Knowledge Base →6 min readUpdated: 2026-09-21

How to Enable BitLocker Encryption in Windows 11

BitLocker is the full-disk encryption built into Windows 11 Pro and above: it scrambles the entire drive with AES so a stolen laptop exposes nothing, and the TPM chip unscrambles it transparently at every boot. You turn it on from the BitLocker Drive Encryption page (search Start for Manage BitLocker, or right-click drive C:), save the 48-digit recovery key somewhere outside the PC, and encryption then finishes in the background while you keep working.

What BitLocker protects and what it needs

BitLocker encrypts the whole volume — system files, programs, your documents — and the unlock key never leaves the TPM chip unless you deliberately export a recovery key. A thief who pulls the SSD out of your laptop gets noise, not data; even a bootable USB with full disk access reads nothing. Encryption runs transparently and at nearly zero cost on any modern CPU, which on this decade's hardware means every CPU.

The catch is edition and hardware. Full BitLocker needs Windows 11 Pro, Enterprise or Education; Home edition offers only the lighter „device encryption“ on supported hardware. Beyond that you need a TPM 2.0 chip, UEFI boot — standard on any Windows 11 machine — and a recovery key you will actually be able to find again in two years.

  • A BIOS, UEFI or TPM firmware update that changes the measured boot state
  • Motherboard or CPU replacement, or moving the SSD into a different PC
  • Changes to the boot order, Secure Boot or a bootable USB left plugged in
  • Protection suspended for maintenance and never resumed
  • A forgotten startup PIN, if you use one in addition to the TPM

Turning BitLocker on, step by step

Open Control Panel → System and Security → BitLocker Drive Encryption — the quickest route is to search Start for Manage BitLocker — or right-click drive C: in File Explorer and pick Turn on BitLocker. The wizard first asks where to save the 48-digit recovery key: Microsoft account, USB flash drive, a file, or printout. The Microsoft account is the most convenient, and you can retrieve the key any time at aka.ms/myrecoverykey; the one rule that matters is never to keep the only copy on the drive it protects.

Next choose Encrypt used disk space only — fine for drives in active use — or Encrypt entire drive, better for a disk that already carried data, then decide whether to run the BitLocker system check at the next restart. After the reboot a padlock icon appears in the tray and encryption chugs along in the background; check progress any time with manage-bde -status C: in an administrator prompt. On a modern NVMe drive the whole job typically takes under an hour. One check beforehand: many preinstalled laptops already run the lighter device encryption out of the box — look under Settings → Privacy & security → Device encryption — but only the full wizard gives you suspend, startup PIN and data-drive control.

After enabling: suspend before firmware updates, decrypt if you must

Two habits keep BitLocker painless. Before a BIOS/UEFI or TPM firmware update, open the same BitLocker page and click Suspend protection: the data stays encrypted, but Windows stops enforcing the measured boot state, so the update will not trigger a recovery prompt on the next boot. Resume afterwards — or simply reboot, since suspension ends automatically. For extra data drives, right-click the drive in Explorer, turn on BitLocker and tick automatic unlock so they open together with the OS drive.

Removing BitLocker entirely — Turn off BitLocker — decrypts the drive fully, which takes hours on an old HDD and far less on an SSD; if you are selling the PC, a Windows reset with the “Remove everything” option is the cleaner route. And if Windows ever does ask for the recovery key at boot, fetch it from aka.ms/myrecoverykey rather than guessing, because repeated wrong attempts can lock you out of the drive.

Questions and Answers

Does BitLocker slow the computer down?

Not measurably on any modern processor — AES hardware acceleration keeps the overhead to a fraction of a percent. You will not notice it in daily work.

Where do I find my BitLocker recovery key?

At aka.ms/myrecoverykey if you saved it to your Microsoft account; otherwise in the file, on the USB stick or on the printout you chose during setup.

Is BitLocker available on Windows 11 Home?

No — full BitLocker requires Pro, Enterprise or Education. Home offers only “device encryption”, which switches on automatically on supported hardware.

Know what is included before you buy.

The one-time 30-minute trial covers core tools. PRO-labelled features stay locked until a paid license is activated.

Read next

All articles · FAQ

Write to us: [email protected]