Skip to content

TechDirectArchive

Hands-on IT, Cloud, Security & DevOps Insights

  • Home
  • About
  • Advertise With US
  • Reviews
  • Contact
  • Toggle search form
Home » Windows » Enable BitLocker AES-XTX 256 Encryption
  • Screenshot 2020 05 14 at 19.43.13
    Repo: How to setup Chef Repository Configuration Management Tool
  • Norton RDP
    Can’t connect via RDP upon installing Norton 360 Anti-Virus Solution
  • Telegram Bot for wordpress
    Configure Telegram to receive Blog Notifications JIRA|Confluence|Apps
  • remote desktop connection 5 1280x720 1
    How to view and remove Remote Desktop connection history Windows
  • GPO 2
    Why GPO is not the best solution for managing Windows updates Windows Server
  • How to Fix Microsoft Outlook Not Syncing Issue
    How to Fix Microsoft Outlook Not Syncing Issue Network | Monitoring
  • original
    Windows Deployment Services: WDSUTIL CommandLine Options on Windows Server 2019 Windows Server
  • maxresdefault
    How to extend a VM Hard Disk on VMware Workstation Virtualization

Enable BitLocker AES-XTX 256 Encryption

Posted on 20/01/202307/05/2024 Matthew By Matthew No Comments on Enable BitLocker AES-XTX 256 Encryption
Enable BitLocker AES-XTX 256 Encryption Method
Enable BitLocker AES-XTX 256 Encryption Method

BitLocker is a full disk encryption feature included with Windows Vista and later versions of the Windows operating system. It uses AES (Advanced Encryption Standard) encryption with a key length of 128-bits or 256-bits to encrypt the entire drive. BitLocker AES-XTX 256 encryption is used to secure data stored on a computer’s hard drive. In this guide, you will learn how to enable BitLocker AES-XTX 256 Encryption method. Here are other related posts: BitLocker Recovery Mode prompted? Cannot find my BitLocker Recovery Key, the Effect of renaming an MBAM or BitLocker-protected Computer, 

BitLocker helps protect against data breaches and unauthorized access to data by encrypting the entire drive, including the operating system, system files, and user files. This makes it more difficult for someone to access the data on the drive if the computer is stolen or if someone tries to access the data without permission.

The AES-XTX encryption method was introduced in Windows 10 (1511) and later versions of Windows. This version of AES is designed specifically for encrypting hard disks. By default, Windows 10 1511 encrypts your hard drives using AES-XTX 128.

If you need to safeguard sensitive data, you might consider utilizing the AES-XTX 256 algorithm. Let’s have a look at how to activate this algorithm. Please refer to these related guides: How and where to find your BitLocker recovery key in Windows, and Why does MBAM not automatically re-encrypt MBAM or Bitlocker-protected devices.

Steps to Enable BitLocker AES-XTX 256 Encryption Method

To enable the BitLocker AES-XTX 256 Encryption method, follow the steps below:

To open the Local Group Policy Editor, press the “Windows key” to open “Start” and type “gpedit” and select the top result.

Enable BitLocker AES-XTX 256 Encryption Method: Launch Local Group Policy Editor from Start menu
Launch Local Group Policy Editor from Start menu

Navigate to the following path: Computer Configuration >> Administrative Templates >> Windows Components >> BitLocker Drive Encryption.

Navigate to the BitLocker Drive Encryption
Navigate to the BitLocker Drive Encryption

Double-click on Choose drive encryption method and cipher strength (Windows 10 [Version 1511] and later)

Select Enabled and choose the encryption algorithm you want, and then click OK to apply the change.

image3
Enable the AES-XTX 256 Encryption

Once this done, you can go ahead to enable BitLocker encryption on your drive. See the following guide on how to enable Bitlocker via the Local Group Policy Editor and the Group Policy Management Console.

To check the encryption status of your drive after enabling BitLocker encryption on it, open the Command Prompt” as administrator. To do this, press the Windows key to open the Start menu and type “cmd” and choose run as administrator.

Launch Command Prompt from Start menu
Launch Command Prompt from Start menu

Type the following command and press Enter:

manage-bde -status
Check BitLocker Encryption Status from CMD
Check BitLocker Encryption Status from CMD

FAQs

Can I validate BitLocker key on my machine is being stored in the MBAM database?

Should you wish to validate that the key on your machine is being stored within the MBAM database it is a simple process on the client. Open an administrative Command Prompt or PowerShell Window on your client machine, and type in the following; manage-bde -protectors -get c:

You can access the SQL server database by using SQL Management Studio to review recovery information. All BitLocker key information is stored in clear text in the RecoveryAndHardwareCores.Keys table in the MBAM Recovery and Hardware database;

How can I exempt a computer from BitLocker encryption?

Add the computer account that you want to be exempted to a security group in Active Directory Domain Services. This allows you to bypass any computer-based BitLocker protection rules. Create a Group Policy Object by using the MBAM Group Policy template, then associate the Group Policy Object with the Active Directory group that you created in the previous step.

When an exempted computer starts, the MBAM client checks the Computer Exemption Policy setting and suspends protection based on whether the computer is part of the BitLocker exemption security group.

I hope you find the post on how to Enable BitLocker AES-XTX 256 Encryption helpful. If you have any questions, please leave a comment below.

Rate this post

Thank you for reading this post. Kindly share it with others.

  • Click to share on X (Opens in new window) X
  • Click to share on Reddit (Opens in new window) Reddit
  • Click to share on LinkedIn (Opens in new window) LinkedIn
  • Click to share on Facebook (Opens in new window) Facebook
  • Click to share on Pinterest (Opens in new window) Pinterest
  • Click to share on Tumblr (Opens in new window) Tumblr
  • Click to share on Telegram (Opens in new window) Telegram
  • Click to share on WhatsApp (Opens in new window) WhatsApp
  • Click to share on Pocket (Opens in new window) Pocket
  • Click to share on Mastodon (Opens in new window) Mastodon
  • Click to share on Bluesky (Opens in new window) Bluesky
  • Click to share on Threads (Opens in new window) Threads
  • Click to share on Nextdoor (Opens in new window) Nextdoor
Security | Vulnerability Scans and Assessment, Windows Tags:Bitlocker, BitLocker Drive Encryption Administration Utilities, BitLocker Status, Enable BitLocker, Microsoft Windows, Windows 10, Windows 11, Windows Server 2016

Post navigation

Previous Post: How to delete AWS S3 Bucket and Objects via  AWS CLI from Linux
Next Post: How to use Azure Compute Gallery

Related Posts

  • QueryBitLocker1
    Query Windows BitLocker status remotely Windows
  • Feature image DEP
    Disable Data Execution Prevention and determine that hardware DEP is available and configured Security | Vulnerability Scans and Assessment
  • Featured image Periodic scanning
    How to enable or disable Windows Defender Antivirus Scanning periodically on Windows via Windows Settings Security | Vulnerability Scans and Assessment
  • Add or remove features   fix dotnet framework issues
    Fix the request to add or remove features on the specified server failed Windows
  • How to create a Recovery Partition in Microsoft Windows
    How to create a Recovery Partition in Microsoft Windows 10/11 Windows
  • Header picture 1
    Find BIOS Serial Number and System Information on Windows 11 Windows

More Related Articles

QueryBitLocker1 Query Windows BitLocker status remotely Windows
Feature image DEP Disable Data Execution Prevention and determine that hardware DEP is available and configured Security | Vulnerability Scans and Assessment
Featured image Periodic scanning How to enable or disable Windows Defender Antivirus Scanning periodically on Windows via Windows Settings Security | Vulnerability Scans and Assessment
Add or remove features   fix dotnet framework issues Fix the request to add or remove features on the specified server failed Windows
How to create a Recovery Partition in Microsoft Windows How to create a Recovery Partition in Microsoft Windows 10/11 Windows
Header picture 1 Find BIOS Serial Number and System Information on Windows 11 Windows

Leave a Reply Cancel reply

You must be logged in to post a comment.

Microsoft MVP

VEEAMLEGEND

vexpert-badge-stars-5

Virtual Background

GoogleNews

Categories

veeaam100

sysadmin top30a

  • Screenshot 2020 05 14 at 19.43.13
    Repo: How to setup Chef Repository Configuration Management Tool
  • Norton RDP
    Can’t connect via RDP upon installing Norton 360 Anti-Virus Solution
  • Telegram Bot for wordpress
    Configure Telegram to receive Blog Notifications JIRA|Confluence|Apps
  • remote desktop connection 5 1280x720 1
    How to view and remove Remote Desktop connection history Windows
  • GPO 2
    Why GPO is not the best solution for managing Windows updates Windows Server
  • How to Fix Microsoft Outlook Not Syncing Issue
    How to Fix Microsoft Outlook Not Syncing Issue Network | Monitoring
  • original
    Windows Deployment Services: WDSUTIL CommandLine Options on Windows Server 2019 Windows Server
  • maxresdefault
    How to extend a VM Hard Disk on VMware Workstation Virtualization

Subscribe to Blog via Email

Enter your email address to subscribe to this blog and receive notifications of new posts by email.

Join 1,839 other subscribers
  • RSS - Posts
  • RSS - Comments
  • About
  • Authors
  • Write for us
  • Advertise with us
  • General Terms and Conditions
  • Privacy policy
  • Feedly
  • Telegram
  • Youtube
  • Facebook
  • Instagram
  • LinkedIn
  • Tumblr
  • Pinterest
  • Twitter
  • mastodon

Tags

AWS Azure Bitlocker Microsoft Windows PowerShell WDS Windows 10 Windows 11 Windows Deployment Services Windows Server 2016

Copyright © 2025 TechDirectArchive

 

Loading Comments...
 

You must be logged in to post a comment.