jmak Posted May 12, 2015 Posted May 12, 2015 It seems that a user had encrypted files on their laptop, which they helpfully copied to the server when they left. However the client machine has been re-imaged and the AD account deleted. When I look at the file details (Properties\Advanced\Encryption Details) I can see that there is a recovery certificate.....but I have no idea how to use it. Please help! (I know I sound like a user!) Screen shot attached. And yes, I will be creating a GPO to prevent users setting up EFS before I go home tonight...
pantscat Posted May 12, 2015 Posted May 12, 2015 Ah... Without the recovery certificate you'll struggle to do anything, that's kinda the point of EFS. I take it that the user didn't export the certificate anywhere?
jmak Posted May 12, 2015 Author Posted May 12, 2015 Ah... Without the recovery certificate you'll struggle to do anything, that's kinda the point of EFS. I take it that the user didn't export the certificate anywhere? I've found a copy of the user's certificate on the server, but when I exported it, it didn't give me the option to export the private keys. Is the recovery certificate (shown in the attached picture) not the one I need? Alternatively, can I recover the deleted user in AD and get access that way? Thanks
pantscat Posted May 13, 2015 Posted May 13, 2015 Is the account listed under the recovery certificate the domain administrator account? If so - you should be able to un-encrypt the files whilst logged on as that user.
jmak Posted May 13, 2015 Author Posted May 13, 2015 The account name is shown as "administrator@domain" which is not the domain admin account. When I log on as domain admin, I still can't open the documents. I presume it's also not the local admin account from the client, as that account name would be "administrator@machine_name"? I think tomorrow (I've now left site) I will go to the server and log on locally as "administrator". Thanks again - will post back how I get on.
pantscat Posted May 13, 2015 Posted May 13, 2015 Literally administrator@domain? or administrator@The-name-of-your-domain
jmak Posted May 13, 2015 Author Posted May 13, 2015 Literally administrator@domain? or administrator@The-name-of-your-domain Sorry - unclear. It's: administrator@our-domain-name
pantscat Posted May 13, 2015 Posted May 13, 2015 In that case the domain "administrator" account should be able to unencrypt the files. 1
jmak Posted May 13, 2015 Author Posted May 13, 2015 Will try that tomorrow - it's not an account I've ever used. I thought my "master" domain admin account would let me achieve anything that any other account can do
pantscat Posted May 13, 2015 Posted May 13, 2015 Nope... it'll be specific to the administrator account. :-)
jmak Posted May 13, 2015 Author Posted May 13, 2015 Just logged in via remote session. There is no account called administrator. I've searched AD and also run a net user command which returns "the user name could not be found". The server is a DC - from a quick Google, it appears that DCs don't have local administrator accounts. If it's not an AD account and there aren't local accounts, I'm feeling a bit stuck again....
jmak Posted May 13, 2015 Author Posted May 13, 2015 Making progress now: I've logged in as main domain admin account, installed/enabled "certificates" snap-in and under certificates/current user/personal/certificates there is a certificate issued to "Administrator" which states it's purpose as "file recovery". Now I just need to work out how to use it...
pantscat Posted May 14, 2015 Posted May 14, 2015 That's the easy bit - it's just a case now of selecting the files and unticking encryption... should be that simple. Let me know how you get on.
jmak Posted May 14, 2015 Author Posted May 14, 2015 That's the easy bit - it's just a case now of selecting the files and unticking encryption... should be that simple. Let me know how you get on. Still failing..... Logged in as the first domain admin account on the only DC in the domain, the certificate console snap-in shows the current user having the certificate matching the one listed on the file properties as the Recovery Certificate. Certificate shows as valid from the date the server was installed through to 100 years later, so should be valid for the date the file was created/modified/encrypted. I can now remove the tick (progress from yesterday), but when I press Apply, I get a prompt saying that you need provide administrator permission to proceed. When I click OK, I get an Error applying attributes" message, with the description Access is denied. No further password is requested - presumably because I'm already logged in with the highest authority possible. Do I need to import the certificate somehow, or tell it what certificate to use? Getting to the point where I might tell the person who wants the file that they can't have it, but very frustrated that I can't work out how to fix the problem - it seems like it should be fixable. Thanks again.
pantscat Posted May 14, 2015 Posted May 14, 2015 What are the permissions on the files? Try taking ownership of them and then try removing the tick...
jmak Posted May 15, 2015 Author Posted May 15, 2015 What are the permissions on the files? Try taking ownership of them and then try removing the tick... Thanks for the suggestion. It was shared with Administrators and Staff OUs, but I changed ownership to the domain admin account anyway. No change unfortunately - I still get the Access Denied message.
pantscat Posted May 15, 2015 Posted May 15, 2015 This might help: https://technet.microsoft.com/en-us/library/cc739973(v=ws.10).aspx I'm getting a bit confused by what I'm reading, but Microsoft seem to imply that the original local administrator on the first DC in your domain would be the EFS recovery agent. Apparently it's possible to get access to this account by booting into safe mode on the DC using F8 - have a read through here: security - Windows - Decrypt encrypted file when user account is destroyed - Super User 1
jmak Posted May 15, 2015 Author Posted May 15, 2015 I've seen articles that mention this. I didn't install our server, but it is the only server on site and it would have been promoted to DC very early on in the install process - the date of the Recovery Certificate for "Administrator" matches the date of install. I don't fancy messing about with starting our only server in safe mode. The risk, given that I would be trying out things I've never done before, doesn't seem worth it - they're files I'd like to have, but they're not legally required archives. I think I'll have a look at re-instating the deleted AD user and if that isn't straight-forward, I'll give it up. Lesson learned: either set up GPOs to prevent users using EFS or set up the recovery process properly! Thank you.
pantscat Posted May 15, 2015 Posted May 15, 2015 Tough lesson that one! Oh well! - have a read of these - might be useful... https://support.microsoft.com/en-us/kb/840001 Revive Deleted AD Objects - Active Directory Recycle Bin - Microsoft Windows | Windows Server 2008 content from Windows IT Pro 1
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now