Can the Documents folder in Windows be encrypted with File Share Encryption? (Blocking and Allowing Files and Folders)
search cancel

Can the Documents folder in Windows be encrypted with File Share Encryption? (Blocking and Allowing Files and Folders)

book

Article ID: 403531

calendar_today

Updated On:

Products

Desktop Email Encryption Drive Encryption Encryption Management Server Endpoint Encryption File Share Encryption Gateway Email Encryption PGP Command Line PGP Key Management Server PGP Key Mgmt Client Access and CLI API PGP SDK

Issue/Introduction

File Share Encryption allows you to encrypt multiple folders within Windows.  Can you Encrypt the Documents folder with File Share Encryption?

This document will discuss blocking and allowing certain files and folders. 

Resolution

File Share Encryption can indeed encrypt the Documents folder. However, there are certain files and folders that are blocked from being encrypted.  

Special Note: Special care should be taken as some folders that appear inside of the documents folder, may not work well if they are encrypted.

It may be better to encrypt specific folders within Documents, rather than the entire folder.  This will ensure that the folders you intend to encrypt, will be fully functional, and any new folders that may not work if they are encrypted, will be functional as well. 


Blocked and Allowed Files, Folders, and Applications:
Certain files, folders, and applications can be blocked or allowed. These items are either never protected or forced to be protected.

PGP File Share Encryption does not allow you to protect certain files and folders. Before a file or folder is protected by PGP File Share Encryption, it is checked against this list, known as the blocked. If a file or folder is identified as being blocked, PGP File Share Encryption continues with creating the Protected folder, but the file and/or folder is skipped and a message is displayed in the File Share Encryption Assistant Progress screen that the item is blocked.

 

Files that are blocked include:
◼ All files with the file extension *.skr, *.pkr, and *.pgd,to prevent you from encrypting your keys or PGP Virtual Disks.

◼ The PGP Encryption Desktop installation folder and all files within it (by default, the folder is located at C:\Program Files\PGP Corporation\PGP Desktop).

◼ The PGP Encryption Desktop Preferences folder and all files within it (by default, the folder is located at C:\Users\User-Profile-Here\AppData\Roaming\PGP Corporation\PGP or C:\Documents and Settings\[yourusername]\Application 
Data\PGP Corporation\PGP).

◼ The PGP default keyring folder (by default, the keyring is located in the My Documents folder).

Other files that PGP  File Share Encryption prevents from adding to Protected Folders are any files or folders that have the System attribute set, and all files and folders in the Windows installation directory (by default, C:\Windows and C:\Windows\System32), as well as the Thumbs.db file created when viewing thumbnail graphics in Windows Explorer. When system files or folders are added to PGP File Share Encryption, the file and/or folder is skipped and a message is displayed in the PGP File Share Encryption Assistant Progress screen that the item is a system file or folder.

 

Blocked and Allowed folders Specified by Symantec Encryption Server via Policy
If you are using PGP Encryption Desktop in a PGP Encryption Server-managed environment, your PGP Encryption Server administrator may have specified certain folders as blocked or allowed. This setting can be found in the PGP Console under Consumers > Consumer Policy > [YourPolicyName] > Symantec Encryption Desktop [Edit...], then the File Share tab:



Blocked folders are folders that are never added to PGP File Share Encryption and encrypted, listed as C:\test and C:\test2 above.

If your Symantec Encryption Server administrator has specified that a folder be blocked and that folder does not exist, it is not created on your system.

Note: Folders and/or files that have been PGP File Share Encryption-protected are not decrypted automatically if they are blocked by PGP Encryption Server policy), even if the policy has been applied. To remove PGP File Share Encryption protection, access or move the file or folder. Any new objects added to a protected blocked folder will not receive PGP File Share Encryption. 

 

Allowed folders
Allowed folders are folders that are always added to PGP File Share Encryption and the contents are encrypted.

If your PGP Encryption Server administrator has specified that a folder be allowed and that folder does not exist, it is created on your system.

For example, if your PGP Encryption Server administrator specified that C:\Documents and Settings\[user name]\My Documents\secured is an allowed folder, and the subfolder \secured does not exist, then it is created. You cannot remove Allowed folders from PGP File Share Encryption.

Note: If you remove a folder that your PGP Encryption Server administrator has specified as allowed, that folder is automatically recreated the next time you access PGP File Share Encryption or restart PGP Encryption Desktop.

 

Additional Information

Encrypting the C:\ root directory is strongly discouraged.

The reason is that the File Share Encryption driver operates at the file system level, not at the kernel level.

Therefore, encrypting any root folder (such as C:) using File Share Encryption is not recommended and may lead to system instability or access issues.

If full disk encryption is required, please use Disk Encryption (WDE or DE) instead.