robk Posted November 24, 2009 Posted November 24, 2009 As a interim measure before replacing our staff laptops with windows 7 and bit locker, I am looking for a very quick fix for a small number of laptops which are taken off site. Our my documents folder is redirected, and Off line files used to provide access to this when working with a cached account off net. If I enable the GPO option to encrypt the off line files cache, are there any issues if the user does not regularly sync the machine/changes their password etc? From what I can see for domain member workstations the domain administrator account should also have recovery rights to the off line files cache. Have I got this right? (I realise this is a very weak security measure, and files saved in the wrong place would not be encrypted, just need to put some form of fix in place while we look at the budget and workload!) The impact of full disk encryption is likely to make some of these machines un-usable, and anything that extends the "time to desktop" is likely to give major problems. Any suggestions? Thanks Robk
glensc Posted November 24, 2009 Posted November 24, 2009 If I enable the GPO option to encrypt the off line files cache, are there any issues if the user does not regularly sync the machine/changes their password etc? From what I can see for domain member workstations the domain administrator account should also have recovery rights to the off line files cache. Have I got this right? Robk For you piece of mind I suggest a search on passwords, encryption and recovery thereof, as I've a vague memory of the ecryption algorythm having somewthing to do with the password hash and a change of password by an administrator ( rather than the user which IIRC re-encrypts them ) may have unwanted effects. I think the logic behind it is that if a file is encrypted and the person wants to change their password it's reasonable that they want to still see the files but if they are sensitive enough to be encrypted then it's unreasonable of them to be able to be read by someone else ( albeit an administrator ) changing the password and having access to them that way. Might be best to set up a temp user account and do it with that, to be sure your system does actually behave the way you expect/want it to, just to be sure.
box_l Posted November 25, 2009 Posted November 25, 2009 The "Encrypt the Offline Files cache" Group Policy setting does not take effect when a user logs on to a Windows XP-based computer You users would have to local admins for this to work correctly, not something we ever allow. truecrypt full disk encryption does not slow "time to desktop" that much, and you know they a fully secure. HTH BoX
robk Posted November 25, 2009 Author Posted November 25, 2009 The "Encrypt the Offline Files cache" Group Policy setting does not take effect when a user logs on to a Windows XP-based computer You users would have to local admins for this to work correctly, not something we ever allow. Doh! Yes that blows that idea out of the water. Thanks for confirming that. Robk
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now