Jump to content

Recommended Posts

Posted

It seems that a user had encrypted files on their laptop, which they helpfully copied to the server when they left. However the client machine has been re-imaged and the AD account deleted.

 

When I look at the file details (Properties\Advanced\Encryption Details) I can see that there is a recovery certificate.....but I have no idea how to use it. Please help! (I know I sound like a user!) Screen shot attached.

 

encryption details.JPG

 

And yes, I will be creating a GPO to prevent users setting up EFS before I go home tonight...

Posted

Ah... Without the recovery certificate you'll struggle to do anything, that's kinda the point of EFS.

I take it that the user didn't export the certificate anywhere?

Posted
Ah... Without the recovery certificate you'll struggle to do anything, that's kinda the point of EFS.

I take it that the user didn't export the certificate anywhere?

 

I've found a copy of the user's certificate on the server, but when I exported it, it didn't give me the option to export the private keys. Is the recovery certificate (shown in the attached picture) not the one I need?

 

Alternatively, can I recover the deleted user in AD and get access that way?

 

Thanks

Posted

Is the account listed under the recovery certificate the domain administrator account?

 

If so - you should be able to un-encrypt the files whilst logged on as that user.

Posted

The account name is shown as "administrator@domain" which is not the domain admin account.

 

When I log on as domain admin, I still can't open the documents.

I presume it's also not the local admin account from the client, as that account name would be "administrator@machine_name"?

 

I think tomorrow (I've now left site) I will go to the server and log on locally as "administrator".

 

Thanks again - will post back how I get on.

Posted
Literally administrator@domain? or administrator@The-name-of-your-domain

 

Sorry - unclear.

 

It's: administrator@our-domain-name

Posted
Will try that tomorrow - it's not an account I've ever used. I thought my "master" domain admin account would let me achieve anything that any other account can do :)
Posted
Just logged in via remote session. There is no account called administrator. I've searched AD and also run a net user command which returns "the user name could not be found". The server is a DC - from a quick Google, it appears that DCs don't have local administrator accounts. If it's not an AD account and there aren't local accounts, I'm feeling a bit stuck again....
Posted
Making progress now: I've logged in as main domain admin account, installed/enabled "certificates" snap-in and under certificates/current user/personal/certificates there is a certificate issued to "Administrator" which states it's purpose as "file recovery". Now I just need to work out how to use it...
Posted

That's the easy bit - it's just a case now of selecting the files and unticking encryption... should be that simple.

 

Let me know how you get on.

Posted
That's the easy bit - it's just a case now of selecting the files and unticking encryption... should be that simple.

 

Let me know how you get on.

 

Still failing.....

 

Logged in as the first domain admin account on the only DC in the domain, the certificate console snap-in shows the current user having the certificate matching the one listed on the file properties as the Recovery Certificate. Certificate shows as valid from the date the server was installed through to 100 years later, so should be valid for the date the file was created/modified/encrypted. I can now remove the tick (progress from yesterday), but when I press Apply, I get a prompt saying that you need provide administrator permission to proceed. When I click OK, I get an Error applying attributes" message, with the description Access is denied. No further password is requested - presumably because I'm already logged in with the highest authority possible.

 

Do I need to import the certificate somehow, or tell it what certificate to use?

 

Getting to the point where I might tell the person who wants the file that they can't have it, but very frustrated that I can't work out how to fix the problem - it seems like it should be fixable.

 

Thanks again.

Posted
What are the permissions on the files? Try taking ownership of them and then try removing the tick...

 

Thanks for the suggestion. It was shared with Administrators and Staff OUs, but I changed ownership to the domain admin account anyway. No change unfortunately - I still get the Access Denied message.

Posted

This might help: https://technet.microsoft.com/en-us/library/cc739973(v=ws.10).aspx

 

I'm getting a bit confused by what I'm reading, but Microsoft seem to imply that the original local administrator on the first DC in your domain would be the EFS recovery agent. Apparently it's possible to get access to this account by booting into safe mode on the DC using F8 - have a read through here: security - Windows - Decrypt encrypted file when user account is destroyed - Super User

  • Thanks 1
Posted

I've seen articles that mention this. I didn't install our server, but it is the only server on site and it would have been promoted to DC very early on in the install process - the date of the Recovery Certificate for "Administrator" matches the date of install. I don't fancy messing about with starting our only server in safe mode. The risk, given that I would be trying out things I've never done before, doesn't seem worth it - they're files I'd like to have, but they're not legally required archives.

 

I think I'll have a look at re-instating the deleted AD user and if that isn't straight-forward, I'll give it up. Lesson learned: either set up GPOs to prevent users using EFS or set up the recovery process properly!

 

Thank you.

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...