EFS Recovery Agent not working on Windows 8.1

I know EFS data recovery has been discussed so many times in the forums but I could not find anything useful in the other threads as I believe I have followed all the required steps but still cannot get EFS recovery agent to work.
I have a Client1 (Win 8.1) and a DC1 (Windows Server 2012 R2) under beta.com domain.
DC1 is a CA server as well as a domain controller.
I logged into DC1 as beta.com\Administrator
which is the Domain Administrator account.
I duplicated the EFS Recovery Agent template on the
DC1 and published it into Active Directory.
Then I edited the Default Domain Policy GPO and under
Computer Settings\Policies\Windows Settings\Security Settings\Public Key Policies
I right clicked Encrypting File System and selected Create a Data Recovery Agent
and a new file recovery certificate was generated for the Administrator account.
I exported the newly-created Recovery Agent certificate and then logged into
Client1 as beta.com\Administrator and imported
it.
I then logged off from Client1 and logged back in using a different account beta.com\johns
and encrypted a folder (with a text file inside) using EFS. (The folder address on local disk is
C:\Reports)
Then I logged back into Client1 again using beta.com\Administrator
but I am unable to open the file inside the folder and I get an
Access is denied message.
It is very strange to get an "Access is denied" message because on the text file when I right click and click Properties -> Advanced -> Details, under the Recovery Certificates, the Administrator account's certificate is listed
and its thumbprint corresponds to the same recovery certificate which I created in step 3. But I am still unable to access the file.
Do you have any idea why? Am I missing something?
Thanks in advance.
MCT, MCSA/MCSE Security
http://esitech.spaces.live.com/

Hi
The Client1 user needs to enrol via GPO to get the recovery certificate normally via automatic enrolment
Check the Personal Certificate store for Client1
I think the policy needs to be applied before you encrypt any data
To manually recover
Did you export the Private key when you did the export ?
Did you export to a .cer file

Similar Messages

  • Nac Agent Not Working on Windows 64 Bit

                       Hi All ,
    I have a Cisco ISE 3315 With Version 1.1.4 .
    We have Windows Work Station and we have some issue with Windows 7 64 Bit users !!
    On Some 64 Bit Workstation the nac Agent is getting about 25 Minute to start Checking the Posture Statu !!
    I don't Havec that Proble With 32 Bit Workstation . We are using Nac Agent 4.9.0.37 and Nac agent 4.9.0.42!!
    Here is log that i get From the 64 bit Workstation

    Hi
    Verify that supplicant is configured properly to conduct a full EAP conversation with ISE. Verify that NAS is configured properly to transfer EAP messages to or from supplicant. Verify that supplicant or network access server (NAS) does not have a short timeout for EAP conversations. Check the network that connects the NAS to ISE. If the external ID store is used for the authentication, it may be not responding fast enough for current timeouts.
    Check whether the proper server certificate is installed and configured for EAP by going to the Local Certificates page (Administration > System > Certificates > Local Certificates ). Also ensure that the certificate authority that signed this server certificate is correctly installed in client's supplicant.
    Check the previous steps in the log for this EAP-TLS conversation for a message indicating why the handshake failed. Check OpenSSLErrorMessage and OpenSSLErrorStack for more information

  • EFS recovery agent

    Hello Geeks,
    In windows 2012R2 CA , I duplicated recovery efs agent template , then in security tab added my agent and grant enroll and autoenroll,
    in properties of CA server , added the recovery agent,
    but in gpmc , when I want to add my agent to recovery agent , it shows me that no certificate available!!!!!!
    please someone help me??
    thanks in advance

    I think you are confusing Key Recovery and Data Recovery agents:
    In the properties of the CA in certsrv.msc you add a KRA (you change a registry key at the CA after you read KRA's certificates from an object on config. container). This will allow storing users' private keys in the CA DB - it can be used as an alternative
    to DRAs but it is unrelated to the DRAs in the GPO.
    In order to add the DRAs to a GPO their certificates need to be published the agent users' objects in AD (option Publish certificate to AD needs to be selected in the template) or you need to have the certificates as files. I would prefer the latter not
    to complicate things now. So if you have issued proper EFS Recovery certificates
    export their certificates from the CA DB (Issued Certificates) or from those agents' personal stores as CRT files and import them to the GPO.
    But make sure that these are really EFS Data Recovery certificates and not Key Recovery certificates, otherwise data recovery will not work. The extended key usage should include File Recovery.
    Elke

  • CaptureDeviceManager.getDeviceList  is not working in Windows VISTA.When

    CaptureDeviceManager.getDeviceList is not working in Windows VISTA.When I run the Application from vista using a jar file.But it is running if i run it from class file without use the jar file.

    This pretty much says it all:
    No connection could be made because the target machine actively refused it.What version of Vista?
    What version of the agent? ... 10g is not a version number it is a marketing label
    Did you check to see if the agent is compatible with your operating system?
    My recommendation would be to get a real operating system: Either Oracle Linux or XP.

  • HP Pavilion dv6-6181TX. System Recovery is not working From HP Recovery Manager.

    HP Pavilion dv6-6181TX
    Product No. A3U49PA
    Genuine Windows 7 Home Premium 64
    (but i upgraded it to windows 7 ultimate)
    System Recovery is not working From HP Recovery Manager. so i cant restore my laptop to its original factory condition. (Genuine Windows 7 Home Premium).
    so when i restart my computer and press Esc and then choose F11 i get this message :
    "Windows failed to start. A recent hardware or software change might be the
    cause. To fix the problem:
    1. Insert your Windows installation disc and restart your computer.
    2. Choose your language settings, and then click "Next."
    3. Click "Repair your computer."
    If you do not have this disc, contact your system administrator or computer
    manufacturer for assistance.
    File: \Boot\BCD
    Status: 0xc0000225
    Info: An error occured while attempting to read the boot configuration data."
    i saw this from the forum
    http://h30434.www3.hp.com/t5/Notebook-Recovery/Hp-recovery-manager-problems/m-p/2395473/highlight/tr...
    Had the C partition been split/shrunk to form a new partition previously?
    Does disk management show the HDD as basic or dynamic? (Start>Right-click Computer>Manage>disk management on the left).
    If it has been switched to dynamic (Windows does this automatically when more than 4 partitions are present on the disk), then the F11 recovery partition won't function until it is restored to basic, but I would like to confirm that is the scenario before providing those steps.
    The Disk management shows that my HDD as Dynamic, what should i do then if this is the case and the possible solution to my problem?
    please help me & Thank you for your time,
    This question was solved.
    View Solution.

    If you have more than 4 partitions you will need to delete the extra partition/partitions, then convert the hdd back to Basic.
    Older versions of Partiton Wizard Free work: 
    http://www.sevenforums.com/tutorials/26829-convert-dynamic-disk-basic-disk.html
    ******Clicking the Thumbs-Up button is a way to say -Thanks!.******
    **Click Accept as Solution on a Reply that solves your issue to help others**

  • Wireless Card does not work in Windows 8.1 for G585

    I just wanted to inform someone that the wireless network card does not work in Windows 8.1 Preview. I suspect the driver needs to be updated. When I go to the Device Manager it appears as a Realtek device RTL8192DE instead of a Qualcomm device that does not start. I tried installing the latest driver from the website but it makes the computer crash (BSOD) when trying to reboot after the installation which makes the Windows 8 automatic recovery turn on and I had to restore the system to a previous state before the driver installation.
    For now, I just refreshed my system back to Windows 8, instead of trying to use Windows 8.1 Preview .  If you have any suggestions, it would be great, otherwise I'll wait for a driver update.

    neilwar wrote:
    Oh goody. Just updated to 8.1 and it doesn't work. Looks like everyone else is having the same problem. Why no answer from Lenovo?
    Please refer to the dedicated thread on "Blue" 8.1.
    Thread locked
    Andy  ______________________________________
    Please remember to come back and mark the post that you feel solved your question as the solution, it earns the member + points
    Did you find a post helpfull? You can thank the member by clicking on the star to the left awarding them Kudos Please add your type, model number and OS to your signature, it helps to help you. Forum Search Option T430 2347-G7U W8 x64, Yoga 10 HD+, Tablet 1838-2BG, T61p 6460-67G W7 x64, T43p 2668-G2G XP, T23 2647-9LG XP, plus a few more. FYI Unsolicited Personal Messages will be ignored.
      Deutsche Community     Comunidad en Español    English Community Русскоязычное Сообщество
    PepperonI blog 

  • My HP Pavilion dv6-2153ee recovery is not working when i choose it from boot menu selection

    my HP Pavilion dv6-2153ee  recovery is not working when i choose it from boot menu selection . it's run but then the windows run without running recovery. help me please?

    Hello Tajamal, 
    Welcome to the HP Forums!
    I understand the webcam isn't working since upgrading to Windows 8.1. I would have to suggest returning to Windows 8 since there are no 8.1 drivers, as indicated here: HP Pavilion dv6-7043cl Entertainment Notebook PC Drivers
    Please let me know if you have any other questions.
    Have a wonderful day! 
    Mario
    I worked on behalf of HP.

  • Beats Audio Control Panel software not working after Windows 10 upgrade.

    Beats Audio Control Panel software not working after Windows 10 upgrade.  the Beats sound enhancement is useless in WIndows 10. When opening the Windows 10 sound properties  I'm getting this box message: Auido enhancement problem Windows has detected the audio enhancement for the following device are causing problems: Speakers / Headphones (IDT High Definition Audio Codec) Woud you like to disable driver enhancement for this device?  IDT High Definition Audio CodecBeats Audio Control Panel version6.10.6491.02013.11.2009:43:18 Please provide some kind of fix for this?

    Well, it has been a long road on the Win 10 upgrade. At first I got the same error message as above, but after deleting the Dolby Advanced Audio v2 in Win 10 using Control Panel Programs and Features and rebooting, I got into the continual BSOD upon reboot. Here are the steps I took to at least get stable on Windows 10. First, I rolled back to Windows 8.1 using the advanced feature in the BSOD recovery options. Once back in Win 8.1, I deleted the Dolby Advanced Audio v2 using Add/Remove Programs in Control Panel. Then I downloaded the Win 10 update and re-installed it. Once that completed, I updated the Intel Graphics driver under the display adapters (on my G780 it is an Intel HD Graphics 4000, and the driver can be found at  https://downloadcenter.intel.com/). Currently I am running version 10.18.10.4252 for my machine. Then, under the Device Manager, I updated the Conexant SmartAudio HD driver under the Sound, video, and game controllers. That driver is currently at 8.66.4.50 and was automatically downloaded from the web when I requested to update driver.  I also changed several others settings such as Notify to schedule restart after updates are installed instead of automatic (under Settings --> Update & Security --> Advanced Options) and Do you want Windows to download driver software and realistic icons for your devices? --> No, let me choose what to do, never install driver software from Windows Update.  After that, I shut down the machine, waited a moment and booted back up. I have no idea why this helped or if it is overkill, but I am stable and running without a fear of rebooting now. Hope this helps if someone else is having this same issue.

  • Exporting Crystal Report to HTML is not working in Windows 7

    Hi Sir,
    I am trying to export Crystal Report to HTML format using VB.NET code. Functionality is working fine at Windows XP Environment (Save to Disk, Open an Application and Email Attachment). But the same functionality is not working at Windows 7 Environment (both 32-Bit as well as 64-Bit).
    Below is the code to Exporting Crystal Report to HTML in VB.NET.
    Dim CrDiskFileDestinationOptions As New DiskFileDestinationOptions
    Dim CrFormatTypeOptions          As New HTMLFormatOptions
    Dim vFormat As Integer
    Dim CrExportOptions As New ExportOptions
    Dim vRdReport As New ReportDocument
    Dim sfd As SaveFileDialog
    Dim vFileName As String = Nothing
    vRdReport = vRptSource
    sfd = New SaveFileDialog
    If Not (vRptPath = "") Then
        sfd.InitialDirectory = vRptPath
    End If
    sfd.Filter = "Webpage, Complete(.htm;.htm)|.htm|Web Archive, Single file(.mht)|.mht|Webpage, HTML only(.htm;.html)|.html"
    If sfd.ShowDialog = DialogResult.OK Then
        ' Set the disk file options.
         CrDiskFileDestinationOptions.DiskFileName = sfd.FileName.ToString()
    Else
         Return
    End If
    CrExportOptions = vRdReport.ExportOptions
    CrFormatTypeOptions.HTMLFileName = vFileName
    CrFormatTypeOptions.HTMLEnableSeparatedPages = True
    CrFormatTypeOptions.HTMLEnableSeparatedPages = True
    CrFormatTypeOptions.HTMLHasPageNavigator = True
    CrFormatTypeOptions.UsePageRange = True
    With CrExportOptions
                        .ExportDestinationType = ExportDestinationType.DiskFile
                        .ExportFormatType = ExportFormatType.HTML32
                        .DestinationOptions = CrDiskFileDestinationOptions.DiskFileName
                        .FormatOptions = CrFormatTypeOptions
    End With
    vRdReport.Export()
    Catch ex As Exception
            MsgBox(ex.ToString)
    End Try
    Code working fine at Windows XP, But it is not woking in Windows 7 environment.
    Please can anyone share your valuable thoughts or ideas reg. this.
    Thanks in Advance
    Deivanayaga Perumal D.

    user13509659 wrote:
    Run this code to reproduce the issue.Which issue?
    It looks like inheritance is broken in the component hierarchy for JFrame in Windows 7 JDK 1.6.0_23-b05. The only thing remotely related to inheritance in your code snippet is the WindowListener, which does little. See camickr's advice about built-in exit management.
    EDIT - using the post title as a clue, I realize you may be talking about the component hierarchy, and whether the contentPane's background is visible through the upper layers. Instead of guessing, I'd prefer you describe your "issue" accurately (observed vs expected behavior).
    Edited by: jduprez on Feb 10, 2011 1:01 PM

  • Web Service Client(Console App) not working on Windows Server 2008 R2 Standard Edition

    I am trying to consume an ASMX Web Service in a console app, its working fine in Windows 7,Windows Server 2012 Standard,Windows Server 2008 R2 DataCenter,Windows Server 2008 R2 Enterprise, But its not working in Windows Server 2008 R2 Standard Edition which
    is the deployment server.
    I tried consuming the ASMX web service using Web Reference and Service Reference as well but its not helping. Its throwing up the following error,
    Message:There is an error in XML document (1, 331491).
    Inner Exception : System.Xml.XmlException: '.', hexadecimal value 0x00, is an invalid character. Line 1, position 331491.
    The scenario is that i call the web service and it returns me an XML i am not able to receive the XML on Windows Server 2008 R2 Standard Edition.
    Please provide suggestions on this I need to resolve this ASAP.

    Hi,
    This question is better asked here:
    http://social.msdn.microsoft.com/Forums/en-US/home?forum=asmxandxml
    Experts here are more familiar about it and they can give you more efficient suggestion.
    Thank you.

  • APPLE mouse & keyboard not working with Windows (Bootcamp)

    I installed Leopard and Windows XP on my Mac Pro. The installation went very smoothly. Only problem I have is that my Apple wireless keyboard and mouse do not work on Windows (frozen) although they work fine on Leopard. I tried a Logitech wireless trackball and it works fine on both Windows and Leopard. Any suggestion?

    Thanks. I upgraded from Tiger and downloaded Bootcamp from Leopard Installation disc ( I did not have a beta version ). I then installed Windows XP SP2 ( brand new, just bought for that purpose ). Wonder if Mac wireless keyboard and mouse are compatible with Window. Everything else work beyond my expectation.

  • Flash player does not work in Windows 8 tiles

    Flash player does not work in Windows 8 start metro tile applications. Flash player also does not work in Windows 8 start tile internet explorer 10 1n windows 8. Flash player does work in Windows 8 desktop internet Explorer 10. I tried all of the recommended fixes suggested by adobe Flash Player Issues/windows 8 page. I have reinstalled Windows 8 operating system.  What should I try next?

    This is a known issue with Flash Pro CC - GM build.
    this crash has been fixed in the update that was released recently. Please update to 13.0.1.808 version and it should fix this.
    Please reply if it still persists after the update.
    -Sujai

  • ITunes 12.1.1 does NOT work with Windows - Fix??

    Hi everyone,
    I had issue after issue with the latest iTunes update (12.1.1) not working on my windows 7. It simply would not lunch when clicking on the shortcut to open.
    After a fair bit of searching I found this alternative version which seemed to do the trick and now it works:
    iTunes 12.1.1.4 for Windows (64-bit - for older video cards) - iTunes64Setup.exe(2015-02-18)

    The "for older video cards" installer - which, like most prior "64 bit" versions of iTunes, is actually a 32 bit application with a 64 bit installer - may be a useful fallback if the full 64 bit version does not install or run correctly.  Although 12.1.1.4 is a major improvement over 12.1.0.71, there are clearly still some lurking incompatibilities with some 64 bit Windows systems/components.  It is, however, a little misleading to say that "iTunes 12.1.1 does NOT work with Windows" - in many cases it works fine without switching to the alternative version.  I have the full 64-bit version of 12.1.1.4 running on three systems - two Windows 7 and one Windows 8.1 - no issues with either installation or operation on any of them.

  • ITunes 9 Home Sharing does not work on Windows 7 x64

    iTunes 9 Home Sharing does not work on Windows 7 x64.
    Getting the following error message:
    Home sharing could not be activated because this computer is not authorized for the account "iTunes account." Please authorize this computer and try again.
    This is a bug since my computer is authorized in iTunes and there is only 2 computer authorized for my iTunes account, so I have 3 more left till I should get this message.
    I've just upgraded my iPhone to OS 3.1 using it this morning.
    Please advise.
    Environment: Windows 7 x64, HP TouchSmart tx2-1020us Notebook
    Ivan Farkas
    <edited by host>

    I am using Windows 7 x64.
    I am running iTunes 9.0.2.25
    I am running Mcafee.
    I can see and play music from the iTunes installation on my Windows 7 machine, but I CANNOT access the library to copy songs from this computer to other computers on my network.
    YES, I have enabled "Home Sharing" using my iTunes account. NO, I have not authorized more than 5 computers on this account.
    I believe this to be a Windows 7 related issue, as Home Sharing worked as advertised when I was using Vista (before I upgraded to Windows 7).
    I CAN set up Home Sharing on two other (host) computers in my home network and it works. These computers are XP and a MacBook Pro. I CANNOT access my Windows 7 machine x64 to COPY music from one autorized library to another. Please help!!!
    P.S. - I have attempted to get this to work by turning OFF my McAfee firewall. Windows firewall is disabled.
    Message was edited by: turcott

  • HT3986 I installed windows 7 to my macbook pro, but my mousepad does not work in windows 7 and also i can not connect my windows 7 to projector, but i can use my macbook's mouse pad and i can connect my mac to projector,so please help me for windows 7 pro

    I installed windows 7 to my macbook pro, but my mousepad does not work in windows 7 and also i can not connect my windows 7 to projector, but i can use my macbook's mouse pad and i can connect my mac to projector,so please help me for windows 7 problem

    i try to download now, do you think when i download and install the windows support software, can i fix the problem?

Maybe you are looking for

  • I download itunes to my dell so i could my new ipad. can i move music form windows media to itunes

    i download itunes to my dell so i could use my new ipad. can i move music form windows media player to itunes

  • Pivoting help required

    Hi I am using oracle 11.2.0 version I need help in pivoting the values. Here is the sample data looks like with t as SELECT 'JACK' C1,'RAM' C2,'LAND' C3,'KELLY' C4, 'WORKING' STATUS FROM DUAL UNION ALL SELECT 'JAMES' C1,'NAREN' C2,'SRUJAN' C3,'GANA'

  • Sort Components in task list

    Dear Friends, I have 20 different components [Assigned to a header assembly] connected to a single operation 010 in general task list. Now I have sorted this components based on Item number as the default sort is based on material criteria. After sor

  • Network ready for Cisco wireless ?

    I know for IPT their is lots of network readiness guides. Is their anything like that for Cisco wireless (with central controler)? We looking at putting in Dell swithcs and not cisco. Anybody have any switch level feture I should be looking out for?

  • Parametric contour and smoothing of point (2D interpolation?)

    I am making a imaging program in 2D surface; X-Y-Z set (normally 64 by 64). The set X, Y can be irregular. I find there is a parametric 3D surface plot control in LV 8.2. How to map my XYZ data to the contour control (actually I use ver. 7 and the co