Can Endpoint Security detect a virus that is encrypted by an encrypted file system (EFS)? Yes, if the user who owns the EFS folder accesses the file when the scan runs. Endpoint Security can use their access token. Otherwise, Endpoint Security can't scan inside encrypted files or packages, and neither can any antivirus scanner. The Endpoint Security logs show the following when an EFS is encountered: Not scanned (The file is encrypted). Detection takes place only when the file has been decrypted or opened.
Let us know if you have any questions regarding information provided above and we will clarify that for you.
Was my reply helpful? If you find my post useful, Please give it a Kudos! Also, Please don't forget to select "Accept as a solution" if my reply resolves your query!
Don't forget, when your helpful posts earn a kudos or get accepted as a solution you can unlock perks and badges. Those aren't the only badges, either. How many can you collect? Click here to learn more.
Community Help Hub
New to the forums or need help finding your way around the forums? There's a whole hub of community resources to help you.