Skip to content

TechDirectArchive

Hands-on IT, Cloud, Security, Veeam & DevOps

  • Home
  • About
  • Advertise With US
  • Reviews
  • Tech News
  • Contact
  • Toggle search form

Enable or disable BitLocker Drive Encryption on Windows

Posted on 30/12/202029/12/2023 IT Expert By IT Expert No Comments on Enable or disable BitLocker Drive Encryption on Windows
  1. Home
  2. Security | Vulnerability Scans and Assessment
  3. Enable or disable BitLocker Drive Encryption on Windows

In this article, we shall discuss how to enable or disable BitLocker Drive Encryption on Windows. BitLocker Drive Encryption is a data protection feature that integrates with the operating system and addresses the threats of data theft or exposure from lost or stolen devices. See this guide for information on Full Disk Encryption with PBA / without PBA, UEFI, Secure Boot, BIOS, File and Directory Encryption, and Container Encryption, and how to enable FileVault disk encryption on a Mac device.

BitLocker is an encryption feature built into computers running Windows 10 Pro. If you’re running Windows 10 Home you will not be able to use BitLocker. BitLocker provides the most protection when used with a Trusted Platform Module (TPM) version 1.2 or later.

 BitLocker Drive Encryption architecture, and implementation scenarios. and the concept of DriveLock with a focus on encryption.

How does TPM work with BitLocker?

The TPM works with BitLocker to ensure that a device hasn’t been tampered with while the system is offline. In addition to the TPM, BitLocker can lock the normal startup process until the user supplies a personal identification number (PIN) or inserts a removable device such as a USB flash drive, that contains a startup key or enters a password.

These additional security measures provide multifactor authentication and assurance that the computer will not start or resume from hibernation until the correct PIN or startup key is presented.

The TPM is a hardware component installed in many newer computers by computer manufacturers. It works with BitLocker to help protect user data and to ensure that a computer has not been tampered with while the system was offline.

On devices without TPM version 1.2 and above, you can still use BitLocker to encrypt the Windows OS drive. However, this implementation will require the user to insert a USB startup key to start the computer or resume from hibernation or enter a Password. In the next section, we shall focus more on how to Enable or disable BitLocker Drive Encryption on Windows devices.

Part A – Turn on BitLocker Drive Encryption

Let’s walk through the needed steps to enable data encryption on Windows 10. There are different ways to launch the Bitlocker in Windows 10. Note: Administrative privilege is required to have this done.

I will proceed by typing “BitLocker” in the Windows search box as shown below. Click on Open or press Enter to launch the BitLocker Driver Encryption window.

This will open the BitLocker Drive Encryption window as shown below.

You can also access BitLocker via the Control Panel "Control Panel\System and Security\BitLocker Drive Encryption"

Alternatively, you can turn on BitLocker by launching the File Manager by pressing the “Windows key + E” to open it.

Right-click on the removable storage device that you want to encrypt as shown above. Select Turn on Bitlocker.

What if you encounter the error “device cannot use the Trusted Platform Adapter (TPM)”

Note: You may get an error as shown below if your device cannot use the Trusted Platform Adapter (TPM). 

To fix this, you will have to “allow BitLocker without a compatible TPM” via the group policy. See this guide “how to fix your device cannot use a Trusted Platform Module: Allow BitLocker without a compatible TPM”.

There is no dire consequence of having BitLocker without a TPM, the difference here is that the encryption key will be saved to a USB instead of being stored on the chip itself.

Device Requirement is being performed

Upon clicking on “Turn on BitLocker”, Bitlocker will verify if your device meets the system requirements as shown below.

When this step is finished, click on Next to continue as shown below

Also, click on Next to proceed. As you can see below, there is a warning suggesting that you back up critical files and data before continuing.

If you desire to do this, please click on “Use File History to perform a backup”. I do not want this at the moment, so I will ignore it.

Continue through the BitLocker Drive Encryption process by clicking on “Next” as shown below.

Decide on how to unlock your drive at startup

Next, you will be prompted to choose how you would like to unlock your drive at startup. Since we do not have the TPM chip inbuilt, we will have to decide on any of the options below. To either use a USB flash drive or Enter a password.

Note: If you provide on using a USB flash drive, you will need to have the flash drive connected to your device each time you boot up your device to be able to access the device.

Since this is a test VM, I will proceed with the second option and enter a password

Create a Password for the Drive unlock.

This will be required to create a password to access to unlock this Drive in the future. When you are done, click on Next as shown below.

There are multiple different ways to back up the BitLocker recovery key.

BitLocker gives you three different options for backing up your recovery key, save to USB Drive, Save it to a file, or print the recovery key. I have decided to save this recovery key to a USB flash drive.

You will be prompted to click on save as shown below in rder to save the recovery key unto the USB Flash Drive..

Note: You can save to a file and print the recovery key as well.

If you decide to save your BitLocker recovery key to a file or print it, ensure it is kept in a safe place that’s not on the encrypted device. 

Without your BitLocker key, all data on your device will remain completely inaccessible. Click on Next when you are done.

Next, you will have to decide on how much data you would like to encrypt as shown below.

Since this is a new VM, I will be selecting the first option. Click on Next to proceed

Select the encryption mode

You will need to decide on the encryption mode to use. I will be selecting the first option as shown below. Click on Next to continue

You can choose to either start encryption of your drive or run a BitLocker system check first.

As you can see below, I have selected the option to run the BitLocker system check and this is recommended by Microsoft. 

Note: This ensures that BitLocker can read the Recovery Key before encrypting the drive.

BitLocker will require a restart of your computer before encrypting, but you can continue to use it while your drive is encrypting.

As you can see below, the device is encrypted and a restart is required. 

Please proceed and restart your device.

Once encryption is complete you will be prompted to unlock the Drive. 

Enter the Bitlocker password you created previously.

Now you should be able to log into your device as usual. BitLocker will work unobtrusively in the background.

Login successful as shown below

Since I have tested an FDE solution with PBA, kindly take a look at these guides “Important DriveLock components to master and how to download DriveLock software and install DriveLock“.

Part B – Disable BitLocker

If you ever wish to disable BitLocker on your Windows 10 device, the steps are pretty straightforward. Launch Control Panel and navigate to the following location

"Control Panel\System and Security\BitLocker Drive Encryption"

Alternatively, you can search for Bitlocker from the Windows search box or from launch the run dialog boy and type BitLocker. You will arrive at the same destination :)

Select “Turn off BitLocker”

Follow the prompts to complete this process.

See the following guides on how to enable FileVault disk encryption on a Mac device, BitLocker Drive Encryption architecture, and implementation scenarios. and the concept of DriveLock with a focus on encryption.

I hope you found this blog post on how to enable or disable BitLocker Drive Encryption on Windows helpful. If you have any questions, please let me know in the comment session.

Rate this post

Thank you for reading this post. Kindly share it with others.

  • Share on X (Opens in new window) X
  • Share on Reddit (Opens in new window) Reddit
  • Share on LinkedIn (Opens in new window) LinkedIn
  • Share on Facebook (Opens in new window) Facebook
  • Share on Pinterest (Opens in new window) Pinterest
  • Share on Tumblr (Opens in new window) Tumblr
  • Share on Telegram (Opens in new window) Telegram
  • Share on WhatsApp (Opens in new window) WhatsApp
  • Share on Mastodon (Opens in new window) Mastodon
  • Share on Bluesky (Opens in new window) Bluesky
  • Share on Threads (Opens in new window) Threads
  • Share on Nextdoor (Opens in new window) Nextdoor
Security | Vulnerability Scans and Assessment Tags:Bitlocker, Container encryption, Encryption, encrytp, FDE, Full Disk Encryption, Windows 10

Post navigation

Previous Post: Device cannot use a Trusted Platform Module: Allow BitLocker without a compatible TPM
Next Post: How to Enable BitLocker without Compatible TPM

Related Posts

  • Trellix BitLocker and fileVault Recovery
    Selfservice Recovery: Trellix BitLocker and fileVault Recovery Security | Vulnerability Scans and Assessment
  • PrintNightMare
    Mitigating ‘PrintNightmare’ Vulnerability: Print Spooler Solutions Security | Vulnerability Scans and Assessment
  • SSL on WAMPServer
    Setup VirtualHost with SSL on WAMP Server Linux
  • Screenshot 2022 03 29 at 19.47.05
    CVE-2022-22948: Patch available to address vCenter Server information disclosure vulnerability  Security | Vulnerability Scans and Assessment
  • ePO installation on Windows Server
    Trellix ePolicy Orchestrator Installation on Windows Server Security | Vulnerability Scans and Assessment
  • How to Disable TLS 1.0, TLS 1.1 and TLS 1 banner
    How to Disable TLS 1.0, TLS 1.1 and TLS 1.2 in Windows Using GPO Security | Vulnerability Scans and Assessment

More Related Articles

Trellix BitLocker and fileVault Recovery Selfservice Recovery: Trellix BitLocker and fileVault Recovery Security | Vulnerability Scans and Assessment
PrintNightMare Mitigating ‘PrintNightmare’ Vulnerability: Print Spooler Solutions Security | Vulnerability Scans and Assessment
SSL on WAMPServer Setup VirtualHost with SSL on WAMP Server Linux
Screenshot 2022 03 29 at 19.47.05 CVE-2022-22948: Patch available to address vCenter Server information disclosure vulnerability  Security | Vulnerability Scans and Assessment
ePO installation on Windows Server Trellix ePolicy Orchestrator Installation on Windows Server Security | Vulnerability Scans and Assessment
How to Disable TLS 1.0, TLS 1.1 and TLS 1 banner How to Disable TLS 1.0, TLS 1.1 and TLS 1.2 in Windows Using GPO Security | Vulnerability Scans and Assessment

Leave a Reply Cancel reply

You must be logged in to post a comment.

Microsoft MVP

VEEAMLEGEND

vexpert-badge-stars-5

Virtual Background

GoogleNews

Categories

veeaam100

Veeam Vanguard

  • PassTheHash
    What is Pass the Hash Attack and how to mitigate the attack Security | Vulnerability Scans and Assessment
  • extend proxmox local container instance
    How to extend Proxmox Local Container Storage Virtualization
  • cb5e9fcbe91618c68c5236d801eb6721
    Real-Time Monitoring: How to setup VeeamONE Network | Monitoring
  • Webp.net resizeimage 1
    Automate Infrastructure Deployments in the Cloud with Ansible and Azure Pipelines AWS/Azure/OpenShift
  • GRADLE FEATURE
    How to install Gradle on Ubuntu Linux
  • fdsdsd
    Configuring DHCP Scope: Post-deployment of Dynamic Host Configuration Protocol Windows Server
  • How to Convert a Distribution Group to a Security Group
    How to convert distribution group to security group Windows Server
  • Windows Productivity Tips
    Windows Productivity Tips To Get The Most Out Of Your PC Windows

Subscribe to Blog via Email

Enter your email address to subscribe to this blog and receive notifications of new posts by email.

Join 1,765 other subscribers
  • RSS - Posts
  • RSS - Comments
  • About
  • Authors
  • Write for us
  • Advertise with us
  • General Terms and Conditions
  • Privacy policy
  • Feedly
  • Telegram
  • Youtube
  • Facebook
  • Instagram
  • LinkedIn
  • Tumblr
  • Pinterest
  • Twitter
  • mastodon

Tags

Active Directory Azure Bitlocker Microsoft Windows PowerShell WDS Windows 10 Windows 11 Windows Deployment Services Windows Server 2016

Copyright © 2026 TechDirectArchive

Loading Comments...

You must be logged in to post a comment.