Re: making administrator account the DRA in XP Profession



Mike Fields wrote:
"Bruce Chambers" <bchambers@xxxxxxxxxxxx> wrote in message
news:O9R%23Yv6DGHA.2292@xxxxxxxxxxxxxxxxxxxxxxx

alexm wrote:

First, I apologize; this question is rather simple, and has already

been

addressed.  But I still can't get it to work.

I encyrpt files with EFS on a user account on my standalone XP Pro
workstation.  I wish to be able to access to them from the admin

account. I

therefore wish to enable the admin account as a data recovery agent.

I have

done the following, while logged on to the admin account:
used cipher /R:filename
to generate a certificate (and private key)
used gpedit to add this certificate to the encryption policy.

However, I still cannot decrypt newly created files from the admin

account;

there seems to be another step I need to complete. Perhaps, I need

to import

the private key I created into the admin account.

Can anyone tell me what I need to do, and tell me or point me to

how?

In order to designate the Administrator as a DRA, the computer must be
part of a Domain; and even then, it is the Domain Administrator who

can

be the DRA, not the local Administrator.  This alternate access method
is unavailable on stand-alone PCs.


Bruce Chambers



From what I read, you can set the administrator (at least
that was what it looked like) as the DRA without being
part of a domain.  I tried that on mine (xp pro) and when
I view the file properties - advanced - details, it shows
both me as the key holder and the administrator as the
DRA.
http://support.microsoft.com/default.aspx?scid=kb;en-us;241201&sd=tech
http://support.microsoft.com/default.aspx?scid=kb;en-us;223316
about 1/2 way down this one is some more info:
http://www.techzonez.com/forums/archive/index.php/t-13009.html
a multi-part article on encryption and recovery agents
http://www.practicalpc.co.uk/computing/windows/xpencrypt1.htm
Here is some info from MS on "adding a recovery agent to a local
computer"  (watch the link wrap)
http://www.microsoft.com/resources/documentation/windows/xp/all/proddocs/en-us/encrypt_to_add_recovery_agent.mspx?pf=true
also look at
http://www.microsoft.com/resources/documentation/windows/xp/all/proddocs/en-us/encrypt_recovery_overview.mspx
There is also a bunch of info in the XP Resource Kit.

mikey



My mistake, then. Thanks for the correction. It would also appear that this KB Article may be pertinent:

The Local Administrator Is Not Always the Default Encrypting File System Recovery Agent
http://support.microsoft.com/kb/255026/



--

Bruce Chambers

Help us help you:
http://dts-l.org/goodpost.htm
http://www.catb.org/~esr/faqs/smart-questions.html

You can have peace. Or you can have freedom. Don't ever count on having both at once. - RAH
.




Relevant Pages

  • RE: Recovery Agent cannot recover encrypted files
    ... encryption software. ... the cipher command which added the efs_recovery user as a recovery agent. ... Logged onto the server as USER2 who is also an administrator. ... some random folder and encrypted the folder and it's contents. ...
    (microsoft.public.windows.file_system)
  • Re: Serious EFS Issue
    ... > be encrypted with no recovery agent. ... Her encryption details shows ... She receives denied because of user access privileges. ... > W3K Server environment with group policies and 2000/ XP Pro ...
    (microsoft.public.windows.server.security)
  • Re: decrypting files
    ... If you did not back-up the encryption key or the Recovery Agent and ... "Adam" wrote in message ... > my user name is the only administrator on the machine. ...
    (microsoft.public.windowsxp.security_admin)
  • Re: decrypting files
    ... Unless you had your encryption key backed up or another system on the ... network set up as the recovery agent the file is history. ... > After reloading the OS I cannot access this file anymore, ... > my user name is the only administrator on the machine. ...
    (microsoft.public.windowsxp.security_admin)
  • Cant access to encryped folder
    ... As a administrator, i did some folder & file encryption ... drive and reinstall win xp pro. ... i CANT access to my d: drive encryped files and folders. ...
    (microsoft.public.windowsxp.security_admin)

Quantcast