Windows Vista EFS
Windows Vista EFS is a feature of windows to store the information on the hard drive in an encrypted form. The feature of Encryption is the strongest protection provided in windows to help the user to keep the information secure. Windows Vista Encrypting file system provides several useful features, you just have to select a check box in the folder's or file properties to turn it on and you can control over who can have the privileges to read the files. Files get encrypted when you close them, but are automatically decrypted when you open them. Windows encrypting file system is not fully supported in windows vista starter, windows vista home basic and windows vista home premium editions.
Advanced efs data recovery v1.20 is the latest version of advanced data recovery that decrypts the files protected with advanced efs in windows 2000, ME, XP, 2003, and Vista. In advanced data recovery Windows Vista, the recovery is even possible when you transfer the protected information into a different PC, when encryption keys are tampered with, or when you format system partition.
The advanced windows encrypting file system enables the files to be transparently encrypted to protect the secret data from attackers and intruders with physical access to the computer. If one uses Vista EFS, it is easy for them to experience that EFS encrypted the files as soon as they closed them.
There are many windows vista services that provide transparency to the users in encryption/decryption process. Like one can encrypt the My Documents folder for all users, this makes sure that personal folder, where most personal documents are stored, is encrypted by default. On the other hand, Vista data recovery is used to effectively decrypt the protected files even when all other methods of recovering the data fail. Scanning the hard-drive in low-level mode and matching the patterns sector by sector allows recovering the encrypted files even if some of the encryption keys are lost.
We have a setup, where we use Windows Vista (without SP1). EFS is used to encrypt company data on users home drive using a mix of
- folder redirection
- offline files
- EFS (to encrypt the data)
- User Certificates (used by EFS)
- Credential Roaming (to roam the certificate with private key to other PC's than where the certificate was initially installed.
This does not seem to be a working setup. Microsoft is working on a statement.
The problem right now is that a user gets issued multiple certificates because a certificate is being enrolled before the credential roaming kicks in. Unfortunately this seems to be a design issue which means that a solution may be difficult to provide in a timely manner. We may need to change to using bitlocker or other 3.party disk encryption and avoid EFS in this setup.
EFS Recovery works completely automatically, locating and recovering encrypted files and folders from healthy, damaged, deleted or inaccessible disks and partitions. The EFS recovery tool will help if you moved the disk into another PC, upgraded or downgraded Windows, or are trying to access encrypted files located on an external disk from a different PC or user account (*). Just specify the disk or partition and enter your Windows account password (*) to begin!
EFS Recovery supports all the features of other data recovery products released by DiskInternals, including the company's signature PowerSearch and pre-recovery preview algorithms. PowerSearch allows the tool to locate and recover files that are no longer present in the file system. EFS Recovery will scan the entire disk or partition, reading the data sector by sector in order to locate the exact beginning and end of more than 200 supported file types. PowerSearch allows recovering important files such as office documents, compressed archived, pictures, video and other types of data from partitions with corrupted or missing file systems, damaged and inaccessible disks.
