Skip to content

TechDirectArchive

Hands-on IT, Cloud, Security, Veeam & DevOps

  • Home
  • About
  • Advertise With US
  • Reviews
  • Contact
  • Toggle search form

Enable or disable BitLocker Drive Encryption on Windows

Posted on 30/12/202030/08/2026 Christian By Christian No Comments on Enable or disable BitLocker Drive Encryption on Windows
  1. Home
  2. Security | Vulnerability Scans and Assessment
  3. Enable or disable BitLocker Drive Encryption on Windows
BitLocker password entry screen with a prompt to unlock a drive, featuring images of hard drives and a Windows 10 BitLocker logo.

In this article, we shall discuss how to enable or disable BitLocker Drive Encryption on Windows. BitLocker Drive Encryption is a data protection feature that integrates with the operating system and addresses the threats of data theft or exposure from lost or stolen devices. See this guide for information on Full Disk Encryption with PBA / without PBA, UEFI, Secure Boot, BIOS, File and Directory Encryption, and Container Encryption, and how to enable FileVault disk encryption on a Mac device.

BitLocker is an encryption feature built into computers running Windows 10 Pro. If you’re running Windows 10 Home you will not be able to use BitLocker. BitLocker provides the most protection when used with a Trusted Platform Module (TPM) version 1.2 or later.

 BitLocker Drive Encryption architecture, and implementation scenarios. and the concept of DriveLock with a focus on encryption.

How does TPM work with BitLocker?

The TPM works with BitLocker to ensure that a device hasn’t been tampered with while the system is offline. In addition to the TPM, BitLocker can lock the normal startup process until the user supplies a personal identification number (PIN) or inserts a removable device such as a USB flash drive, that contains a startup key or enters a password.

These additional security measures provide multifactor authentication and assurance that the computer will not start or resume from hibernation until the correct PIN or startup key is presented.

The TPM is a hardware component installed in many newer computers by computer manufacturers. It works with BitLocker to help protect user data and to ensure that a computer has not been tampered with while the system was offline.

On devices without TPM version 1.2 and above, you can still use BitLocker to encrypt the Windows OS drive. However, this implementation will require the user to insert a USB startup key to start the computer or resume from hibernation or enter a Password. In the next section, we shall focus more on how to Enable or disable BitLocker Drive Encryption on Windows devices.

Part A – Turn on BitLocker Drive Encryption

Let’s walk through the needed steps to enable data encryption on Windows 10. There are different ways to launch the Bitlocker in Windows 10. Note: Administrative privilege is required to have this done.

I will proceed by typing “BitLocker” in the Windows search box as shown below. Click on Open or press Enter to launch the BitLocker Driver Encryption window.

Screenshot of a Windows search interface showing 'Manage BitLocker' as the best match, with a search term 'Bitlocker' entered in the search bar.

This will open the BitLocker Drive Encryption window as shown below.

BitLocker Drive Encryption settings window, displaying options to encrypt drives for data protection, with 'Turn on BitLocker' highlighted.

You can also access BitLocker via the Control Panel “Control Panel\System and Security\BitLocker Drive Encryption”

Alternatively

You can turn on BitLocker by launching the File Manager by pressing the “Windows key + E” to open it.

File Explorer window showing 'This PC' section with a context menu and the option 'Turn on BitLocker' highlighted.

Right-click on the removable storage device that you want to encrypt as shown above. Select Turn on Bitlocker.

What if you encounter the error “device cannot use the Trusted Platform Adapter (TPM)”

Note: You may get an error as shown below if your device cannot use the Trusted Platform Adapter (TPM).

To fix this, you will have to “allow BitLocker without a compatible TPM” via the group policy. See this guide “how to fix your device cannot use a Trusted Platform Module: Allow BitLocker without a compatible TPM”.

There is no dire consequence of having BitLocker without a TPM, the difference here is that the encryption key will be saved to a USB instead of being stored on the chip itself.

Device Requirement is being performed

Upon clicking on “Turn on BitLocker”, Bitlocker will verify if your device meets the system requirements as shown below.

BitLocker Drive Encryption progress window showing 'Checking your PC's configuration' with a green progress bar.

When this step is finished, click on Next to continue as shown below

BitLocker Drive Encryption setup screen displaying instructions to prepare and encrypt the drive, with 'Next' button highlighted.

Also, click on Next to proceed. As you can see below, there is a warning suggesting that you back up critical files and data before continuing.

If you desire to do this, please click on “Use File History to perform a backup”. I do not want this at the moment, so I will ignore it.

BitLocker Drive Encryption setup screen displaying preparation steps for a drive, including options to create a recovery drive and cautions about backing up data.

Continue through the BitLocker Drive Encryption process by clicking on “Next” as shown below.

BitLocker Drive Encryption setup window with instructions and a 'Next' button highlighted.

Decide on how to unlock your drive at startup

Next, you will be prompted to choose how you would like to unlock your drive at startup. Since we do not have the TPM chip inbuilt, we will have to decide on any of the options below. To either use a USB flash drive or Enter a password.

Note: If you provide on using a USB flash drive, you will need to have the flash drive connected to your device each time you boot up your device to be able to access the device.

BitLocker Drive Encryption prompt showing options to unlock the drive at startup: 'Insert a USB flash drive' or 'Enter a password'.
Since this is a test VM, I will proceed with the second option and enter a password

Create a Password for the Drive unlock.

This will be required to create a password to access to unlock this Drive in the future. When you are done, click on Next as shown below.

BitLocker Drive Encryption interface prompting the user to create a strong password for unlocking the drive, featuring fields for password entry and a 'Next' button.

There are multiple different ways to back up the BitLocker recovery key.

BitLocker gives you three different options for backing up your recovery key, save to USB Drive, Save it to a file, or print the recovery key. I have decided to save this recovery key to a USB flash drive.

Screenshot of BitLocker Drive Encryption options showing how to back up a recovery key, with 'Save to a USB flash drive' option highlighted.

You will be prompted to click on save as shown below in rder to save the recovery key unto the USB Flash Drive..

Dialog box for saving a recovery key to a USB flash drive, showing options to insert the device, select it, and click 'Save'.

Note: You can save to a file and print the recovery key as well.

If you decide to save your BitLocker recovery key to a file or print it, ensure it is kept in a safe place that’s not on the encrypted device.

Without your BitLocker key, all data on your device will remain completely inaccessible. Click on Next when you are done.

BitLocker Drive Encryption settings screen asking how to back up the recovery key with options to save to a USB flash drive, save to a file, or print the recovery key.

Next, you will have to decide on how much data you would like to encrypt as shown below. Since this is a new VM, I will be selecting the first option. Click on Next to proceed

Screenshot of the BitLocker Drive Encryption setup window, displaying options to encrypt used disk space only or the entire drive, with a 'Next' button highlighted.

Select the encryption mode

You will need to decide on the encryption mode to use. I will be selecting the first option as shown below. Click on Next to continue

BitLocker Drive Encryption settings screen displaying options for choosing an encryption mode in Windows 10.

You can choose to either start encryption of your drive or run a BitLocker system check first.

As you can see below, I have selected the option to run the BitLocker system check and this is recommended by Microsoft.

Note: This ensures that BitLocker can read the Recovery Key before encrypting the drive.

BitLocker Drive Encryption setup screen displaying a checkbox for 'Run BitLocker system check' and a 'Continue' button, with instructions for preparing the drive for encryption.

BitLocker will require a restart of your computer before encrypting, but you can continue to use it while your drive is encrypting.

As you can see below, the device is encrypted and a restart is required.

Please proceed and restart your device.

Screenshot of the BitLocker Drive Encryption settings in Windows Control Panel, indicating that the operating system drive (C:) requires a restart.
Once encryption is complete you will be prompted to unlock the Drive.

Enter the Bitlocker password you created previously.

BitLocker password entry screen with a blue background

Now you should be able to log into your device as usual. BitLocker will work unobtrusively in the background.

User login screen displaying the name 'Christian' and a password input field.

Login successful as shown below

Since I have tested an FDE solution with PBA, kindly take a look at these guides “Important DriveLock components to master and how to download DriveLock software and install DriveLock“.

Part B – Disable BitLocker

If you ever wish to disable BitLocker on your Windows 10 device, the steps are pretty straightforward. Launch Control Panel and navigate to the following location

"Control Panel\System and Security\BitLocker Drive Encryption"

Alternatively, you can search for Bitlocker from the Windows search box or from launch the run dialog boy and type BitLocker. You will arrive at the same destination 🙂

Select “Turn off BitLocker”

Screenshot of the BitLocker Drive Encryption settings in the Control Panel, displaying options to manage BitLocker for the operating system drive and fixed data drives.
Follow the prompts to complete this process.

See the following guides on how to enable FileVault disk encryption on a Mac device, BitLocker Drive Encryption architecture, and implementation scenarios. and the concept of DriveLock with a focus on encryption.

I hope you found this blog post on how to enable or disable BitLocker Drive Encryption on Windows helpful. If you have any questions, please let me know in the comment session.

Thank you for reading this post. Kindly share it with others.

  • Share on X (Opens in new window) X
  • Share on Reddit (Opens in new window) Reddit
  • Share on LinkedIn (Opens in new window) LinkedIn
  • Share on Facebook (Opens in new window) Facebook
  • Share on Pinterest (Opens in new window) Pinterest
  • Share on Tumblr (Opens in new window) Tumblr
  • Share on Telegram (Opens in new window) Telegram
  • Share on WhatsApp (Opens in new window) WhatsApp
  • Share on Mastodon (Opens in new window) Mastodon
  • Share on Bluesky (Opens in new window) Bluesky
Security | Vulnerability Scans and Assessment Tags:Bitlocker, Container encryption, Encryption, encrytp, FDE, Full Disk Encryption, Windows 10

Post navigation

Previous Post: Device cannot use a Trusted Platform Module: Allow BitLocker without a compatible TPM
Next Post: How to Enable BitLocker without Compatible TPM

Related Posts

  • VBR Console on a Jump Server
    How to install Veeam Backup Console on a Jump Server Backup
  • Trellix Native Encryption
    Manage BitLocker and FileVault with Trellix Native Encryption Mac
  • How to upgrade Trellix ePolicy Orchestrator
    How to upgrade Trellix ePolicy Orchestrator Security | Vulnerability Scans and Assessment
  • MBAM Replacement
    MBAM extended support ends April 2026: Find alternative solution Security | Vulnerability Scans and Assessment
  • PassTheHash
    What is Pass the Hash Attack and how to mitigate the attack Security | Vulnerability Scans and Assessment
  • HiveNightmare
    Workaround for “SeriousSAM or HiveNightmare” registry vulnerability for Windows 10 and 11 Security | Vulnerability Scans and Assessment

More Related Articles

VBR Console on a Jump Server How to install Veeam Backup Console on a Jump Server Backup
Trellix Native Encryption Manage BitLocker and FileVault with Trellix Native Encryption Mac
How to upgrade Trellix ePolicy Orchestrator How to upgrade Trellix ePolicy Orchestrator Security | Vulnerability Scans and Assessment
MBAM Replacement MBAM extended support ends April 2026: Find alternative solution Security | Vulnerability Scans and Assessment
PassTheHash What is Pass the Hash Attack and how to mitigate the attack Security | Vulnerability Scans and Assessment
HiveNightmare Workaround for “SeriousSAM or HiveNightmare” registry vulnerability for Windows 10 and 11 Security | Vulnerability Scans and Assessment

Leave a Reply Cancel reply

You must be logged in to post a comment.

Microsoft MVP

vexpert-badge-stars-5

Virtual Background

VEEAMLEGEND

Categories

veeaam100

Veeam Vanguard

  • Screenshot 2022 04 27 at 00.50.35
    How to create a BitLocker System Partition [Part 2] Windows
  • Restrict the number of tabs a user can open in Chrome and Edge
    Restrict the number of tabs a user can open in Chrome and Edge Windows
  • control panel
    Enable or Disable Control Panel and Windows Settings App Windows
  • How to Change the Default Web Browser on Windows 11 banner
    How to Change the Default Web Browser on Windows 11 Windows
  • DELL Data Protection
    How does DELL Free Fall Data Protection work? Windows
  • Norton RDP
    Can’t connect via RDP upon installing Norton 360 Anti-Virus Solution
  • Featured image SmartScreen
    Fix SmartScreen can’t be reached right now on Windows 10 and 11 Anti-Virus Solution
  • How to stay protected on Windows 10 and11 device with Windows Security
    Stay protected on Windows device with Windows Security Security | Vulnerability Scans and Assessment

Subscribe to Blog via Email

Enter your email address to subscribe to this blog and receive notifications of new posts by email.

Join 1,752 other subscribers
  • RSS - Posts
  • RSS - Comments
  • About
  • Authors
  • Write for us
  • Contact
  • Advertise with us
  • General Terms and Conditions
  • Privacy policy
  • Feedly
  • Telegram
  • Youtube
  • Facebook
  • Instagram
  • LinkedIn
  • Tumblr
  • Pinterest
  • Twitter
  • mastodon
  • Bsky

Tags

Active Directory Azure Bitlocker Microsoft Windows PowerShell WDS Windows 10 Windows 11 Windows Deployment Services Windows Server 2016

Copyright © 2026 TechDirectArchive

Loading Comments...

You must be logged in to post a comment.