CloudBerry Backup now warns about EFS encrypted files instead of backing them up

[reply=“Matt;5455”] That’s unfortunate. Version 6.3 is not even out, so when is 6.4 expected? I was under the impression that this would be resolved in months, not years.

Was this ever resolved? I am having this issue now.

Hey Guys,

I’ve seen a few fixes on here but can anyone confirm they have worked? Also having this same issue

@Matt Is there any update to this now that v7 is out? There never was a v6.4 release. I only point that out because that is the version you stated would include a fix. I see nothing about any EFS related fixes or updates in the “What’s New” release notes going back to version 6.3.2. I don’t typically complain, but Cloudberry is supposed to be an enterprise-level backup solution and isn’t super cheap either. The basic server-capable license for Cloudberry also at some point recently increased in price to $180 from $120 (a 50% increase).

[reply=“Davison;7580”] The solution is not an easy one for file / folder backups that need to access EFS encrypted files created by users other than the service account that is running the backup service. Windows prevents such access, as you’re aware. I assume if you’re using EFS at the user level, you have a reason for doing so. The easiest way around this might be to perform an image backup instead. You can restrict the image to just the folders needed using the Exclude Option. But the caveat here is that in order to restore files to a system other than the one that was used for the backup would require you had the certificates and would have to back them up. In my opinion, this adds additional complexity you may not want to absorb.

I saw your earlier post about MozyPro, but when I check other products like CrashPlan, Carbonite, Acronis, and Veeam, I see information which would suggest that it’s not supported on those platforms either. It’s possible some of these other products do what you need, but I haven’t come across that information.

The requirement, as you noted, has been pushed to 7.4, which is some time off. At this point I do not think it would be realistic that it will be added in a time-frame you need it (if at all). I know the team is looking at options and if something is found during their research, they will re-prioritize.

I would like to ask why you are using EFS, are you using it for more than one user, and whether Bitlocker encryption would suffice in its place since it’s whole-drive encryption - and we support it?

[reply=“David Gugick;7581”] I’m not expecting some magic solution. Of course the EFS certificates would need to be backed up. In a Windows domain scenario, the best solution would likely be backing up the recovery agent’s private key (since the default recovery agent is the admin account on the first domain controller).

While it might be possible for backup software with sufficient privileges to handle this key backup automatically, I’m certainly OK with having to do a one-time manual export of a recovery agent key to a file that could then be backed up along with all the other files.

But all of that is moot if the software refuses to backup EFS encrypted files at all. There are certainly other apps that have successfully backed up EFS files without decrypting them. The trick is using an EFS specific API from Microsoft. Bvckup2 is one such software (great software, but only supports local network source/destinations). You can google “bvckup2 efs” and the top result should be a forum where there are details and a link to Microsoft’s EFS API.

You ask why I am using EFS. I’m not, nor do I like it. I’m actually about to disable support for it domain-wide with GPOs for most of my clients. The problem is that, unless it is disabled in the domain, any domain user can choose to use it. So any clients with users that already have EFS-encrypted files will still have those files. It is what it is.

In regards to the image backup, there is a lot more flexibility for a variety of things (like retention) that you can do with file-level backups, so I don’t see an image backup as being a viable workaround at this point. Bottom line, it doesn’t seem like it would be that hard to just back up the files as-is using Microsoft’s EFS API in a file-level backup (along with warnings for any EFS files in regards to the need for a recovery key).

[reply=“Davison;7585”] I have a question pending for the dev team onthis request. If I get an update from them, I’ll post it here. Thanks for your feedback.

[reply=“Davison;7585”] EFS Support was added to the latest Windows 7.6 agent. https://help.mspbackups.com/backup/about/efs

You have options to either Keep EFS Encryption or Decrypt EFS files at backup time. The new feature is only available when using the New Backup Format.

I am looking forward to it. I still don’t see it though, here a month later.

[reply=“nickycruze2;9779”] While I confirm at my end, can you confirm what version you are using?

[reply=“nickycruze2;9779”] After a quick review of the release notes, EFS support was added when using the New Backup Format only. You get backup options for decrypting EFS files at backup time or backing them up with EFS encryption intact. But if you need EFS backup support, you’ll need to move to the new backup format.

As an option: If your EFS files are contained in a limited number of folders, leave your legacy backups in place, but with a change that excludes any folders with EFS encrypted files. Then create a new file backup format plan that manages only those folders with EFS encrypted files. Please let me know if you have any additional questions.