Updated: October 2026
Turning BitLocker on takes a few clicks. The trouble shows up later, when a firmware update or a swapped motherboard asks for a recovery key nobody saved. Here's how to run BitLocker on Windows 10 and Windows 11 so both halves work: the encryption, and the key you'll need the day the recovery screen shows up.
Device Encryption vs BitLocker
Windows ships two versions of the same idea. Both use the BitLocker engine. They differ in who turns them on and where the key goes.
Device encryption is the automatic version. On a qualifying PC it encrypts the OS drive and fixed drives after setup, then removes the clear key once the recovery key is backed up. On a work device that backup goes to Microsoft Entra ID or Active Directory. On a personal device it goes to the Microsoft account used to sign in. Device encryption is available on every Windows edition, including Home, but it doesn't encrypt USB drives and gives you few settings.
BitLocker is the managed version. It needs Windows Pro, Enterprise or Education. You choose the protectors, the encryption method, used space or full disk, removable drives, and where recovery information must be stored before encryption starts. For company devices, that's the one you want.
Windows 11 24H2 widened the net. Microsoft removed the DMA and HSTI/Modern Standby prerequisites for device encryption, so more PCs now encrypt themselves after a clean install. Worth knowing before you reimage a fleet and wonder why some laptops came back encrypted.
Check the PC Before You Turn It On
BitLocker gets its best protection from a TPM. The TPM checks the boot chain and only releases the key if nothing was tampered with. That needs TPM 1.2 or later, and TPM 2.0 needs native UEFI mode with Legacy and CSM turned off. If a machine says it has no TPM, fix that first. Our guide to TPM device not detected covers firmware settings and the Windows side.
The drive layout matters too. BitLocker needs a small unencrypted system partition next to the OS drive. A normal Windows install creates it, so this only bites on odd images and cloned disks.
Two quick checks tell you where a PC stands. msinfo32 shows "Device Encryption Support" and, if it says "Meets prerequisites," the hardware qualifies. manage-bde -status shows each volume, its encryption method and whether protection is on.
How to Enable BitLocker on Windows 10 and 11
On a single PC, the Control Panel wizard is the fastest route:
- Open Manage BitLocker and select Turn on BitLocker next to the OS drive.
- Save the recovery key to your Entra ID or Microsoft account, a file on another device, or a printout. Never to the drive you're encrypting.
- Choose Encrypt entire drive for any PC that already has data on it.
- Pick New encryption mode unless the drive will move to an older Windows version.
- Restart and let the system check run.
"Used space only" is faster, but Microsoft is clear about the catch: deleted files look like free space, so they stay unencrypted until something overwrites them. On a new PC that never held data, used space only is fine. On a laptop that's been in use for a year, encrypt the whole drive.
For scripts, PowerShell and manage-bde do the same job:
powershell# Status of every volume Get-BitLockerVolume | Format-Table MountPoint, VolumeStatus, ProtectionStatus, EncryptionPercentage # Turn on BitLocker with a TPM protector and add a recovery password Enable-BitLocker -MountPoint C: -EncryptionMethod XtsAes128 -TpmProtector Add-BitLockerKeyProtector -MountPoint C: -RecoveryPasswordProtector
This walkthrough covers what BitLocker protects against and the first setup on a single PC:
TPM Only or TPM Plus PIN
A TPM-only protector unlocks the drive automatically at boot. Users never see it. It stops the "pull the drive and read it elsewhere" attack, which covers the lost-laptop case.
TPM plus a startup PIN adds a second factor before Windows loads. It's the stronger setting for people who carry sensitive data or travel. It's also the setting that breaks silent enrollment, because a PIN needs a person at the keyboard.
A startup key on a USB drive is the option for PCs without a TPM. Password-only protection for the OS drive exists, but Microsoft disables it by default because it has no lockout.
Escrow the Recovery Key Before You Need It
The recovery key is the whole game. BitLocker without an escrowed key is a data-loss feature with a nicer name.
Store keys centrally. For Entra-joined devices, the recovery password lives on the device object in Entra ID. For domain-joined devices, it's a child object of the computer account in AD DS. Set the "Choose how BitLocker-protected operating system drives can be recovered" policy, and turn on Do not enable BitLocker until recovery information is stored. That one setting blocks encryption on any machine that can't reach the escrow target, so you never end up with an encrypted drive and no key.
Machines that were encrypted before they joined your tenant are the usual gap. You can push the key up by hand, or in a remediation script:
powershell$v = Get-BitLockerVolume -MountPoint C: $id = ($v.KeyProtector | Where-Object KeyProtectorType -eq 'RecoveryPassword').KeyProtectorId BackupToAAD-BitLockerKeyProtector -MountPoint C: -KeyProtectorId $id # Domain-joined instead: Backup-BitLockerKeyProtector -MountPoint C: -KeyProtectorId $id
This r/Intune thread is the case you're trying to avoid: a locked drive, and no key in Entra or Intune.
The replies suggest a remediation script that forces the key into Entra. That only helps while the drive is still unlocked, which is why escrow has to be checked, not assumed.
Turning It On Across a Fleet With Intune
In Intune, BitLocker lives under Endpoint security > Disk encryption, in a BitLocker profile. Microsoft recommends that profile over the Settings Catalog for BitLocker, because the catalog lacks the TPM startup controls silent enablement needs.
Silent encryption, where users see nothing, has a short list of requirements: Entra joined or hybrid joined, a TPM, native UEFI, Secure Boot on and Windows RE available. In the profile, set Require Device Encryption to enabled, Allow Warning For Other Disk Encryption to disabled, and Allow Standard User Encryption to enabled if people don't run as admins. The TPM startup settings must not allow a PIN or startup key. Microsoft warns that the Defender security baseline can turn those on by default and quietly block silent enablement.
Two admin details save a lot of tickets. The Encryption report under Devices > Monitor shows which machines are encrypted and whether their keys reached Entra. And with rotation enabled in policy, the BitLocker key rotation device action issues a new recovery password after one has been read out to a user. More on the rest of the console is in our Microsoft Intune review.
To check a mixed fleet outside Intune, Get-BitLockerVolume returns everything you need in one line per volume. OpenFrame can run it as a script across a client's devices and collect the output, so unencrypted and suspended drives show up in one list.
What Triggers BitLocker Recovery
The recovery screen appears when the TPM sees a boot chain it doesn't recognize. Often that's routine maintenance, not an attack. Microsoft's list of common triggers includes:
- A BIOS or UEFI firmware upgrade
- Turning off, clearing or resetting the TPM
- Changes to the boot manager or the partition table
- A CD, DVD or PXE entry placed ahead of the disk in the boot order
- Docking or undocking a laptop
- Too many wrong PIN entries
Firmware updates are the trigger you can plan for. Suspend BitLocker before you flash, and it resumes on its own after the next restart. For updates that reboot more than once, set a reboot count:
powershellSuspend-BitLocker -MountPoint C: -RebootCount 2
Suspending doesn't decrypt anything. It leaves the key readable for the reboots you asked for, then reseals it. Our guide to a BIOS update shows where this fits in the update order.
The same rule covers docks, SSDs and network cards. Our guide to updating other firmware walks through each one.
Suspension can also go wrong. In this thread, a firmware update suspended protection and it never resumed. The drive was decrypted and re-encrypted, and the new key wouldn't save to Entra:
The fix the replies point to is the same backup command from the escrow section, plus the BitLocker event log to see why the upload failed.
Finding a Recovery Key, and When There Isn't One
The recovery screen shows a Key ID. Match it to the stored key. In Intune, open the device and select Recovery keys. In Entra, it's on the device object. For domain-joined PCs, look under the computer account in Active Directory. Every lookup in Entra is audit-logged, and Microsoft Entra ID holds up to 200 keys per device, which matters on machines that re-encrypt often.
If there's no key anywhere, there's no way in. That's the design. A data recovery agent certificate helps only if you configured one in policy, and the BitLocker Repair Tool still needs a key package plus a recovery password to salvage a damaged drive. Without those, the answer is a wipe and a restore from backup. Plan the escrow, and this section stays theoretical.
BitLocker, in Short
Use device encryption where it turns itself on, and managed BitLocker on every company PC. Require escrow before encryption, check the Encryption report, and suspend with a reboot count before firmware updates. Have a lookup path ready for the day the recovery screen shows up.
Managing Macs too? FileVault is the Apple equivalent, and the key escrow rules are the same idea on a different platform.

Aliaska Varieva
Head of Platform
Hi! I’m Aliaska, and I’ve been working as a software engineer (mostly Java + a bit Kotlin) for over 8 years now. I mostly spend my time building backend services, integrating systems, fixing bugs (the fun part 🙃), and making sure things don’t fall apart behind the scenes.
