Re: How to make folder private from other users?

Tech Tip: Click here to run a free scan for Windows Errors and optimize PC performance

From: Torgeir Bakken \(MVP\) (Torgeir.Bakken-spam_at_hydro.com)
Date: 08/28/04


Date: Sat, 28 Aug 2004 20:25:38 +0200

Tony wrote:

> For XP Pro (which you said you have) just encrypt the
> folder, and no one else will have access to it or it's
> files. Do this by right clicking the folder. Under
> general tab, click advanced under attributes. check the
> box that says 'encrypt...' See if this helps you.
Hi

Using encryption is overkill in many cases, and also "dangerous".

It is not without reason that many calls EFS the "delayed Recycle Bin",
and I advise people to not use EFS unless they are in a domain. Several
times a week posts cries for help in the newsgroups after having lost
their encrypted files, some even if they exported their keys/certs.
To many thing can go wrong in a non-domain environment.

 From a previous posting of mine in the
microsoft.public.windowsxp.security_admin newsgroup:

Read and understand the information in the links below before you start
using Encrypting File System (EFS), or you will very likely loose your
files one time in the future:

Best Practices for the Encrypting File System
http://support.microsoft.com/default.aspx?scid=kb;EN-US;223316

Encrypting File System in Windows XP and Windows Server 2003
http://www.microsoft.com/technet/prodtechnol/winxppro/deploy/CryptFS.asp

(58 pages, will also tell the differences between Win2k and WinXP
regarding EFS)

also gives information/links on to how to export keys, e.g.

"Data Recovery on Standalone Machines"

Under "Knowledge Base Articles on EFS" you will find e.g.

241201 How to Back Up Your Encrypting File System Private Key
259732 EFS Recovery Agent Cannot Export Private Keys
255742 Methods for Recovering Encrypted Data Files

Reading 255742, will give you this as well:

241201 HOW TO: Back Up Your Encrypting File System Private Key in
Windows 2000

242296 How to Restore an EFS Private Key for Encrypted Data Recovery

If your computer is not a member of an AD domain, this part of the
document is obligatory reading:

"Using EFS with Standalone Machines or NT 4.0 Domains"

-- 
torgeir, Microsoft MVP Scripting and WMI, Porsgrunn Norway
Administration scripting examples and an ONLINE version of
the 1328 page Scripting Guide:
http://www.microsoft.com/technet/scriptcenter/default.mspx


Relevant Pages

  • Re: Using cipher.exe to Create a DRA Certificate
    ... > it is described how to create a a data recovery agent (DRA), ... Back Up Your Encrypting File System Private Key in Windows ...
    (microsoft.public.windowsxp.security_admin)
  • Re: HELP!!! Cant open an encrypted file.
    ... Encrypting File System (EFS), or you will very likely loose your files one ... Best Practices for the Encrypting File System ... Back Up Your Encrypting File System Private Key in Windows 2000 ... 242296 How to Restore an EFS Private Key for Encrypted Data Recovery ...
    (microsoft.public.windowsxp.security_admin)
  • Re: EFS and RDA features????
    ... Best Practices for the Encrypting File System ... Under "Knowledge Base Articles on EFS" you will find e.g. ... 241201 How to Back Up Your Encrypting File System Private Key ... 242296 How to Restore an EFS Private Key for Encrypted Data Recovery ...
    (microsoft.public.windowsxp.security_admin)
  • Re: Cant use EFS: "This machine is disabled for encryption."
    ... Right-click Encrypting File System, ... File System (EFS)" check box. ... 241201 How to Back Up Your Encrypting File System Private Key ... "Using EFS with Standalone Machines or NT 4.0 Domains" ...
    (microsoft.public.windowsxp.general)
  • Re: An EFS encryption question.
    ... Can I get a link to that EFS white paper that you mentioned? ... About those smart card readers you mentioned. ... Best practices for the Encrypting File System ...
    (microsoft.public.windows.vista.security)