You encrypted a folder with EFS, then something happened — a reinstall, a profile reset, an accidental deletion, a drive moved to another PC. Now the files are back, but every one throws Access Denied. The data itself is not damaged; the private key that unlocks it is simply missing. This guide covers why that happens and how to recover and decrypt EFS-encrypted files with RS Partition Recovery.

Contents
- Why EFS Files Become Inaccessible: Common Recovery Scenarios
- Preparing for EFS Recovery: Locating Your Certificate
- How to Recover and Decrypt EFS-Encrypted Files with RS Partition Recovery
- What to Do If You Don't Have the EFS Certificate
No data recovery tool can bypass EFS encryption. RS Partition Recovery can locate and restore encrypted files from a deleted or damaged NTFS volume, but decrypting them still requires the original certificate and private key — or, in a domain environment, a Data Recovery Agent certificate. If that key is permanently gone, the recovered files stay encrypted.
Why EFS Files Become Inaccessible: Common Recovery Scenarios
EFS ties each encrypted file to a certificate and private key stored under a specific Windows user profile. The file itself doesn’t move or change — but the moment that certificate is no longer where Windows expects it, the file becomes unreadable to everyone, including the person who encrypted it. Six situations account for most EFS data recovery cases:
Windows Reinstall or Reset
A clean install or “Reset this PC” creates a new user profile with a new certificate. The old certificate — the only key that could decrypt your files — is gone unless it was exported beforehand.
Drive Moved to Another PC or Profile
The files travel, the certificate doesn’t. EFS certificates live in the user profile on the original machine, not on the drive holding the encrypted data.
Administrator Password Reset
Resetting a local account password through an administrator tool, rather than the user changing it directly, breaks the link Windows uses to unlock the EFS master key — even though the account still logs in normally.
Corrupted or Deleted User Profile
Profile corruption, a botched update, or a deleted profile folder can take the certificate store with it, often without any warning at the time.
Accidental Deletion
The straightforward case: an encrypted file or folder gets deleted. The certificate is still intact, but the file needs recovering from the volume before decryption is even relevant.
Moved to External or Removable Drives
EFS requires NTFS. Copying encrypted files to a FAT32 or exFAT flash drive strips the encryption silently or blocks the copy outright — and even on an NTFS external drive, the certificate problem above still applies. If the goal is protecting the whole drive rather than individual files, BitLocker To Go is the more common choice for removable media, with its own separate recovery process.
How to tell a file is EFS-encrypted, not just access-restricted:
- Windows Explorer shows the filename in green text on an NTFS volume with EFS enabled
- Opening the file returns “Access is denied,” even when logged in as the account that owns it
- File Properties → Advanced shows “Encrypt contents to secure data” checked
- In RS Partition Recovery, encrypted items are flagged with a lock icon during a scan, and Preview shows “File encrypted” instead of file content
Preparing for EFS Recovery: Locating Your Certificate
Before opening any recovery tool, confirm whether you have access to the EFS certificate — this determines which recovery path applies. If you can still log into the Windows account that encrypted the files, the certificate is already in your certificate store, and RS Partition Recovery can pull it directly from Windows with no extra steps. If you’re working from a different machine, a different profile, or a mounted image of the old drive, you’ll need a PFX export of the certificate instead — one made in advance, recovered from a backup, or supplied by a domain Data Recovery Agent.
Open certmgr.msc (press Win+R, type it, and hit Enter).
Navigate to Personal → Certificates and look for an entry issued to your username with the intended purpose “Encrypting File System.”
Right-click the certificate → All Tasks → Export to launch the Certificate Export Wizard.
Choose Yes, export the private key, then save it as a .pfx file protected with a password.
Store that PFX file on a different disk than the files it protects — a certificate backup kept only on the drive you’re trying to recover doesn’t help if that drive fails
If neither the original account nor a PFX export is available, skip ahead to What to Do If You Don’t Have the Certificate. Recovering the file structure won’t restore access to encrypted content without one of these.
How to Recover and Decrypt EFS-Encrypted Files with RS Partition Recovery
RS Partition Recovery handles EFS recovery in two separate steps: first it recovers the file structure from the drive, using the same scan process as any deleted or lost data, then it decrypts the recovered files using whichever certificate you provide. The scan itself doesn’t need the certificate — you can run it and browse the results before deciding how to unlock anything.
Connect the drive and launch RS Partition Recovery. Select the volume — or the physical disk, if the partition itself is missing — and start a scan. A fast scan is usually enough for recently deleted files; run a full scan if it doesn’t turn up what you’re looking for.
When the scan finishes, check for an “Encrypted files found” notice in the results summary, confirming EFS-protected items were detected on the volume.
Browse the recovered file tree. Encrypted items carry a lock icon; deleted items carry a separate red-cross marker, and a file can show both. Selecting an encrypted file shows “File encrypted — Preview is unavailable until the decryption data is added” in place of a thumbnail.
Double-click the encrypted file, or use the Add Decryption Data button in the Preview pane, to open the decryption dialog. Set Type to Encrypting File System (EFS) certificate (.pfx, .p12).
Choose how to supply the key. Click Import from Windows if you’re running the recovery under the same account that originally encrypted the files — no further input needed. Otherwise, browse to your exported .pfx file and enter its password; the certificate’s thumbprint fills in automatically as confirmation that the right certificate was selected.
Click Add. A confirmation message reports that the EFS key was imported successfully, and Preview switches from the “File encrypted” placeholder to the actual file content.
The certificate now applies to every file matching that thumbprint — no need to repeat the step per file. Select what you need and save it to a different physical drive than the one being recovered.
Notes on this workflow:
- Recovery and decryption are independent — a missing certificate doesn’t prevent the scan from finding and restoring the underlying files, it only blocks reading their content
- Import from Windows only works when the tool runs under the same Windows account and profile that holds the original certificate
- Recovered files are saved in decrypted form; there’s no need to re-apply EFS afterward unless you want to
- Never save recovered files back to the drive or partition being recovered — doing so risks overwriting the data you’re trying to retrieve
What to Do If You Don’t Have the EFS Certificate
If the original account, the PFX export, and any certificate backup are all gone, decryption isn’t something a recovery tool — or brute-force cryptography — can restore; the key lengths involved make guessing impractical. One path is worth checking before writing the data off.
Check for a Data Recovery Agent (DRA)
In a domain environment, an administrator may have configured a Data Recovery Agent — a designated certificate that can decrypt any EFS file encrypted under that domain’s policy, independent of the individual user’s own key. This is a domain-level mechanism, not something available on a standalone home PC unless explicitly set up. If the machine was ever joined to a domain, check with the IT administrator or certificate authority before concluding the files are unrecoverable.
Outside of a DRA, there’s no supported way to decrypt EFS files without the original key. Treat “no certificate, no backup, no domain DRA” as a dead end for decryption specifically — the file structure can still be recovered and saved, but its contents will remain encrypted.









