EFS, Credentials, and Private Keys from Certificates Are Unavailable After a Password Is Reset (290260)
The information in this article applies to:
- Microsoft Windows XP Professional
- Microsoft Windows XP Home Edition
This article was previously published under Q290260 SYMPTOMS
After you reset the password of an account on a Windows XP-based computer that is joined to a workgroup, you may lose access to the user's:
- Web page credentials.
- File share credentials.
- EFS-encrypted files.
- Certificates with private keys (SIGNED/ENCRYPTed e-mail).
CAUSE
This issue can occur if the password was forcefully reset by an administrator or owner, instead of being changed by the user.
RESOLUTIONNOTE: For any of the following resolutions to work, the user's original account must still exist, and the user's profile must be present and unchanged since the user last had access to the data.
To recover all of the data, you must have one of the following:
- The original password. This is the password with which the user last logged on successfully and was able to access their credentials and files.
- Password Recovery Disk (PRD). This password recovery disk must have been created while the user had access to the files.
To Completely Recover By Using the Original Password- Log on to the computer as the user with the current password.
- Click Start, and then click Control Panel.
- In Control Panel, click User Accounts.
- Click your user name.
- Click Change my password.
- Follow the instructions to change the password back to your original password.
- Restart your computer.
To Completely Recover By Using the Password Recovery Disk- If you are logged on, log off of the computer.
- Attempt to log on as the user, and deliberately type an incorrect password.
- Click use your password reset disk.
- Follow the instructions in the wizard.
- Log on, and note that you have access to your files.
Recovering Access to Encrypted EFS Data
If you have encrypted some of your files by using the Encrypting File System (EFS), you have additional options to recover access to those encrypted files. The following provisions apply only to EFS encrypted files, and will not recover access to saved credentials or certificates.
If you have previously exported the user's EFS private key from the user's account, you may import the key back into the account and recover access to the encrypted files.
If you did not export the private key and you have defined a Data Recovery Agent (DRA) prior to encrypting the files, you may regain access to EFS files as the Data Recovery Agent.
For additional information about how to recover data in this case, click the article number below
to view the article in the Microsoft Knowledge Base:
255742 Methods for Recovering Encrypted Data Files
If you do not have the required items or information specified for the preceding recovery solutions, the data is permanently encrypted, and cannot be recovered.
STATUSThis behavior is by design.
Modification Type: | Minor | Last Reviewed: | 6/15/2005 |
---|
Keywords: | kbenv kberrmsg kbprb kbtool KB290260 |
---|
|