services
----------------------------------------------------------
    ** SPEED ** RETENTION ** COMPLETION ** ANONYMITY **
----------------------------------------------------------
                http://www.usenet.com



Relevant Pages

  • Re: Securing Data from Administrators
    ... EFS file can be shared by users but even this does not guarantee ... A domain admin could easily create a Recovery Agent to give ... allow users needed access to that server. ...
    (microsoft.public.windows.server.security)
  • Re: EFS
    ... Efs is very complicated. ... Even if the domain admin is not the recovery agent ... >> environment there is a designated recovery agent who could decrypt the ...
    (microsoft.public.windowsxp.help_and_support)
  • Re: Restrict User account creation
    ... Has anyone found a way to restrict a Domain Admin member from creating new ... Encryption Recovery Agent. ...
    (microsoft.public.windows.server.active_directory)
  • Re: EFS
    ... is there a way to check what is the designated recovery agent? ... The domain administrator is the default ... > environment there is a designated recovery agent who could decrypt the ...
    (microsoft.public.windowsxp.help_and_support)
  • encrypted file
    ... someone encrypted a file on there computer in the domain, is the domain admin ... setup by default to be the recovery agent or is there something i have to ... Prev by Date: ...
    (microsoft.public.windows.server.active_directory)