Enable EFS --- GPO Problem



Hi,

I've just configured a Windows server 2003 PKI in the company I'm
working for, unfortunately we are experiencing some difficulties while
trying to put it into production.

Basically, EFS is disabled by the Default Domain Policy GPO, and
another one.
I want to enable EFS on a subset of computers, so I created an OU and
applied a GPO that is supposed to allow users to use EFS on the
machines (XP SP2) located in this OU.
Unfortunately EFS is not enabled on those machines.

Group Policy Management Snap-in is telling me that the "EFS-enabling"
GPO is the last one being applied, but the Group Policy Results tool
shows that one EFS blocking GPO (not the default global policy) is
still winning, even if I enforce the EFS-Enabling GPO !

Is it due to the fact tha the Default Domain Policy is disabling EFS by
default?
Is it due to the fact that 2 GPOs are blocking EFS, while just one (the
last one being applied) is permitting it?
Does it have anything to do with GPOs applied on Domain Controllers?

I'd be happy to share your thoughts on this obscure problem...


Thanks,

Jim

.



Relevant Pages

  • Re: EFS files without recovery agent
    ... being managed by that GPO. ... actual settings differ you need to investigate if there is a problem with GP ... before to apply EFS settings and import the new RA certificate into it under ... Someone before me has configured EFS policy in "Default Domain GPO". ...
    (microsoft.public.security)
  • Re: EFS files without recovery agent
    ... Someone before me has configured EFS policy in "Default Domain GPO". ... "EFS GPO" where I created Recovery agent with proper certificate. ...
    (microsoft.public.security)
  • Re: Enabling EFS in only one OU
    ... You can disable it in a domain-wide policy, ... EFS, and link this GPO to the OU with your laptop accounts. ... Properties of Encrypting File System: ...
    (microsoft.public.windows.group_policy)
  • Re: Enable EFS --- GPO Problem
    ... Try moving the computers into another OU that is a child of the domain OU ... have your Group Policy configured correctly and it should work the way you ... GPO that you are using to enable EFS has the computer configuration settings ...
    (microsoft.public.windowsxp.security_admin)
  • Re: Enabling EFS in only one OU
    ... just a single check box for "Allow users to encrypt files using ... I enabled EFS on that GPO. ... I'll change our group policy structure so that it is ...
    (microsoft.public.windows.group_policy)