Solved

EFS encryption via GPO on XP laptops

Posted on 2013-05-20
1
588 Views
Last Modified: 2013-05-21
Need to encrypt 50 laptops including offline files cache, my documents, outlook and desktop.
Created a GPO which is working and encrypts the offline files cache. Created a login script which does not seem to be working:

cipher /e /s /a "%userprofile%\My Documents"

cipher /e /s /a "%userprofile%\Application Data\Microsoft\Outlook"

cipher /e /s /a "%userprofile%\Desktop"

And I need a password either on the folders (preferable) or at bootup which I can control.
Encryption is basically Greek to me. Need help.
0
Comment
Question by:sandbagger2u
1 Comment
 
LVL 38

Accepted Solution

by:
Rich Rumble earned 500 total points
ID: 39183311
What are you protecting the data from? If your worried about a LT being stolen and someone getting into these files, then you probably want full disk encryption wich EFS can't do. If your worried about someone gaining access to these files while the system is on you may want to try to get EFS going, but you can get to EFS data using PassWare or AEFSDR from Elcomsoft, both are very capable recovery programs. If the LT is off and is stolen, EFS won't protect you, because an attacker can use AEFSDR or PassWare, but if the disk is fully encrypted then they can't. I'd suggest TrueCrypt, FreeOTFE, PGP and possibly Microsofts Bitlocker, but bitlocker is not available for XP.
This may help with your current attempts:
http://support.microsoft.com/kb/810859
http://technet.microsoft.com/en-us/library/ee449438%28v=ws.10%29.aspx
http://www.truecrypt.org/faq (no backdoor's for TC, but EFS has MANY)
-rich
-rich
0

Featured Post

Why won’t your email signature format correctly?

Struggling to get your corporate email signatures to format correctly? Does the logo keep resizing? Is the text appearing too big? What can you do to prevent this? Find out how you can save your signatures today.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Suggested Solutions

Several part series to implement Internet Explorer 11 Enterprise Mode
Storage devices are generally used to save the data or sometime transfer the data from one computer system to another system. However, sometimes user accidentally erased their important data from the Storage devices. Users have to know how data reco…
As developers, we are not limited to the functions provided by the VBA language. In addition, we can call the functions that are part of the Windows operating system. These functions are part of the Windows API (Application Programming Interface). U…
With the advent of Windows 10, Microsoft is pushing a Get Windows 10 icon into the notification area (system tray) of qualifying computers. There are many reasons for wanting to remove this icon. This two-part Experts Exchange video Micro Tutorial s…

910 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

16 Experts available now in Live!

Get 1:1 Help Now