Using EFS

EFS must have a recovery agent available before a file can be encrypted. In a default installation, the recovery agent is always available, but it can be disabled; in that case you get an error message indicating the operation cannot happen. Later in this section, you will see how to disable EFS, enable EFS, and back up recovery agent's certificate.

You cannot encrypt system files or folders; an error message indicates access denied. You can ignore the message or just cancel; it is better to cancel the operation because you do not want to accidentally encrypt any file needed for boot (the boot code, hal, kernel, drivers, services, and dependencies). At boot time, there is no impersonation process and boot files cannot be decrypted. ...

Get Microsoft® Windows® 2000 Security Handbook now with the O’Reilly learning platform.

O’Reilly members experience books, live events, courses curated by job role, and more from O’Reilly and nearly 200 top publishers.