Home > Ask the Windows Experts > Questions & Answers > Encrypting folders for Win2k laptops
Ask The Win IT Expert: Questions & Answers
EMAIL THIS

Encrypting folders for Win2k laptops

William  Boswell EXPERT RESPONSE FROM: William Boswell

Pose a Question
Other Win IT Categories
Meet all Win IT Experts
Become an Expert for this site


Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us   


>
QUESTION POSED ON: 22 March 2001
Am I correct in thinking that if we implement the right group policy and make use of a certified key we can recover encrypted data by specifying certain recovery agents. How do we do this for our directors who have laptops with sensitive information on them and who require encrypted folders but are not always connected to the domain?

>

You can have a central set of Data Recovery Agents that are used by laptops even when they are not connected to the network.

Be sure to have your laptop users log onto the domain even when they are on the road. The logon will pause a few seconds then proceed with cached credentials. The public key of the domain DRA is stored in the Registry. Because the user logged onto the domain (from the perspective of Winlogon), EFS running under the user's security context can access the domain DRA key.

It's very, very important that the users don't log onto their local desktop SAM rather than the domain. If they do, then the local Admin account on the Pro desktop will become the DRA for their encrypted files. Also, the password hash from their local SAM account will be used to encrypt the master Crypto key used to encrypt the user's private EFS key. When the user comes back to the office and logs onto the domain, they will not be able to open the files they encrypted while they were logged onto the local SAM.

Even worse, if a bad guy steals the laptop, it's a trivial process to change the local Admin password and use that account to open the encrypted files. File encryption is only secure when the laptop is a member of a domain and the user logs onto the domain account.


Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us   



RELATED RESOURCES
2020software.com, trial software downloads for accounting software, ERP software, CRM software and business software systems
Search Bitpipe.com for the latest white papers and business webcasts
Whatis.com, the online computer dictionary



Search and Browse the Expert Answer Center
Search and browse more than 25,000 question and answer pairs from more than 250 TechTarget industry experts.
Browse our Expert Advice



Windows IT White Papers including Change Management, Cost Management and Problem Management
HomeNewsTopicsITKnowledge ExchangeTipsAsk the ExpertsMultimediaWhite PapersIT Downloads
About Us  |  Contact Us  |  For Advertisers  |  For Business Partners  |  Site Index  |  RSS
SEARCH 
TechTarget provides technology professionals with the information they need to perform their jobs - from developing strategy, to making cost-effective purchase decisions and managing their organizations' technology projects - with its network of technology-specific websites, events and online magazines.

TechTarget Corporate Web Site  |  Media Kits  |  Site Map




All Rights Reserved, Copyright 1999 - 2009, TechTarget | Read our Privacy Policy
  TechTarget - The IT Media ROI Experts