The Data Protection profile encrypts enterprise data and restricts access to approved devices. Create an EFS certificate to encrypt your enterprise data protected by a Data Protection profile.


  1. On a computer without an EFS certificate, open a command prompt (with admin rights) and navigate to the certificate store you where you want to store the certificate.
  2. Run the command:cipher /r:<EFSRA>
    The value of <EFSRA> is the name of the .cer and .pfx files that you want to create.
  3. When prompted, enter the password to help protect your new .pfx file.
  4. The .cer and .pfx files are created in the certificate store you selected.
  5. Upload your .cer certificate to devices as part of a Data Protection profile. For more information, see Configure a Data Protection Profile.