As a default, the operating system does show you who actually encrypted the file. Here are a couple must-have tools to add to your EFS toolkit:
- EFSInfoComes in the Windows 2000 toolkit. Displays who decrypted a file and shows the identity of the data recovery agent(s).
- EFSDumpIs a great tool from Bryce Cogswell and the folks at System Internals. This tool gives similar information to EFSInfo, but in a more useful format.
For an information-packed introduction to Windows 2000, attend one of the trainAbility classes held nationwide. The registration schedule is at http://www.trainability.com/.