Symptoms

Consider the following scenario:

  • You enable a Work Folders service on a file server that is running Windows 8.1, Windows RT 8.1, or Windows Server 2012 R2 in a domain.

  • You create credentials in┬áthe CredLocker tool to encrypt data on the file server.

  • You change the password of your domain account on a computer, and then you log on to another computer by using the new password in the same domain.

In this scenario, the credentials in the CredLocker tool become corrupted. Therefore, you cannot access the data on the file server.

Cause

This issue occurs because the Data Protection API (DPAPI) cannot recover a key that calls MasterKey from a domain controller after a password is changed on a domain-joined computer.

Resolution

To resolve this issue, install the November 2014 update rollup for Windows RT 8.1, Windows 8.1, and Windows Server 2012 R2.

Status

Microsoft has confirmed that this is a problem in the Microsoft products that are listed in the "Applies to" section.

More Information

For more information about software update terminology, see the Description of the standard terminology that is used to describe Microsoft software updates.

Need more help?

Expand your skills
Explore Training
Get new features first
Join Microsoft Insiders

Was this information helpful?

What affected your experience?

Any additional feedback? (Optional)

Thank you for your feedback!

×