Click here to get back home

Folder Encryption Multiple User Access

 HomeNewsGroups | Search | About
 microsoft.public.windows.server.security    Post an article   get this group's latest topics as an RSS feed add this group's latest topics to your My MSN content add this group's latest topics to your My Yahoo content
Subject Author Date
Folder Encryption Multiple User Access DotNetDeveloperDude 10-16-2007
Posted by DotNetDeveloperDude on October 16, 2007, 10:35 am
Please log in for more thread options
I've read that Win 2k server does not support multiple users accessing
files that have been saved in an encrypted folder. Does Win Server
2k3? I will have several files a day being saved by an automated user
to an encrypted folder and I will have another automated user opening
(and decrypting) those files also several times a day. I can't have
some person sitting at a machine looking for new files and right
clicking on each new file and adding permissions for the 2nd user .
SO I'm hoping that Win 2k3 supports multiple users on encrypted
folders.
Thanks


Posted by Steve Riley [MSFT] on October 16, 2007, 7:44 pm
Please log in for more thread options
EFS in Windows 2000 did support multiple users, but only through the API --
there was no UI for it. XP and 2003 have a UI that allows you to add
multiple users to an EFS-protected file or folder. See
http://www.microsoft.com/windowsxp/using/security/expert/sharefilesefs.mspx.

--
Steve Riley
steve.riley@microsoft.com
http://blogs.technet.com/steriley
http://www.protectyourwindowsnetwork.com


> I've read that Win 2k server does not support multiple users accessing
> files that have been saved in an encrypted folder. Does Win Server
> 2k3? I will have several files a day being saved by an automated user
> to an encrypted folder and I will have another automated user opening
> (and decrypting) those files also several times a day. I can't have
> some person sitting at a machine looking for new files and right
> clicking on each new file and adding permissions for the 2nd user .
> SO I'm hoping that Win 2k3 supports multiple users on encrypted
> folders.
> Thanks
>

Posted by Steven L Umbach on October 16, 2007, 8:09 pm
Please log in for more thread options
Hey Steve.

My understanding is that this has to be done at the file level and can not
be done at the folder level so that a particular user is added to every file
that is placed in that folder for encryption. If there is a way to do it at
the folder level please let me know.

Maybe in this case for the OP the user account that needs to open the files
could be a RA??

As always thanks for your help.

Steve


> EFS in Windows 2000 did support multiple users, but only through the
> API -- there was no UI for it. XP and 2003 have a UI that allows you to
> add multiple users to an EFS-protected file or folder. See
> http://www.microsoft.com/windowsxp/using/security/expert/sharefilesefs.mspx.
>
> --
> Steve Riley
> steve.riley@microsoft.com
> http://blogs.technet.com/steriley
> http://www.protectyourwindowsnetwork.com
>
>
>> I've read that Win 2k server does not support multiple users accessing
>> files that have been saved in an encrypted folder. Does Win Server
>> 2k3? I will have several files a day being saved by an automated user
>> to an encrypted folder and I will have another automated user opening
>> (and decrypting) those files also several times a day. I can't have
>> some person sitting at a machine looking for new files and right
>> clicking on each new file and adding permissions for the 2nd user .
>> SO I'm hoping that Win 2k3 supports multiple users on encrypted
>> folders.
>> Thanks
>>



Posted by Roger Abell [MVP] on October 16, 2007, 10:56 pm
Please log in for more thread options
Hi Steve (long time!!)

I believe you are correct, re EFS being file based.

I think the solution in this case might be to have the
first account, that writes the file, use the api to add
the other account after creating the file, or to run the
second process using the same account, or have a
process running as file writing account that events
on files being added to specific locations and then
does the adding of the second account.

Roger

> Hey Steve.
>
> My understanding is that this has to be done at the file level and can not
> be done at the folder level so that a particular user is added to every
> file that is placed in that folder for encryption. If there is a way to do
> it at the folder level please let me know.
>
> Maybe in this case for the OP the user account that needs to open the
> files could be a RA??
>
> As always thanks for your help.
>
> Steve
>
>
>> EFS in Windows 2000 did support multiple users, but only through the
>> API -- there was no UI for it. XP and 2003 have a UI that allows you to
>> add multiple users to an EFS-protected file or folder. See
>> http://www.microsoft.com/windowsxp/using/security/expert/sharefilesefs.mspx.
>>
>> --
>> Steve Riley
>> steve.riley@microsoft.com
>> http://blogs.technet.com/steriley
>> http://www.protectyourwindowsnetwork.com
>>
>>
>>> I've read that Win 2k server does not support multiple users accessing
>>> files that have been saved in an encrypted folder. Does Win Server
>>> 2k3? I will have several files a day being saved by an automated user
>>> to an encrypted folder and I will have another automated user opening
>>> (and decrypting) those files also several times a day. I can't have
>>> some person sitting at a machine looking for new files and right
>>> clicking on each new file and adding permissions for the 2nd user .
>>> SO I'm hoping that Win 2k3 supports multiple users on encrypted
>>> folders.
>>> Thanks
>>>
>
>



Posted by DotNetDeveloperDude on October 17, 2007, 11:29 am
Please log in for more thread options
Thanks for replies.
My problem is that when I right click on a folder to encrypt it, the
details button is grayed out, and thus can't add additional users to
it. When I right click on the file, then the button is enabled and I
can additional users.
So one of my solutions proposed to our OPS team was to change the user
for the 2nd process (as Roger suggested) to be the same user as the
first process, but that means changes to code elsewhere, which they
don't wanna do.
I like the idea of using the API to add rights to "this" file as it
being written for the 2nd user. That way I can develop that into my
solution and other teams won't be affected (hence the whole reason for
using EFS).
Where can I find docs on the API, and are there any classes in .Net
1.1?

Thanks
Gregg


Similar ThreadsPosted
audit folder access, exclude user November 27, 2007, 5:14 pm
File/Folder encryption - Compliancy with PCI September 28, 2005, 10:31 am
Multiple user certificate thumbprint April 19, 2006, 10:04 pm
Adding multiple entries for the same user with xcacls... July 19, 2007, 2:21 pm
Firewall setting for multiple FTP sites using multiple ports September 12, 2006, 12:35 pm
Everybody denied access to a folder June 19, 2006, 4:52 am
Anonymous folder access December 13, 2006, 9:14 pm
Deny folder access for administrators January 24, 2006, 4:28 am
Remove List Folder access only? March 16, 2006, 2:18 am
users, groups, and access to a folder May 2, 2006, 11:17 pm

Our other projects:

Art Dolls, Fairies and Mermaids - Sunnyfaces.net

Roy's Linux, Programming and Search Engines messages

1-Script XML SitemapXML Sitemap