Re: EFS Encrypt User Profile



Glenn wrote:
> What thoughts do people have on efs encrypting the documents and
> settings root so that all new user profiles are EFS encryped . Is this
> feasible/reliable?
>
> Thanks
>
> Glenn

There are many perils in using efs. Why would you want to encrypt everyone's
documents? I would only consider this in an active directory environment
where you can more easily set up a recovery agent. Anyone who uses efs
sooner or later loses data due to it. Make sure you have a good backup
strategy. Make sure you have a recovery agent set up. Make sure you export
all user efs keys and the recovery agent efs key. Something as simple as
user forgetting their password can cause data loss.

Most importantly read everything you can find on efs. Make sure you test and
understand how to recover efs files when a user profile gets lost,
corrupted, changed, etc. Test and retest many times before implementing it.
Here is a starting point for reading:

http://www.microsoft.com/technet/security/topics/cryptographyetc/efs.mspx

http://www.microsoft.com/technet/prodtechnol/winxppro/deploy/cryptfs.mspx

http://support.microsoft.com/?kbid=241201

Personally I would not recommend doing this. If you really need user's
documents to be secure then ntfs permissions and enforcing that they be
stored on a physically secure server is a better idea. If the users are
using laptops then look at 3rd party encryption solutions. Be aware that if
the encryption is any good there is always the danger of data loss. The
whole point of encryption is to make the data hard to get at.

Kerry


.



Relevant Pages

  • Re: Question, how do I decrypt data files without encryption key?
    ... Next time, I will avoid EFS ... the EFS decrypy key must be located in a hidden file ... how do I decrypt data files without encryption ... as well not having created a Recovery Agent (with ...
    (microsoft.public.win2000.security)
  • Re: decrypt my encrypted files
    ... If you use EFS, and since you are the admin of your own host, you are expected to read ALL the help articles in the included help regarding EFS. ... You then import that EFS certificate so the files that were encrypted using it can be decrypted using that same certificate. ... You can also designate another recovery agent to recreate the EFS cert for you, but you probably didn't do that, either. ... There is no backdoor to EFS if you don't have the cert to import or a recovery agent and there is no backdoor to TrueCrypt's password encryption. ...
    (microsoft.public.windowsxp.security_admin)
  • RE: Protecting sensitive files on a Windows file server
    ... especially secure (using the file encryption is better though). ... Protecting sensitive files on a Windows file server ... recovery (which can also break EFS) and online password/data recovery ...
    (Security-Basics)
  • Re: EFS Private Keys
    ... It's possible to have a cluster that was in use that couldn't be wiped. ... > syskey was to EFS in W2K, ... >>> the private keys are protected however the key to the private key is ... >>> stronger encryption available for EFSfiles permanently if you don't. ...
    (microsoft.public.win2000.security)
  • Re: EFS Private Keys
    ... > The user and recovery agent private EFS keys are stored in the associated ... > the private keys are protected however the key to the private key is the ... > stronger encryption available for EFS. ...
    (microsoft.public.win2000.security)