You can use BitLocker encryption for extra data security. Here's how to enable the feature on Windows 11.
BitLocker on Windows 11 adds an extra layer of security with encryption to protect your device and files from unauthorized access. When using encryption, the feature scrambles the data on the drive to make it unreadable for anyone without the correct decryption key.
The BitLocker security feature is available on Windows 11 Pro, Enterprise, and Education editions. However, on Windows 11 Home, you can use "device encryption," a limited version of BitLocker. It works identical to the full version but without many of the advanced management settings and capabilities, such as "BitLocker To Go." Also, when using device encryption, all the drives will encrypt automatically, while the full version of BitLocker allows you to choose the storage using encryption.
In this Windows 11 guide, we will walk you through the steps to get started setting up device encryption with BitLocker on your computer.
How to set up BitLocker on Windows 11 Pro
To configure BitLocker in the Pro edition of Windows 11, use these steps:
- Open Settings.
- Click on Storage.
- Under the "Storage management" section, click on Advanced storage settings.
Click on Disks & volumes.
- Select the drive with the partition to encrypt.
- Select the partition to enable encryption.
Click the Properties button.
Click the Turn on BitLocker option.
Click the Turn on BitLocker option again.
Select the option to back up the recovery key — for example, Save to your Microsoft account.
Quick note: You can always find the recovery key on your Microsoft account. Also, the option to save online is only available when the account is connected with a Microsoft account.
- Click the Next button.
Select the Encrypt used disk space only option.
- Click the Next button.
Select the New encryption mode option.
Check the Run BitLocker system check option.
- Click the Restart now button (if applicable).
Once you complete the steps, the system will begin encrypting the data on the drive.
While in the "BitLocker Drive Encryption," it is also possible to encrypt other drives, such as secondary storage, external USB hard drives, and removable data drives, using "BitLocker To Go."
Remove BitLocker encryption
If you need to remove the system encryption, use these steps:
- Open Control Panel.
- Click on System and Security.
Click on BitLocker Drive Encryption.
Under the "Operating system drive" section, click the Turn off BitLocker option.
- Click the Turn off BitLocker button again.
After you complete the steps, the decryption process will take a while, depending on how large the drive is and your data.
How to set up BitLocker on Windows 11 Home
To configure BitLocker in the Home edition of Windows 11, use these steps:
- Open Settings.
- Click on Privacy & Security.
Click the Device encryption setting.
Turn on Device encryption toggle switch.
- (Optional) Under the "Related" section, click the BitLocker drive encryption option.
Under the "Operating system drive" section, click the Back up your recovery key option.
- Click the Save to a file option.
- Save the BitLocker recovery key in a different location.
- Click the Save button.
Once you complete the steps, BitLocker will turn on the system to encrypt the files on the drive.
This version of BitLocker is only available on some devices. If you don't find the option, the device most likely doesn't support device encryption. You would typically see this feature on devices like Microsoft Surface devices, and those from other brands like HP, Lenovo, Dell, etc.
Remove BitLocker encryption
To decrypt a device using BitLocker, use these steps:
- Open Settings.
- Click on Privacy & Security.
Click the Device encryption setting.
Turn off the Device encryption toggle switch.
After you complete the steps, the decryption process will begin on the device.
More Windows resources
For more helpful articles, coverage, and answers to common questions about Windows 10 and Windows 11, visit the following resources: