Skip to content
EntityQ1088609· pop 18· linked from 668 articles

Encrypting File System

Sign in to save

Also known as EFS

feature in Microsoft Windows

Described at

Encrypting File System | Microsoft Learn

technet.microsoft.com

Encrypting File System (EFS) is a powerful tool for encrypting files and folders on client computers and remote file servers. It enables users to protect their data from unauthorized access by other users or external attackers. EFS is useful for user-level file and folder encryption. EFS was first introduced in the Microsoft® Windows® 2000 operating system, and has been enhanced in subsequent releases of the operating system. Administrators, IT security professionals, and compliance officers who are tasked with ensuring that confidential data is not disclosed without authorization. Administrators responsible for servers or Windows Vista® client computers that are portable. Before implementing EFS, administrators should plan for recovery of information in the event that keys or certificates are lost. EFS supports a robust recovery mechanism which includes three major changes in this release of Windows: Data Recovery Agent (DRA) can now be on a smartcard, which eliminates the need for an offline recovery station and makes remote recovery possible. The ntbackup tool is no longer included in the operating system. Instead, the Robocopy utility has been added to Windows Server® 2008 and can copy EFS-encrypted files without needing the decryption key. (Copies made in this way will remain encrypted.) Windows Backup supports backup of EFS files in Windows Server 2008. All of these changes can significantly change the deployment plan for EFS. Several important enhancements to EFS are provided in Windows Server® 2008. These include the ability to store encryption certificates on smart cards, per-user encryption of files in the client side cache, additional Group Policy options, and a new rekeying wizard. EFS encryption keys and certificates can be stored on smart cards, providing stronger protection for the encryption keys. This can be especially valuable to help protect portable computers or shared workstations. Using smart cards to store encryption keys may also provide ways to improve key management in large enterprises. Using a smart card to store the EFS keys keeps those keys off of the hard disk of the computer. This increases the security of those keys because they cannot be attacked by another user or by someone who steals the computer. In Windows Server 2008 and Windows Vista, EFS supports the storage of users’ private keys on smart cards. Using Group Policy settings, you can configure EFS to store private keys on smart cards in non-cached or cached mode. Non-cached mode . Similar to the traditional way EFS works, all decryption operations requiring the user’s private key are performed on the smart card. Cached mode . A symmetric key is derived from the user’s private key and cached in protected memory. Encryption and decryption operations involving the user’s key are then replaced with the corresponding symmetric cryptographic operations by using this derived key. This eliminates the need to keep the smart card plugged in at all times or to use the smart card processor for every decryption. It therefore provides a significant increase in performance. EFS also provides policies to enforce “smart card required” and to control the parameters and caching behavior of users’ keys. The user does not have a valid EFS encryption key on the computer, and smart cards are required for EFS by policy settings. The user has a valid EFS encryption key that resides on the smart card used for logon. When SSO is triggered, EFS caches the personal identification number (PIN) entered by the user at logon and uses it for EFS operations as well. Thus the user does not see any PIN prompts from EFS during the session. If the smart card used for the logon is removed from the smart card reader before any encryption operations are performed, Single Sign On is disabled. The user will be prompted for a smart card and PIN at the first EFS operation. To prepare to use smart cards to store EFS certificates, you should examine your existing

Excerpt from a page describing this subject · 18,263 chars · not written by Vinony

Wikidata facts

Show 2 more facts
short name
EFS
Sources (2)

via Wikidata · CC0

Connections

Categories