I am in the process of retiring an old Windows-integrated CA and bringing online a new, properly-configured one (several, actually). Most of our systems are unable to use EFS thanks to Group Policy... but due to some misconfiguration, a handful of domain users were able to autoenroll for EFS certificates. So far, none of the users are aware of any files they have encrypted, and searching through their files with cipher /u /n
isn't finding anything... but I can't be sure that there are no encrypted files we have missed.
I must retire this CA soon, so I'll have to revoke the EFS certificates and ensure that EFS is totally disabled for those users. I really can't migrate the old CA to a new one either, for several reasons. So what are my options for shutting off EFS for those who may have been using it without losing their data?