Encrypted File System



Hi,

i run a sbs2k3 server and i have a folder that needs to be secured
from the administrator,but acessable to the other users.so after some
research i ve found out that i could use the encrypted file system to
encrypt the folder and files.it would block the access to the
admin,but still he would be the default recovery agent within the
domain.

so i figued out that i would create another admin account to perform
all the regular tasks/backups and use the domain admin just for
recovery purposes.

i would also like to know if would help to create a new account and
give itself admin privleges to perform the routine tasks and
backups,instead of using the domain admin account?

what permissions or groups should i assign the new account so that it
has all the admin access except for the efs key recovery?

after i encrypt a folder and when i try to share the files within the
folder by adding users i recieve an message like this "no appropriate
certificates correspond to the user" how do i get the certificates for
the users that i want to let access?

i would also like to know ,if shadow copies enabled on the
server ,would retain the previous version of the folder/files?

what other things should i be aware before deploying the EFS.

Thank You.
.



Relevant Pages

  • Re: PF Admin tool & Administrative Rights
    ... Path in that server!! ... Actually I am testing with our lab server and the Ex admin path is ... I successfully received full information from the folder (size, ... If I add the same account as client member as owner, ...
    (microsoft.public.exchange2000.development)
  • Re: ghost account - files still there, but PC wont let me access
    ... You should be able to "take ownership" of the old admin folder to give you ... it gives me the old error message you see above. ... message) I should be able to log on to my old admin account and retrieve ...
    (microsoft.public.windowsxp.help_and_support)
  • Re: Stashing Temp Files Under Documents and SettingsAll Users?
    ... I just use the folder where the MDE resides. ... the Windows and Program Files folders) -- ... running as admin. ... install your Access front ends in user-writable storage space. ...
    (comp.databases.ms-access)
  • Re: Exclude 1 user from Folder Redirection
    ... Move the admin account to another OU with none policies applied except the domain policy. ... Basically your administrators should have a normal user account and a domain admin, which is used only for administrative tasks. ... Setup Desktop Folder Redirection in GPO. ... desktop files are saved in the same folder AND the files from Server1 ...
    (microsoft.public.windows.server.general)
  • Re: Program requires admin rights
    ... > We have a program that requires admin rights to run correctly. ... The vendor is ... Start Menu folder and Desktop folder shortcuts from the user profile ... limited accounts, you can fix it to allow limited users to access the ...
    (microsoft.public.windowsxp.general)

Loading