Microsoft KB Archive/221997

= Cannot Gain Access to Previously Encrypted Files on Windows 2000 =

Article ID: 221997

Article Last Modified on 10/30/2006

-

APPLIES TO


 * Microsoft Windows 2000 Server
 * Microsoft Windows 2000 Professional Edition

-



This article was previously published under Q221997



SUMMARY
When you join a domain and log on with a domain account, you may not be able to gain access to files previously encrypted with the Encrypting File Service (EFS).

To gain access to files encrypted under a local user context, you must log on with that local account and then decrypt the files.



MORE INFORMATION
Windows 2000 includes the ability encrypt files and folders with a new, CryptoAPI-based service known as EFS. Files and folders that have been configured to use EFS are completely undecipherable except to the user who originally encrypted them.

Folders themselves are not encrypted, but are marked so that files created in them will be encrypted. The user who created the file might not be the only user who can decrypt the file. All recovery agents can also decrypt the file.

NOTE: You can import keys. It is possible for a local account to import the key of a domain account and have access.

Keywords: kbinfo KB221997

-

[mailto:TECHNET@MICROSOFT.COM Send feedback to Microsoft]

© Microsoft Corporation. All rights reserved.