Problem with forcing Offline Files encryption.



I cannot get this to work through group policies.

1. A Windows XP SP2 client
2. Enabled the "encrypt the offline files cache" group policy and
applied the GP object to the OU in which the client resides.

Result is:
1. The "Encrypt offline files to secure data" option greyed out (but
unchecked).
2. The registry setting
"HKLM\Software\Policies\Microsoft\Windows\NetCache!EncryptCache" set to
one.
3. Files in c:\windows\csc are not encrypted. (I checked all the
subfolders as well.)

I can remove the group policy, use the GUI on the client to check the
box to encrypt offline files, and the files encrypt.

I can set the group policy to disabled (i.e., force offline files not
to be encrypted) but offline files remain encrypted. (Again, the
checkbox in the GUI is greyed out, but it remains checked.)

I will further note that when you use the GUI to set the offline files
to be encrypted that it sets the
"HKLM\software\Microsoft\Windows\CurrentVersion\NetCache!EncryptCache"
and this is different from the GP setting. (A custom .adm in group
policy to set this registry entry results in the registry entry, but no
encrypted offline files....)

Can anyone shed any light on this?

.



Relevant Pages

  • RE: Tired of fighting with Group Policy and Offline File Encryptio
    ... To modify the Active Directory Group Policy setting to reference the new ... Group Policy Client Side extension, use the new Client Side extension in an ... Modify the "Encrypt the Offline Files cache" Group Policy setting. ...
    (microsoft.public.windows.group_policy)
  • RE: Tired of fighting with Group Policy and Offline File Encryptio
    ... To modify the Active Directory Group Policy setting to reference the new ... Group Policy Client Side extension, use the new Client Side extension in an ... Modify the "Encrypt the Offline Files cache" Group Policy setting. ...
    (microsoft.public.windows.group_policy)
  • Re: Encrypt Offline Files - Access Denied
    ... There is a Group Policy setting to disable using EFS for offline files ... sure that any file you are trying to encrypt does not have the system ...
    (microsoft.public.windowsxp.security_admin)
  • Re: Encrypt Offline Files - Access Denied
    ... I don't use offline files but what I would try is to see if you can encrypt ... and then select encrypt this file only - NOT folder and other files in ... Be VERY VERY careful with EFS as it is not uncommon for a user to ... So, I've set up offline files for the drive, and it synchronizes fine. ...
    (microsoft.public.windowsxp.security_admin)
  • Encrypting offline files
    ... using GPO in Active Directories. ... I have set the policy. ... that is enabled in the policy is the encrypt offline files. ...
    (microsoft.public.windowsxp.security_admin)

Loading