Clearly, EFS re-keying isn't an obvious action that you would expect average
users to perform regularly. But we'll have to live with it for now: At this
time, Microsoft doesn't provide an option to perform re-keying centrally or
automatically at regular intervals.
Extended EFS Configuration and Central Control
In Vista and Longhorn Server, Microsoft exposes a valuable new set of EFS configuration
parameters, some of which control new EFS features that weren't available in
previous EFS editions. Prime examples include the ability to encrypt the paging
file, as well as the ability to control the clearing of the EFS encryption key
cache. In previous EFS editions, when an encrypted file was opened (and thus
decrypted) and paged to disk, the file became available in clear text in the
paging file. Also in previous editions, the EFS encryption key cache was only
cleared when a user logon session ended; now, the cache can be cleared when
a user locks his workstation or after a certain time limit. . . .