Skip to content

TechDirectArchive

Hands-on IT, Cloud, Security, Veeam & DevOps

  • Home
  • About
  • Advertise With US
  • Reviews
  • Contact
  • Toggle search form

Enable or disable BitLocker Drive Encryption on Windows

Posted on 30/12/202030/08/2026 Christian By Christian No Comments on Enable or disable BitLocker Drive Encryption on Windows
  1. Home
  2. Security | Vulnerability Scans and Assessment
  3. Enable or disable BitLocker Drive Encryption on Windows
BitLocker password entry screen with a prompt to unlock a drive, featuring images of hard drives and a Windows 10 BitLocker logo.

In this article, we shall discuss how to enable or disable BitLocker Drive Encryption on Windows. BitLocker Drive Encryption is a data protection feature that integrates with the operating system and addresses the threats of data theft or exposure from lost or stolen devices. See this guide for information on Full Disk Encryption with PBA / without PBA, UEFI, Secure Boot, BIOS, File and Directory Encryption, and Container Encryption, and how to enable FileVault disk encryption on a Mac device.

BitLocker is an encryption feature built into computers running Windows 10 Pro. If you’re running Windows 10 Home you will not be able to use BitLocker. BitLocker provides the most protection when used with a Trusted Platform Module (TPM) version 1.2 or later.

 BitLocker Drive Encryption architecture, and implementation scenarios. and the concept of DriveLock with a focus on encryption.

How does TPM work with BitLocker?

The TPM works with BitLocker to ensure that a device hasn’t been tampered with while the system is offline. In addition to the TPM, BitLocker can lock the normal startup process until the user supplies a personal identification number (PIN) or inserts a removable device such as a USB flash drive, that contains a startup key or enters a password.

These additional security measures provide multifactor authentication and assurance that the computer will not start or resume from hibernation until the correct PIN or startup key is presented.

The TPM is a hardware component installed in many newer computers by computer manufacturers. It works with BitLocker to help protect user data and to ensure that a computer has not been tampered with while the system was offline.

On devices without TPM version 1.2 and above, you can still use BitLocker to encrypt the Windows OS drive. However, this implementation will require the user to insert a USB startup key to start the computer or resume from hibernation or enter a Password. In the next section, we shall focus more on how to Enable or disable BitLocker Drive Encryption on Windows devices.

Part A – Turn on BitLocker Drive Encryption

Let’s walk through the needed steps to enable data encryption on Windows 10. There are different ways to launch the Bitlocker in Windows 10. Note: Administrative privilege is required to have this done.

I will proceed by typing “BitLocker” in the Windows search box as shown below. Click on Open or press Enter to launch the BitLocker Driver Encryption window.

Screenshot of a Windows search interface showing 'Manage BitLocker' as the best match, with a search term 'Bitlocker' entered in the search bar.

This will open the BitLocker Drive Encryption window as shown below.

BitLocker Drive Encryption settings window, displaying options to encrypt drives for data protection, with 'Turn on BitLocker' highlighted.

You can also access BitLocker via the Control Panel “Control Panel\System and Security\BitLocker Drive Encryption”

Alternatively

You can turn on BitLocker by launching the File Manager by pressing the “Windows key + E” to open it.

File Explorer window showing 'This PC' section with a context menu and the option 'Turn on BitLocker' highlighted.

Right-click on the removable storage device that you want to encrypt as shown above. Select Turn on Bitlocker.

What if you encounter the error “device cannot use the Trusted Platform Adapter (TPM)”

Note: You may get an error as shown below if your device cannot use the Trusted Platform Adapter (TPM).

To fix this, you will have to “allow BitLocker without a compatible TPM” via the group policy. See this guide “how to fix your device cannot use a Trusted Platform Module: Allow BitLocker without a compatible TPM”.

There is no dire consequence of having BitLocker without a TPM, the difference here is that the encryption key will be saved to a USB instead of being stored on the chip itself.

Device Requirement is being performed

Upon clicking on “Turn on BitLocker”, Bitlocker will verify if your device meets the system requirements as shown below.

BitLocker Drive Encryption progress window showing 'Checking your PC's configuration' with a green progress bar.

When this step is finished, click on Next to continue as shown below

BitLocker Drive Encryption setup screen displaying instructions to prepare and encrypt the drive, with 'Next' button highlighted.

Also, click on Next to proceed. As you can see below, there is a warning suggesting that you back up critical files and data before continuing.

If you desire to do this, please click on “Use File History to perform a backup”. I do not want this at the moment, so I will ignore it.

BitLocker Drive Encryption setup screen displaying preparation steps for a drive, including options to create a recovery drive and cautions about backing up data.

Continue through the BitLocker Drive Encryption process by clicking on “Next” as shown below.

BitLocker Drive Encryption setup window with instructions and a 'Next' button highlighted.

Decide on how to unlock your drive at startup

Next, you will be prompted to choose how you would like to unlock your drive at startup. Since we do not have the TPM chip inbuilt, we will have to decide on any of the options below. To either use a USB flash drive or Enter a password.

Note: If you provide on using a USB flash drive, you will need to have the flash drive connected to your device each time you boot up your device to be able to access the device.

BitLocker Drive Encryption prompt showing options to unlock the drive at startup: 'Insert a USB flash drive' or 'Enter a password'.
Since this is a test VM, I will proceed with the second option and enter a password

Create a Password for the Drive unlock.

This will be required to create a password to access to unlock this Drive in the future. When you are done, click on Next as shown below.

BitLocker Drive Encryption interface prompting the user to create a strong password for unlocking the drive, featuring fields for password entry and a 'Next' button.

There are multiple different ways to back up the BitLocker recovery key.

BitLocker gives you three different options for backing up your recovery key, save to USB Drive, Save it to a file, or print the recovery key. I have decided to save this recovery key to a USB flash drive.

Screenshot of BitLocker Drive Encryption options showing how to back up a recovery key, with 'Save to a USB flash drive' option highlighted.

You will be prompted to click on save as shown below in rder to save the recovery key unto the USB Flash Drive..

Dialog box for saving a recovery key to a USB flash drive, showing options to insert the device, select it, and click 'Save'.

Note: You can save to a file and print the recovery key as well.

If you decide to save your BitLocker recovery key to a file or print it, ensure it is kept in a safe place that’s not on the encrypted device.

Without your BitLocker key, all data on your device will remain completely inaccessible. Click on Next when you are done.

BitLocker Drive Encryption settings screen asking how to back up the recovery key with options to save to a USB flash drive, save to a file, or print the recovery key.

Next, you will have to decide on how much data you would like to encrypt as shown below. Since this is a new VM, I will be selecting the first option. Click on Next to proceed

Screenshot of the BitLocker Drive Encryption setup window, displaying options to encrypt used disk space only or the entire drive, with a 'Next' button highlighted.

Select the encryption mode

You will need to decide on the encryption mode to use. I will be selecting the first option as shown below. Click on Next to continue

BitLocker Drive Encryption settings screen displaying options for choosing an encryption mode in Windows 10.

You can choose to either start encryption of your drive or run a BitLocker system check first.

As you can see below, I have selected the option to run the BitLocker system check and this is recommended by Microsoft.

Note: This ensures that BitLocker can read the Recovery Key before encrypting the drive.

BitLocker Drive Encryption setup screen displaying a checkbox for 'Run BitLocker system check' and a 'Continue' button, with instructions for preparing the drive for encryption.

BitLocker will require a restart of your computer before encrypting, but you can continue to use it while your drive is encrypting.

As you can see below, the device is encrypted and a restart is required.

Please proceed and restart your device.

Screenshot of the BitLocker Drive Encryption settings in Windows Control Panel, indicating that the operating system drive (C:) requires a restart.
Once encryption is complete you will be prompted to unlock the Drive.

Enter the Bitlocker password you created previously.

BitLocker password entry screen with a blue background

Now you should be able to log into your device as usual. BitLocker will work unobtrusively in the background.

User login screen displaying the name 'Christian' and a password input field.

Login successful as shown below

Since I have tested an FDE solution with PBA, kindly take a look at these guides “Important DriveLock components to master and how to download DriveLock software and install DriveLock“.

Part B – Disable BitLocker

If you ever wish to disable BitLocker on your Windows 10 device, the steps are pretty straightforward. Launch Control Panel and navigate to the following location

"Control Panel\System and Security\BitLocker Drive Encryption"

Alternatively, you can search for Bitlocker from the Windows search box or from launch the run dialog boy and type BitLocker. You will arrive at the same destination 🙂

Select “Turn off BitLocker”

Screenshot of the BitLocker Drive Encryption settings in the Control Panel, displaying options to manage BitLocker for the operating system drive and fixed data drives.
Follow the prompts to complete this process.

See the following guides on how to enable FileVault disk encryption on a Mac device, BitLocker Drive Encryption architecture, and implementation scenarios. and the concept of DriveLock with a focus on encryption.

I hope you found this blog post on how to enable or disable BitLocker Drive Encryption on Windows helpful. If you have any questions, please let me know in the comment session.

Thank you for reading this post. Kindly share it with others.

  • Share on X (Opens in new window) X
  • Share on Reddit (Opens in new window) Reddit
  • Share on LinkedIn (Opens in new window) LinkedIn
  • Share on Facebook (Opens in new window) Facebook
  • Share on Pinterest (Opens in new window) Pinterest
  • Share on Tumblr (Opens in new window) Tumblr
  • Share on Telegram (Opens in new window) Telegram
  • Share on WhatsApp (Opens in new window) WhatsApp
  • Share on Mastodon (Opens in new window) Mastodon
  • Share on Bluesky (Opens in new window) Bluesky
Security | Vulnerability Scans and Assessment Tags:Bitlocker, Container encryption, Encryption, encrytp, FDE, Full Disk Encryption, Windows 10

Post navigation

Previous Post: Device cannot use a Trusted Platform Module: Allow BitLocker without a compatible TPM
Next Post: How to Enable BitLocker without Compatible TPM

Related Posts

  • Featured image new
    How to update the BIOS on your Dell system Security | Vulnerability Scans and Assessment
  • Print Spooler
    Mitigate Windows Print Spooler Remote Code Execution Vulnerability Security | Vulnerability Scans and Assessment
  • Trellix MVISOSN
    How to install Trellix MVISON Endpoint Security | Vulnerability Scans and Assessment
  • vcenter sign on
    CVE-2021-22048: VMware vCenter Server updates address a privilege escalation vulnerability Security | Vulnerability Scans and Assessment
  • PrintNightMare 1
    PrintNightmare security update for Windows Server and Windows 10 Security | Vulnerability Scans and Assessment
  • microsoft ntlm2
    NT LAN Manager: How to prevent NTLM credentials from being sent to remote servers Security | Vulnerability Scans and Assessment

More Related Articles

Featured image new How to update the BIOS on your Dell system Security | Vulnerability Scans and Assessment
Print Spooler Mitigate Windows Print Spooler Remote Code Execution Vulnerability Security | Vulnerability Scans and Assessment
Trellix MVISOSN How to install Trellix MVISON Endpoint Security | Vulnerability Scans and Assessment
vcenter sign on CVE-2021-22048: VMware vCenter Server updates address a privilege escalation vulnerability Security | Vulnerability Scans and Assessment
PrintNightMare 1 PrintNightmare security update for Windows Server and Windows 10 Security | Vulnerability Scans and Assessment
microsoft ntlm2 NT LAN Manager: How to prevent NTLM credentials from being sent to remote servers Security | Vulnerability Scans and Assessment

Leave a Reply Cancel reply

You must be logged in to post a comment.

Microsoft MVP

VEEAMLEGEND

vexpert-badge-stars-5

Virtual Background

GoogleNews

Categories

veeaam100

Veeam Vanguard

  • Add User to Slack
    How to add a user to the Slack workspace JIRA|Confluence|Apps
  • VBR upgrade
    Upgrade Veeam Backup and Replication to version 12.2 Backup
  • Dockerize NodeJS Application
    Dockerizing a NodeJs Express Application Automation
  • Licensing
    Manage Windows Product key with Software Licensing Manager Windows
  • uninstall installed Windows Update from Windows
    How to uninstall installed Windows Update Windows
  • M0365VBO
    Why should you use Veeam to protect your Microsoft 365 Data? Backup
  • Word backup day Veeam Backup configuration File saved the backup sever
    [World Backup Day] V13 Upgrade Failure: Veeam Configuration Backup Saved the Day Backup
  • Was ist Windows Server und wie unterscheidet er sich vom normalen Windows
    Create a certificate template for BitLocker Network Unlock Windows Server

Subscribe to Blog via Email

Enter your email address to subscribe to this blog and receive notifications of new posts by email.

Join 1,762 other subscribers
  • RSS - Posts
  • RSS - Comments
  • About
  • Authors
  • Write for us
  • Contact
  • Advertise with us
  • General Terms and Conditions
  • Privacy policy
  • Feedly
  • Telegram
  • Youtube
  • Facebook
  • Instagram
  • LinkedIn
  • Tumblr
  • Pinterest
  • Twitter
  • mastodon
  • Bsky

Tags

Active Directory Azure Bitlocker Microsoft Windows PowerShell WDS Windows 10 Windows 11 Windows Deployment Services Windows Server 2016

Copyright © 2026 TechDirectArchive

Loading Comments...

You must be logged in to post a comment.