- EFS Best Practices
- Join All Desktops and Laptops to a Domain
- Protect Private Keys
- Add More DRAs at Local OU Level
- Use the Trusted for Delegation Option Sparingly
- Back Up Laptops Containing Locally Encrypted Files
- EFS File Handling
- Figuring Out Who Encrypted a File
Use the Trusted for Delegation Option Sparingly
It can be convenient to permit encrypting files on servers, but this requires a Trusted for Delegation setting that makes the server vulnerable to Trojan horse attacks. Keep tight physical and network security on servers that are trusted for delegation.
In addition, trainAbility recommends that you never designate a desktop as Trusted for Delegation. If users want to access encrypted files on their personal machines from home across a VPN, then you can deploy a secure remote control utility.