Error DataBase-One Place all Solutions Forums Blog Glossary    Contact Us
Search  
   
Browse by Category
Error DataBase-One Place all Solutions .: Operating Systems .: Windows Operating Systems .: Windows 2003 .: How to secure the Default Recovery Key on a Stand-alone Computer

How to secure the Default Recovery Key on a Stand-alone Computer

As part of the local administrator's initial logon, a default recovery policy is set up on each stand-alone computer. This policy makes the local administrator the default recovery agent for the computer.

To change this policy:

1.

Click Start, click Run, and type MMC in the Open box. Click OK.

2.

Click Console, click Add/Remove Snap-In. Click Add.

3.

Click Group Policy and click Add.

4.

Accept the default of Local Computer and click Finish. Click Close and click OK.

5.

Click the + next to Local Computer Policy to expand it. In the same way, expand Computer Configuration, Windows Settings, Security Settings, Public Key Policies, and then click Encrypted Data Recovery Agents. The screen should look something like the one below.

6.

There is a self-signed Administrator certificate in the policy. This makes the local administrator account the default recovery agent. If this certificate is deleted, there will be an empty recovery policy, which turns EFS off. EFS does not allow encryption of data if there are no recovery agents set up.

7.

To protect the recovery key associated with this certificate, click Console, and click Add/Remove snap-ins. Click Add.

8.

Click Certificates, and click Add. Click Current User. Click Finish. Click Close. Click OK.

9.

Click the + next to Certificates–Current User. In the same way, expand the Personal folder. Click Certificates in the left pane.

10.

Click Administrator in the right pane and scroll to Intended Purposes. This should be set to File Recovery. Use the procedure in the subsection, "Restoring Files to a Different Computer, " to export the certificate and private key in a .pfx file.

11.

After creating the .pfx file, delete the certificate and the private key associated with it from the Personal store. This ensures that the only copy of the key is in the .pfx file. To do so, click Administrator in the right pane and then click the red X on the toolbar. There will be a warning message saying that the user will not be able to decrypt data encrypted using this certificate. Click Yes to continue.

12.

Secure the .pfx file in a safe or locked cabinet. This file should be used only when a file needs to be recovered.

Securing the Default Recovery Key for the Domain: As with the stand-alone computer, a default recovery policy is configured for the domain when the first domain controller is set up. The default recovery policy uses a self-signed certificate to make the domain Administrator account the recovery agent.

Note: To change the default, log on as Administrator on the first domain controller of the domain, and follow the steps above to secure the recovery key for the domain.


How helpful was this article to you?

Related Articles

article How to Secure your VMware ESX Server
As VMware ESX is loaded directly on hardware...

(No rating)  4-13-2008    Views: 217   
article CTX799332 - Running Citrix Secure Gateway and IIS

(No rating)  4-20-2008    Views: 221   
article HOW TO: Use IPSec Policy to Secure Terminal Services Communications in Windows Server 2003
SUMMARY You can use Windows Server 2003...

(No rating)  2-20-2008    Views: 217   

User Comments

Add Comment
No comments have been posted.