Re: EFS RA works on an OU but not when the same GPO is linked to the domain root




kcsteele wrote:
I created a GPO for an EFS Recovery Agent and added the appropriate
public key to the GPO. The GPO was linked to a test OU. User on a
machine in that OU encrypted some files. I was able to successfully
access the files w/ the defined Recovery Agent.

I then unlinked this GPO from the test OU and linked it to the domain
root. No longer can the Recovery Agent access files that have been
encrypted, even ones where the encryption has been updated.

I have the private key for the Recovery Agent in the Recovery Agent's
profile on the machine w/ the encrypted files. I also ran gpresult
which shows that the Recovery Agent GPO (from the domain root) has been
applied.

Anyone know why this might be happening?

Well for some reason it only worked when I added the RA to the Default
Domain Policy.

Anyone have an explanation as to why this happens?

.



Relevant Pages

  • EFS RA works on an OU but not when the same GPO is linked to the domain root
    ... I created a GPO for an EFS Recovery Agent and added the appropriate ... public key to the GPO. ... even ones where the encryption has been updated. ...
    (microsoft.public.windows.server.general)
  • Re: Co-Administrator
    ... While your steps will move towards securing from the domain admin, ... the domain admin still controls both the CA *and* GPO that sets the ... RA and can simple add another recovery agent, ... The solution of using encryption to block the administrator is to use ...
    (microsoft.public.windows.server.sbs)
  • Re: Can no longer encrypt files
    ... It is saying the certificate for the "Recovery Agent" is invalid, ... > the actual account doing the Encryption. ... > Win2k, the designated recovery agent was the default "Domain Admin", WinXP ... This was working fine until the account password expired and was ...
    (microsoft.public.windowsxp.security_admin)
  • Re: Can no longer encrypt files
    ... the actual account doing the Encryption. ... Win2k, the designated recovery agent was the default "Domain Admin", WinXP ... This was working fine until the account password expired and was ...
    (microsoft.public.windowsxp.security_admin)
  • Re: Folder Encryption
    ... Unless you are on a domain, do not use encryption. ... it is described how to create a data recovery agent, ... page 5 "Data Recovery on Standalone Machines" ... Back Up Your Encrypting File System Private Key in Windows 2000 ...
    (microsoft.public.windowsxp.security_admin)