Re: making administrator account the DRA in XP Profession




"Bruce Chambers" <bchambers@xxxxxxxxxxxx> wrote in message
news:O9R%23Yv6DGHA.2292@xxxxxxxxxxxxxxxxxxxxxxx
> alexm wrote:
> > First, I apologize; this question is rather simple, and has already
been
> > addressed. But I still can't get it to work.
> >
> > I encyrpt files with EFS on a user account on my standalone XP Pro
> > workstation. I wish to be able to access to them from the admin
account. I
> > therefore wish to enable the admin account as a data recovery agent.
I have
> > done the following, while logged on to the admin account:
> > used cipher /R:filename
> > to generate a certificate (and private key)
> > used gpedit to add this certificate to the encryption policy.
> >
> > However, I still cannot decrypt newly created files from the admin
account;
> > there seems to be another step I need to complete. Perhaps, I need
to import
> > the private key I created into the admin account.
> >
> > Can anyone tell me what I need to do, and tell me or point me to
how?
> >
>
> In order to designate the Administrator as a DRA, the computer must be
> part of a Domain; and even then, it is the Domain Administrator who
can
> be the DRA, not the local Administrator. This alternate access method
> is unavailable on stand-alone PCs.
>
>
> Bruce Chambers
>

>From what I read, you can set the administrator (at least
that was what it looked like) as the DRA without being
part of a domain. I tried that on mine (xp pro) and when
I view the file properties - advanced - details, it shows
both me as the key holder and the administrator as the
DRA.
http://support.microsoft.com/default.aspx?scid=kb;en-us;241201&sd=tech
http://support.microsoft.com/default.aspx?scid=kb;en-us;223316
about 1/2 way down this one is some more info:
http://www.techzonez.com/forums/archive/index.php/t-13009.html
a multi-part article on encryption and recovery agents
http://www.practicalpc.co.uk/computing/windows/xpencrypt1.htm
Here is some info from MS on "adding a recovery agent to a local
computer" (watch the link wrap)
http://www.microsoft.com/resources/documentation/windows/xp/all/proddocs/en-us/encrypt_to_add_recovery_agent.mspx?pf=true
also look at
http://www.microsoft.com/resources/documentation/windows/xp/all/proddocs/en-us/encrypt_recovery_overview.mspx
There is also a bunch of info in the XP Resource Kit.

mikey

.



Relevant Pages

  • Re: DRA and access denied
    ... Windows/XP workstation that is member of the domain. ... I set up administrator as DRA before User encrypted his files. ... The actual certificate and private key is stored in the Administrator's ...
    (microsoft.public.windows.server.security)
  • Re: DRA and access denied
    ... Windows/XP workstation that is member of the domain. ... I set up administrator as DRA before User encrypted his files. ... The actual certificate and private key is stored in the Administrator's profile on the first ...
    (microsoft.public.windows.server.security)
  • Re: EFS | File Decryption
    ... The domain administrator would have to logon to the ... > private key of the Recovry Agent of the domain to decrypt user's data ?? ... He is the only DRA of the domain. ...
    (microsoft.public.security)
  • Re: Admin Priveleges Not Working
    ... SBS does use GPO. ... > changed - it is the only member of the administrator ... >>> SBS box the admin account won't add/ remove programmes ... >>> workstation I go through ...
    (microsoft.public.backoffice.smallbiz2000)
  • Re: VS2005/Vista issues
    ... ever have to explicitly run a program "as administrator" if I ... Right-click the shortcut and click on Properties. ... An Admin account doesn't prompt for a password to elevate. ...
    (microsoft.public.vc.mfc)