I have a domain environment with CA. I made a shared folder on the file server. The folder is encrypted with EFS and a domain user certificate. I don't have any delegations enabled. I connect to the shared folder from a computer outside the domain. As expected, I cannot open the file. The file server does not have a user certificate. It also cannot import it from CA because delegation is disabled. That's what I wanted. Using powershell, I imported a user certificate to the file server. At this point, I can open an encrypted file from my computer with share outside of my domain. OKAY. Now, I am removing the user certificate from the file server using powershell. And at this point, there is something I don't understand. I can still open the encrypted file from a computer outside the domain. Since MS says that the file cannot be opened without a certificate, how could I do that?
But ... I log in directly to the user account on file server. I check if there is a certificate. There isn't. At the same time, when I am logged in to file server, I check access from a computer outside the domain. Access denied. Cool! I log out of the FS server and ... on a computer outside the domain I have access to the encrypted file. Something is wrong. I log in again directly on FS. Access denied. I log out. Access is possible again.
This happens until FS is restarted. After rebooting, I don't have access. I import the certificate and delete it. The whole situation repeats itself.
Can someone explain it to me? How can I block access when there is no certificate? The whole situation is shocking to me. How can I use an encrypted file without having a certificate?