繁体中文
设为首页
加入收藏
当前位置:技术首页 >> 系统 >> Windows >> 知识库 >> KB222022:Disable EFS in a Windows 2000-Based Domain

KB222022:Disable EFS in a Windows 2000-Based Domain

2006-10-19 17:45:47  作者:admin  来源:互联网  浏览次数:76  文字大小:【】【】【
关键字:efs


HOW TO: Disable EFS for All Computers in a Windows 2000-Based Domain

SUMMARY
Microsoft Windows 2000 includes an encryption tool called Encrypting File System (EFS). Clients can use this tool to protect files by encrypting them. However, it is possible that in some environments, an administrator may want to prevent users from encrypting data on their workstations. An administrator can do so for domain clients by modifying a controlling group policy object (GPO) or locally with a local GPO.

Disabling EFS throughout a Windows 2000-based Domain to Modify the "Default Domain Policy" Group Policy Object
1. Click Start, point to Programs, point to Administrative Tools, and then click Active Directory Users and Computers.
2. View the appropriate node for your domain, right click this node, and then click Properties.
3. Click the Group Policy tab, click the Default Domain Policy GPO, and then click Edit. Note that you do not need to use the Default Domain Policy, you can use a new GPO such as Disable EFS to accomplish the same task.
4. In the Group Policy Editor Snap-In, view the following node:
Default Domain Policy\Computer Configuration\Windows Settings\Security Settings\Public Key Policies\Encrypted Data Recovery Agents
NOTE: If any certificates exist in the right side pane, delete them.  
5. Right-click the Encrypted Data Recovery Agents node, click Delete Policy, and then click Yes.
6. Right-click the Encrypted Data Recovery Agents node, and then click Initialize Empty Policy.
NOTE: Users on client workstations to which this policy is applied are no longer able to encrypt files or folders. Also, if users attempt to apply encryption attributes, they will receive the following error message:
Error Applying Attributes
An error occurred applying attributes to the file:

file name

There is no encryption recovery policy configured for this system.

To use EFS, the presence of a data recovery policy is required. A data recovery policy configured as "empty" is not treated the same as one configured as "no policy". Setting up "no policy" (deleting policy) allows for the use of the default local policy on computers, in effect permitting local administrators to control the recovery of data on their individual computers. Setting up an "empty policy" turns EFS off, so that users are unable to encrypt files on computers that fall into this category. Because policies are cumulative, enforcing an empty policy at the domain level ensures that all Windows 2000 domain clients are denied EFS capabilities.

APPLIES TO
• Microsoft Windows 2000 Server
• Microsoft Windows 2000 Advanced Server
• Microsoft Windows 2000 Professional Edition
• Microsoft Windows 2000 Datacenter Server

Keywords:  kbhowto kbhowtomaster kbnetwork KB222022

URL:
http://support.microsoft.com/def ... ;222022&sd=tech

责任编辑:admin

本文引用地址: http://tech.itzero.com/2006/1019/1874.html 请粘贴到你的QQ/MSN上推荐给你的好友

相关文章
 

最新文章

更多

· MS08-006:Internet Inf...
· 适用于 Windows Server ...
· 修改安全设置和用户权限...
· 安装 Windows Defender ...
· 安装 Office 2003 Servi...
· 有关安装了 Office 2003...
· Windows Installer 3.1 ...
· 在运行 Windows XP Serv...
· 如何在 Windows XP 中将...
· 如何配置 SQL Server 20...

热点文章

更多

· Windows Installer 3.1 ...
· 修改安全设置和用户权限...
· 如何配置 SQL Server 20...
· 如何在 Windows XP 中将...
· 适用于 Windows Server ...
· 在 Windows XP 中启用系...
· 在运行 Windows XP Serv...
· 安装 Office 2003 Servi...
· MS08-006:Internet Inf...
· 如何将数据从 Excel 导入...

其它推荐