Re: EFS access



Zyggy wrote:
When I use EFS to encrypt data for an account in XP, I can log into
another account with admin privilages and traverse the
sub-directories of the EFS-protected parent director. Although this
other account cannot open or copy the EFS files to a different
drive/partition, it can see the names of these files, even rename
them and delete them. Is there a way to use EFS to block even the
opening of an EFS protected folder from another admin account?

No. EFS cannot do this. NTFS permissions, however, can. Of course, NTFS
permissions can be overridden by an admin. If this is a problem for you then
you probably need to start restricting admin account access to people you
actually trust.

EFS is not some kind of magical shield of super-secret protection for
confidential files, it is simply a method of encrypting files and combining
the keys for this with the account that owns the files so that the process
is transparent to the logged in user.


.



Relevant Pages

  • Re: EFS recovery problem
    ... > groups *should* _not_ effect efs. ... >>A recovery agent will only be of use if it was set up before ... >>and since changing the group memberships of an account should ... Log out of Admin, ...
    (microsoft.public.windowsxp.security_admin)
  • Re: Co-Administrator
    ... All the admin needs is one of the ... necessary steps are the designation of a data recovery agent with the EFS ... certificate/key of the administrator account. ... The EFS encrypted files are no longer readable by the Administrator or data ...
    (microsoft.public.windows.server.sbs)
  • Re: EFS recovery problem
    ... I am not sure at which point your EFS access was broken, ... A recovery agent will only be of use if it was set up before ... Since your account is now set with the same password as before, ... Log out of Admin, ...
    (microsoft.public.windowsxp.security_admin)
  • EFS recovery problem
    ... I have a Power User Account. ... Log out of Admin, ... Still no access to EFS ...
    (microsoft.public.windowsxp.security_admin)
  • Re: File attributes & access rights
    ... NTFS permissions on that folder, then it may be that it ... admin during the testing. ... > the other 3 as limited accounts. ... > I then installed a LabTec webcam (from the admin account) ...
    (microsoft.public.windowsxp.security_admin)