Re: EFS Access



Mark St. Laurent wrote:
Is there any way to set up EFS so that only users granted specific rights can
access the encrypted files, including system administrators? And, if the
rights were set up in this way, would the Backup Operators group still be
able to access the files to back them up?

The whole point of EFS is that only selected users can read the content
of the file, and that not even system administrators can "get" to the
content; the only exception is the recovery agent, if a recovery agent
is installed.

EFS only protects the content of the file, other operations, such as
listing file attributes, renaming or removing the file are not protected
by EFS.

As a special case, the Backup Operators can open the file *for backup*.
They will be able to backup the file, but still not find out what the
content is, i.e. they will backup the encrypted data as-is. This
requires that the backup program being used indeed opens the file
*for backup*; if a backup operator tries to open the file in the
regular way, they still cannot get to the content.

Regards,
Martin
.



Relevant Pages

  • Re: MSKB 891957, VSS Update for Windows Server 2003
    ... These are some RDP config suggestions which may help... ... Are you able to ping the server by ip or name during a dropout? ... I will use RDP to create a user Backup login and see if the next ... I can run an error free backup with a Backup Operators group account as ...
    (microsoft.public.windows.server.general)
  • Re: MSKB 891957, VSS Update for Windows Server 2003
    ... FTP server also resolved the flaky RDP connections to it. ... I left the server with user Backup logged in when I left the ... I will check tomorrow if the VSS error appeared in Event ... I can run an error free backup with a Backup Operators group account as ...
    (microsoft.public.windows.server.general)
  • Re: MSKB 891957, VSS Update for Windows Server 2003
    ... So I spent some time the last couple of days trying to break my test server ... I can run an error free backup with a Backup Operators group account as long ... no VSS errors were logged. ...
    (microsoft.public.windows.server.general)
  • Re: MSKB 891957, VSS Update for Windows Server 2003
    ... I left the server with user Backup logged in when I left the ... These are some RDP config suggestions which may help... ... I can run an error free backup with a Backup Operators group account as ...
    (microsoft.public.windows.server.general)
  • Re: MSKB 891957, VSS Update for Windows Server 2003
    ... Scratch that RDP fix! ... RDP into the old Windows 2000 Server server worked great. ... I will use RDP to create a user Backup login and see if the next ... I can run an error free backup with a Backup Operators group account as long ...
    (microsoft.public.windows.server.general)

Loading