Sorry, the FAT example was merely to illustrate that silent decryption of EFS encrypted files when moved was possible - I'm certainly not intending to make the file servers FAT based!
I had a look at the group EFS when this all began, but it's clunky and hard work - frankly unmanageable for us given the rate some of the departments add and remove temps, contractors, etc.
More over, I'd simply also like to avoid EFS encryption being used on the file server as it makes recovery by IT staff tiresome, as we have to fetch the DRA key, import, decrypt, etc and makes backups difficult.
Is there really no setting, registry key, policy object, etc, that can be set to simply deny the use of EFS on certain disks, folders, shares, etc?
Main Topics
Browse All Topics





by: mkbeanPosted on 2005-08-15 at 10:25:23ID: 14676224
This is not possible to do. When you copy an EFS file to a FAT partition it not only uses its EFS attributes but it also loses all NTFS attributes which usually is not a good idea.
Windows XP and above have a version of EFS that supports multiple users. You have to have a key for all the users that you want to view the encrypted files though.
Brian