Re: EFS



http://www.microsoft.com/resources/documentation/Windows/XP/all/reskit/en-us/Default.asp?url=/resources/documentation/windows/xp/all/reskit/en-us/prnb_efs_lnfx.asp

Efs is very complicated. Even if the domain admin is not the recovery agent
they could access your files by using the recovery agents certificate or by
logging in as the recovery agent. If you are trying to hide something from
the domain admin it impossible unles you only keep the file on removable
storage, i.e a floppy, CDRW, USB drive etc.. If you are the doamin admins
supervisor and you need to keep files from them you should look at how the
permissions are delegated and possibly reduce that person's permissions.
With Windows server (and most any other server OS's) you have to trust
someone with ultimate power to do anything they like on the network.

Kerry


"Lynn" <MarryLynn@xxxxxxxxx> wrote in message
news:%236TOTo9rFHA.2540@xxxxxxxxxxxxxxxxxxxxxxx
> is there a way to check what is the designated recovery agent ?
>
> "Kerry Brown" <kerry@xxxxxxxxxxxxxxxxxxx*a*m> wrote in message
> news:eOkDH%238rFHA.1788@xxxxxxxxxxxxxxxxxxxxxxx
>> "Lynn" <MarryLynn@xxxxxxxxx> wrote in message
>> news:uyRzC27rFHA.3216@xxxxxxxxxxxxxxxxxxxxxxx
>> > Hi,
>> > will the domain administrator able to decrypt and view my files even if
> i
>> > encrypt it with EFS ?
>> > thanks
>> >
>> >
>>
>> In most cases the answer is yes. The domain administrator is the default
>> recovery agent. This may have been changed. In any case in a domain
>> environment there is a designated recovery agent who could decrypt the
>> files.
>>
>> Kerry
>>
>>
>
>


.



Relevant Pages

  • Re: EFS: Almost all files are encrypted?! How did this happen?
    ... | Okay, I don't know a lot about EFS, so bear with me... ... | contractor is listed as a recovery agent. ... That contractor has domain admin ... Each individual will create their own Security Certificate that is used to ...
    (microsoft.public.windowsxp.security_admin)
  • Re: recovery agent keys/certs
    ... To decrypt a file two things are needed a) read permissions ... Create the recovery agent before users encrypt files so that you ... Backing up EFS certificates will allow for later ...
    (microsoft.public.windowsxp.security_admin)
  • RE: Laptop Security - Microsoft EFS
    ... When you use EFS, ... who can also decrypt the respective persons info. ... If the private key for the recovery agent sits on the very computer you are ... trying to protect, then you may as well not encrypt anything, because it's ...
    (Security-Basics)
  • Re: Decrypting files without key or DRA after restoring Windows XP crash
    ... If you did not back-up the encryption key or the Recovery Agent and ... EFS is very good at what it does and there is no back door. ... > had not generated the key to decrypt them nor assigning DRA ... > (data recovery agent) as I had not prior knowledge of these ...
    (microsoft.public.windowsxp.security_admin)
  • Re: EFS and Biometrics? Other options?
    ... There is no password involved in EFS. ... specified recovery agent and available keys. ... To decrypt the file, the machine must be able to access either the user's ... the private key that corresponds to the public key that was used to encrypt ...
    (Focus-Microsoft)