Working on EFS DRA and Certificates

I found I couldn’t just “add” a user as a new recovery agent, because that account’s user object didn’t have an appropriate certificate. According to the document in my previous post, there are significant advantages to using our Certificate Authority to manage EFS-related keys.
I found the following sequence of articles useful:
I’m still working on this, though.

