Enabling and Configuring BitLocker Drive Encryption
Windows troubleshooting
BitLocker
encryption
security
drive
By Kerry · Updated 03/05/26 07:34 AM
BitLocker encrypts the entire Windows drive, protecting data if a laptop is lost or stolen. It requires Windows 10/11 Pro, Enterprise, or Education and a TPM 2.0 chip (standard on most business laptops since 2016).
To enable: search for 'Manage BitLocker' in the Start menu and click Turn on BitLocker for the C: drive. Choose how to unlock at startup (TPM only is seamless for users), then choose where to save the recovery key — saving to Active Directory or Azure AD is strongly recommended for enterprise environments so IT can recover access if needed.
The recovery key is a 48-digit code needed if BitLocker locks the drive (e.g., after BIOS changes or motherboard swap). Store it somewhere secure and separate from the device. For organization-wide deployment, manage BitLocker through Microsoft Intune or Group Policy. Enable encryption silently in background mode using the MDM policy 'RequireDeviceEncryption'.