Re: Encrypted Folders and Upgrading to XP

From: Kerry Brown (kerry_at_kdbNOSPAMsystems.c*o*m)
Date: 04/30/05


Date: Fri, 29 Apr 2005 21:39:19 -0700


"Chuck Gibson" <Chuck Gibson@discussions.microsoft.com> wrote in message
news:1F51AA04-258F-45CA-AF42-78FEA4E6C7BE@microsoft.com...
>I just upgraded a machine to XP from 2K, and found that the encrypted
>folders
> (EFS) on the NTFS data disk are no longer accessable. The permissions on
> the
> folders are still set correctly, but I am unable to access, copy or
> disable
> encryption.
> The domain user accounts are still valid, so I am assuming this has
> something to do with the SID from the 2K install vs the new SID for the XP
> install.
> Is there any way to recover these files? (the old machine account has been
> deleted from the domain).
>
> TIA
>

EFS works differently in XP and 2K, and differently again with domain
accounts and local accounts. If there is a designated recovery agent for the
domain you may be able to use that key to unencrypt the files. See the
following link:

http://www.microsoft.com/resources/documentation/Windows/XP/all/reskit/en-us/Default.asp?url=/resources/documentation/windows/xp/all/reskit/en-us/prnb_efs_lnfx.asp

It's a long and hard to understand chapter in the docs. Basically you would
need to export the DRA certificate and key and import them on the computer
with the encrypted files. If the domain admins do not want to allow this key
to be exported (it is a major security risk) then you would have to back up
the files and they could unencrypt them on a different computer.

Kerry



Relevant Pages

  • Re: Lose ability to decrypt EFS files after reboot
    ... AV and EFS, or any type of encryption for that matter. ... After a reboot, when we attempt to read files in an directory ... This is true of local or domain accounts. ...
    (microsoft.public.security)
  • Re: Lose ability to decrypt EFS files after reboot
    ... AV and EFS, or any type of encryption for that matter. ... After a reboot, when we attempt to read files in an directory ... This is true of local or domain accounts. ...
    (microsoft.public.security)
  • Re: XP File Encryption
    ... EFS encryption is tied to the encrypting account ... Did you export any EFS keys from the old install? ... restore it and log in as the accounts with EFS ... encrypted data, using the passwords they last had, ...
    (microsoft.public.windowsxp.security_admin)
  • Re: Lose ability to decrypt EFS files after reboot
    ... EFS encrypted. ... After a reboot, when we attempt to read files in an directory ... with the encryption property set, the data is does not appear ... This is true of local or domain accounts. ...
    (microsoft.public.security)
  • RE: Protecting sensitive files on a Windows file server
    ... especially secure (using the file encryption is better though). ... Protecting sensitive files on a Windows file server ... recovery (which can also break EFS) and online password/data recovery ...
    (Security-Basics)