Symptoms
Consider the following scenario:
-
You enable a Work Folders service on a file server that is running Windows 8.1, Windows RT 8.1, or Windows Server 2012 R2 in a domain.
-
You create credentials in the CredLocker tool to encrypt data on the file server.
-
You change the password of your domain account on a computer, and then you log on to another computer by using the new password in the same domain.
In this scenario, the credentials in the CredLocker tool become corrupted. Therefore, you cannot access the data on the file server.
Cause
This issue occurs because the Data Protection API (DPAPI) cannot recover a key that calls MasterKey from a domain controller after a password is changed on a domain-joined computer.
Resolution
To resolve this issue, install the November 2014 update rollup for Windows RT 8.1, Windows 8.1, and Windows Server 2012 R2.
Status
Microsoft has confirmed that this is a problem in the Microsoft products that are listed in the "Applies to" section.
More Information
For more information about software update terminology, see the Description of the standard terminology that is used to describe Microsoft software updates.