Encrypted files (Windows EFS)

Windows notification: Back up your file encryption key

EFS is a Windows feature that allows you to encrypt individual files on disk. Magnus Box supports backing up EFS-encrypted files on Windows. The files will be silently decrypted if possible (e.g. if Magnus Box is running as the encryption user, or if Magnus Box is running as the EFS Recovery Agent user).

If it is not possible to automatically decrypt the file for backup, Magnus Box will back up the file in its encrypted form, and will only be able to restore it in its encrypted form. EFS-encrypted files are displayed with green text in the Restore browser dialog in Magnus Box.

If you have a PC failure, the EFS encryption keys may be lost. In this situation, the EFS-encrypted files may be unusable, even after restoring from backup. Magnus Box warns you about this situation by adding a warning message in the backup job log.

Warning "EFS-encrypted files may be unusable once restored..."

The warning in the backup job log looks like this:

EFS-encrypted files may be unusable once restored, unless you also backup the EFS encryption keys from this PC. To disable this warning, please ensure you have backed up the EFS encryption keys, and then tick the 'Dismiss the EFS warning' option in the Protected Item settings.

The backup job itself succeeded. But if you restore the data to a new PC, the files may not be readable, because the EFS encryption keys are tied to the Windows user account. In practice, the backup might not be restorable. Back up the keys as described below, and then dismiss the warning.

In order to safely prepare for this scenario, you should export the PC's EFS encryption keys, so that the files can be accessed after a PC failure. On Windows, you can do this via certmgr.msc; or on Windows Server, taking a System State backup may be sufficient.

Once you have safely backed up the PC's EFS encryption keys, you can suppress the warning in Magnus Box Backup by enabling the "I confirm EFS keys are exported" option in the Protected Item settings. The warning text refers to this as the 'Dismiss the EFS warning' option.

If you have only a partial PC failure (e.g. files lost, but OS installation and user accounts remain intact) the EFS-encrypted files will be restorable without any further attention to the EFS keys.

Finding files using EFS

You can use the cipher /u /n command to list all files on the local PC that are EFS-encrypted.

Finding the certificate used to encrypt a file

You can use the cipher /C C:\path\to\file.txt command to display the user accounts and certificates that are able to decrypt a file. This may indicate which user originally encrypted the file and/or which EFS certificates are necessary for backup

Did this answer your question? Thanks for the feedback There was a problem submitting your feedback. Please try again later.

Still need help? Contact Us Contact Us