Windows-itpro-docs: DRA certificate added to WIP policy but not found

Created on 27 Feb 2019  Â·  6Comments  Â·  Source: MicrosoftDocs/windows-itpro-docs

Running cipher /c with an elevated account on a protected file returns (user name and domain obfuscated):

Compatibility Level: Enterprise Protected
Users who can decrypt: COMPANY\Username
No recovery certificate found.
Enterprise key has been revoked.
The specified file could not be decrypted.


Document Details

⚠ Do not edit this section. It is required for docs.microsoft.com ➟ GitHub issue linking.

Most helpful comment

@Martony78 - thank you for submitting feedback.

I think the best way forward is if you can open a service ticket so this can get resolved ASAP. Based on outcome let me know if it is something that can be called out in the docs.

Please follow this link to contact support for Windows 10 products:
https://support.microsoft.com/en-us/hub/4338813/windows-help?os=windows-10

If you don't mind please keep us posted here on the resolution and I really want to get this information you are discovering back into the docs.

All 6 comments

@Martony78 - thank you for submitting feedback.

I think the best way forward is if you can open a service ticket so this can get resolved ASAP. Based on outcome let me know if it is something that can be called out in the docs.

Please follow this link to contact support for Windows 10 products:
https://support.microsoft.com/en-us/hub/4338813/windows-help?os=windows-10

If you don't mind please keep us posted here on the resolution and I really want to get this information you are discovering back into the docs.

Ticket created on 02/27, waiting for a resolution, I’ll post it here

@AndreaBarr - This issue can be closed. Thank you.

Ticket created on 02/27, waiting for a resolution, I’ll post it here

Hey Martony, I'm facing the same issue. Could you please let us know how you fixed the issue? My DRA cert that is part of our WIP policy doesn't show up in when executing cypher /c .

Thanks!

Have a look at your Default Domain Policy registry.pol if it has an ESFBlob setting.
That was the problem in my case, an old setting from DC 2003 I had to delete manually because was not showing in the Group Policy Editor...

BTW Microsoft was unable to solve it, I had to find and resolve the issue myself.

Was this page helpful?
0 / 5 - 0 ratings

Related issues

helloitsliam picture helloitsliam  Â·  3Comments

arcotek-ltd picture arcotek-ltd  Â·  3Comments

RAJU2529 picture RAJU2529  Â·  3Comments

marcnil815 picture marcnil815  Â·  3Comments

thohun picture thohun  Â·  3Comments