Jump to content

EFS encryption of XP offline files


Recommended Posts

Posted

As a interim measure before replacing our staff laptops with windows 7 and bit locker, I am looking for a very quick fix for a small number of laptops which are taken off site.

 

Our my documents folder is redirected, and Off line files used to provide access to this when working with a cached account off net.

 

If I enable the GPO option to encrypt the off line files cache, are there any issues if the user does not regularly sync the machine/changes their password etc?

 

From what I can see for domain member workstations the domain administrator account should also have recovery rights to the off line files cache.

 

Have I got this right?

 

(I realise this is a very weak security measure, and files saved in the wrong place would not be encrypted, just need to put some form of fix in place while we look at the budget and workload!)

 

The impact of full disk encryption is likely to make some of these machines un-usable, and anything that extends the "time to desktop" is likely to give major problems.

 

Any suggestions?

 

Thanks

 

Robk

Posted
If I enable the GPO option to encrypt the off line files cache, are there any issues if the user does not regularly sync the machine/changes their password etc?

 

From what I can see for domain member workstations the domain administrator account should also have recovery rights to the off line files cache.

 

Have I got this right?

 

Robk

 

For you piece of mind I suggest a search on passwords, encryption and recovery thereof, as I've a vague memory of the ecryption algorythm having somewthing to do with the password hash and a change of password by an administrator ( rather than the user which IIRC re-encrypts them ) may have unwanted effects. I think the logic behind it is that if a file is encrypted and the person wants to change their password it's reasonable that they want to still see the files but if they are sensitive enough to be encrypted then it's unreasonable of them to be able to be read by someone else ( albeit an administrator ) changing the password and having access to them that way.

 

Might be best to set up a temp user account and do it with that, to be sure your system does actually behave the way you expect/want it to, just to be sure.

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...