Re: EFS access




Zyggy wrote:
When I use EFS to encrypt data for an account in XP, I can log into another
account with admin privilages and traverse the sub-directories of the
EFS-protected parent director. Although this other account cannot open or
copy the EFS files to a different drive/partition, it can see the names of
these files, even rename them and delete them. Is there a way to use EFS to
block even the opening of an EFS protected folder from another admin
account?

I have an XP Pro machine that has a few users, all of whom are
administrators. I use the default build-in Administrator account to fix
problems and manage this machine. I use EFS to encrypt all the data created
with these other accounts. I do not want any of these users to be able even
to see the file names of the files created by the others. In fact, I don't
even want myself to be able to see this. In other words, I do not want any
backdoor to the files stored in EFS-encrypted folders, not even the ability
to open the folder to see what files are stored in it.

Sorry, you can't. Try a program like PGP if it's urgent.

.



Relevant Pages

  • Re: EFS recovery problem
    ... > groups *should* _not_ effect efs. ... >>A recovery agent will only be of use if it was set up before ... >>and since changing the group memberships of an account should ... Log out of Admin, ...
    (microsoft.public.windowsxp.security_admin)
  • Re: EFS Disabling
    ... > I had to reinstall XP on a computer and so I copied my EFS ... Each time you create a user account, a new SID gets ... instances of Windows NT/2000/XP. ... in your profile directory. ...
    (microsoft.public.security)
  • Re: EFS recovery problem
    ... I should have studied EFS ... Dave User cert, I get "Access Denied". ... especially now since my account name is Dave for some reason. ... export the Dave User certificate (in *.p7b ...
    (microsoft.public.windowsxp.security_admin)
  • Re: EFS recovery problem
    ... this seems to break efs as it does not update the locking ... some files are missing - for each cert in mmc, ... >especially now since my account name is Dave for some reason. ... export the Dave User certificate ...
    (microsoft.public.windowsxp.security_admin)
  • Re: Password Protecting/Hiding Files & Folders on Windows 2003 server???
    ... First, to be clear, EFS allows for one account (inital encryptor) to ... Auditing can be very verbose. ...
    (microsoft.public.win2000.security)