Task 4.2: EFS Data Recovery

One of the fundamental responsibilities of an administrator is to protect the company’s information. This means that it is your responsibility to be able to recover any lost or inaccessible data. There are several reasons that an administrator may need to recover content users encrypted via EFS. A user can accidentally delete their decryption key, or a user may forget their password and need to have it reset. (Resetting a user’s password disables a user’s ability to decrypt their EFS content.) The decryption key is stored inside the user profile. If this profile gets deleted, the decryption key is lost.

Since you have been configured as an EFS Data Recovery Agent, you can decrypt users’ encrypted content and recover ...

Get Security Administrator Street Smarts: A Real World Guide to CompTIA Security+™ Skills, Third Edition now with the O’Reilly learning platform.

O’Reilly members experience books, live events, courses curated by job role, and more from O’Reilly and nearly 200 top publishers.