Q. EFS certificate always tries to enroll the Basic EFS template?

The EFS (Encrypting File System) always attempts to enroll the Basic EFS template.

When requesting a certificate on first use, EFS requests the Basic EFS template, or it uses auto-enrollment. When no certificates exist on the client computer, the version 1 template of the Basic EFS is used.

When configuring a version 2 template of the Basic EFS for enhanced configuration options, and you want users to automatically obtain the EFS certificate, you must use auto-enrollment.

NOTE: EFS does not know if there is the version 2 template on first use because the version 2 template has a different name.

NOTE: When you manually request a certificate in the MMC (Microsoft Management Console), the EFS certificate works with both versions of the template.

NOTE: See Encrypting File System in Windows XP and Windows Server 2003


Please or Register to post comments.

IT/Dev Connections

Las Vegas
September 30th - October 4th

Paul ThurottYou'll have the opportunity to experience:
• The Microsoft
Technology Roadmap
• Office 365 Implementation
• Hyper-V Optimizing
• Windows 8 Deployment
and much more!

Come See Paul Thurrott & Rod Trent in Person!

Early Registration Now Open

Upcoming Training

Mastering System Center 2012

During over 6 hours of training you can join John Savill from your computer as he will walk you through the key components and capabilities of System Center 2012, what’s involved in using the components, and the benefit they can bring to your environment.

Register Now

Current Issue

May 2013 - The NameTranslate object is useful when you need to translate Active Directory object names between different formats, but it's awkward to use from PowerShell. Here's a PowerShell script that eliminates the awkwardness.

CURRENT ISSUE / ARCHIVE / SUBSCRIBE

Windows Forums

Get answers to questions, share tips, and engage with the Windows Community in our Forums.