Back Up the EFS Certificate That Matches an Encrypted Windows File
If a Windows user can currently open EFS-encrypted files, preserve that authorised access before retiring the profile. A backup of the encrypted document and a backup of the key needed to read it are different parts of the recovery plan.
EFS applies to files on NTFS. This task concerns that file-encryption layer, rather than a BitLocker prompt when a whole drive starts. On an organisation-managed computer, involve the administrator responsible for its encryption and recovery policy.
Identify the key associated with a real file
Sign in as the user who can read the file. In Command Prompt, use cipher /c followed by the quoted full path of a known encrypted document. Microsoft documents /c as displaying information about that encrypted file. Record the file identity and certificate information privately.
Create a secure export destination that will remain available independently of the profile. This example backs up the user’s certificate and keys associated with a specific file; replace both example paths:
cipher /x:"C:\Work\Example.docx" "E:\KeyBackup\EFS-example"
Follow the export prompts and protect the resulting key material. With no file specified after /x, Cipher instead exports the user’s current EFS certificate and keys. That difference matters when older files may use a different certificate.
Keep evidence of coverage, not just a filename
Check that the export completed without an error and that its output exists in the intended secure location. Record which sample file and certificate it corresponds to. If several collections use different certificates, account for those separately rather than assuming one current-key export covers everything.
Keep the encrypted files, the key export and its required access information under an approved recovery plan. Do not paste private keys or export passwords into a repair ticket or shared document.
Before deleting the original profile, arrange an authorised recovery test on a protected copy of representative files. A file existing on the backup disk does not prove that a replacement account can decrypt it. Leave the working account intact until the coverage and recovery result are understood.
Sources: Microsoft cipher reference.