File recovery agents not authorized (Windows)

Module: Encrypted File System

Supported Platforms: Windows 2000, Windows 2003, Windows 2008, Windows Vista, Windows XP

This check reports files with recovery agents that are not specified in the name list. The name list can contain user names or certificate thumbprints or both. If the name list is empty, no errors will be detected.

The following table lists the error messages for the check.

Table: Error messages for File recovery agents not authorized

Message String ID and Category

Platform and Message Numeric ID

Message Title and Description

Additional Information

String ID: ESM_EFS_OTHER_RECOVERY_AGENTS

Category: System Information

  • Windows 2000 (106933)

  • Windows 2003 (206933)

  • Windows 2008 (249933)

  • Windows Vista (229933)

  • Windows XP (201933)

Title: Recovery agent name not authorized

Description:The file recovery agent name is not specified in the name list of authorized recovery agents.

Severity: yellow-2

Correctable: false

Snapshot Updatable: false

Template Updatable: false

Information Field Format: [Recovery agent: %s]

String ID: ESM_EFS_RECOVERY_AGENTS_THUMBPRINT

Category: System Information

  • Windows 2000 (106934)

  • Windows 2003 (206934)

  • Windows 2008 (249934)

  • Windows Vista (229934)

  • Windows XP (201934)

Title: Recovery agent thumbprint not authorized

Description:The file recovery agent thumbprint is not specified in the name list of authorized recovery agents.

Severity: yellow-2

Correctable: false

Snapshot Updatable: false

Template Updatable: false

Information Field Format: [Recovery agent certificate thumbprint: %s]