Skip to content
WindowsAdvanced

What Is BitLocker? How Windows Drive Encryption Protects Your Data

QUICK ANSWER BitLocker is Microsoft’s built-in full-volume encryption technology for Windows that protects data stored on a computer or drive from unauthoriz...

BI
Bison Technical Team Enterprise IT specialists
Updated 04 Sep 2026 15 min read 1 total views

QUICK ANSWER

BitLocker is Microsoft’s built-in full-volume encryption technology for Windows that protects data stored on a computer or drive from unauthorized offline access. It is especially useful if a laptop, desktop, SSD, or hard drive is lost, stolen, removed from the computer, or accessed using another operating system.

BitLocker encrypts the contents of a protected volume so that simply removing the SSD or hard disk and connecting it to another computer does not provide readable access to the files. Microsoft recommends using BitLocker with a Trusted Platform Module (TPM) for stronger protection and startup integrity checking.

Advertisement

A critical part of BitLocker is the recovery password, commonly called the BitLocker recovery key. The recovery password is a 48-digit number that can unlock the encrypted volume when its normal unlocking method is unavailable. Losing all available recovery information can make the encrypted data inaccessible.


COMPLETE ARTICLE

What Is BitLocker?

BitLocker is a data-protection feature integrated into Microsoft Windows. It provides full-volume encryption, meaning that the information stored on a protected Windows volume is encrypted rather than merely hidden or protected by Windows file permissions.

Its primary purpose is to protect data at rest against unauthorized access when someone gains physical access to a computer or storage device. Microsoft specifically positions BitLocker as protection against data exposure resulting from lost, stolen, or improperly decommissioned computers and drives.

For example, imagine that a company laptop containing customer records, financial documents, saved files, emails and other confidential information is stolen.

Without disk encryption, an attacker might remove its SSD, connect the SSD to another computer and attempt to read the files without knowing the original user's Windows password.

With BitLocker properly enabled, the information on the protected volume remains encrypted and cannot simply be read by attaching the drive to another computer.

In simple terms:

Windows password protects access to your Windows account.

BitLocker protects the data stored on the encrypted drive itself.

These are related security controls, but they are not the same thing.


Why Is BitLocker Important?

Modern computers can contain enormous amounts of confidential information, including:

  • Business documents
  • Customer information
  • Accounting data
  • Emails
  • Saved browser information
  • Personal photographs and documents
  • Financial records
  • Software databases
  • Company reports
  • Intellectual property
  • Backup files

Windows account permissions are important, but they do not by themselves provide the same protection against offline attacks.

Microsoft explains that without additional protection, someone with physical access to an unencrypted operating-system volume may be able to boot another operating system and bypass normal Windows file permissions. BitLocker addresses this problem by encrypting the volume.

This makes BitLocker particularly valuable for laptops because laptops have a higher risk of being lost or stolen.


How Does BitLocker Work?

BitLocker encrypts information before it is stored on the protected volume and decrypts it when authorized access is available.

Microsoft states that BitLocker uses the Advanced Encryption Standard (AES). Current BitLocker configurations support encryption using XTS or CBC modes with 128-bit or 256-bit key lengths, depending on configuration and policy.

The process is transparent during normal Windows operation.

When the computer starts normally and BitLocker successfully validates the expected security conditions, Windows can access the encrypted operating-system volume.

If BitLocker detects a condition that prevents normal unlocking, however, Windows may enter BitLocker Recovery and request recovery information.


What Is TPM and How Does It Work with BitLocker?

TPM stands for Trusted Platform Module.

A TPM is a security component used by Windows for cryptographic and security operations. It can protect cryptographic keys and tie them to specific platform conditions.

BitLocker provides its strongest and most convenient protection when used with a TPM.

During startup, the TPM can help BitLocker verify that important boot components have not unexpectedly changed before releasing the information required to unlock the operating-system volume.

Microsoft's current BitLocker requirements support TPM 1.2 or later for TPM-based system-integrity checking, although modern Windows 11 computers normally use TPM 2.0.

BitLocker with TPM

A common configuration is:

Computer starts → TPM checks expected startup conditions → BitLocker unlocks the Windows volume → Windows starts normally

The user may therefore use a BitLocker-protected computer every day without manually entering a BitLocker password.


Can BitLocker Work Without TPM?

Yes.

Microsoft supports BitLocker on an operating-system drive without a TPM, but the configuration is different.

For example, a startup key stored on removable media can be required. A computer without TPM also loses the preboot system-integrity verification that TPM-based BitLocker provides.

For modern computers, using BitLocker together with TPM is generally the preferred configuration.


BitLocker vs Windows Login Password

One of the most common misconceptions is that a Windows password and BitLocker perform the same job.

They do not.

Security Feature Main Purpose
Windows Password/PIN Controls access to the Windows user account
Windows Hello Provides secure user authentication
BitLocker Encrypts data stored on a volume
TPM Hardware-backed security that can protect cryptographic keys and startup integrity

Suppose an unencrypted SSD is removed from a Windows computer.

The Windows account password does not necessarily prevent someone from attempting to access files through another operating system or computer.

BitLocker is designed to protect against this type of offline access.


What Drives Can BitLocker Protect?

BitLocker technologies can protect several types of storage.

Operating System Drive

Usually:

C:

This contains Windows, installed applications and user profiles.

Fixed Data Drives

For example:

D:

E:

These can also be encrypted using BitLocker.

Removable Drives

Microsoft calls BitLocker encryption for removable storage BitLocker To Go.

It can be used with removable storage such as:

  • USB flash drives
  • External hard drives
  • External SSDs
  • SD cards

BitLocker To Go drives can be configured with supported unlock methods such as a password or smart card.


Which Windows Editions Support BitLocker?

According to Microsoft's current BitLocker documentation, BitLocker enablement is supported on editions including:

  • Windows Pro
  • Windows Enterprise
  • Windows Pro Education/SE
  • Windows Education

Microsoft separately provides Device Encryption, which can automatically enable BitLocker-based encryption on eligible Windows devices and has different availability and requirements.

Therefore, you should not assume that the BitLocker management interface available on Windows Pro will appear identically on every Windows edition.


BitLocker vs Device Encryption

BitLocker and Device Encryption are closely related but should not be treated as identical user experiences.

BitLocker

Traditional BitLocker provides administrators and advanced users with more configuration and management options.

Device Encryption

Device Encryption simplifies the process and can automatically enable BitLocker encryption on qualifying systems.

Microsoft states that Device Encryption encrypts the operating-system drive and fixed drives, but not external/USB drives. Starting with Windows 11 version 24H2, Microsoft removed some previous hardware prerequisites, allowing more devices to qualify for automatic or manual Device Encryption.

This is important because a new Windows 11 computer may already have encryption enabled even if the owner does not remember manually configuring traditional BitLocker.


How to Check Whether BitLocker Is Enabled

There are several supported ways to check BitLocker status.

Method 1: Control Panel

On supported Windows editions, open:

Control Panel → System and Security → BitLocker Drive Encryption

You can review the BitLocker status of available drives.

Method 2: Command Prompt

Open Command Prompt as Administrator and run:

manage-bde -status

The command displays information about BitLocker-capable volumes, including encryption and protection status.

Method 3: PowerShell

Open PowerShell as Administrator and run:

Get-BitLockerVolume

This is particularly useful for administrators managing Windows computers.

Administrator Rights

Some BitLocker management operations require administrative privileges. Do not change encryption settings on a business-managed computer unless you are authorized to do so.


What Is a BitLocker Recovery Key?

This is one of the most important concepts to understand before using BitLocker.

When normal BitLocker unlocking is unavailable, Windows can enter recovery mode.

A BitLocker recovery password is a 48-digit numerical value that can be used to unlock the protected volume. Microsoft also distinguishes this from a recovery key stored as a .bek file on removable media. In everyday Windows interfaces, however, users commonly refer to the 48-digit recovery password simply as their "BitLocker recovery key."

It may look conceptually like:

XXXXXX-XXXXXX-XXXXXX-XXXXXX-XXXXXX-XXXXXX-XXXXXX-XXXXXX

The actual recovery password contains numeric digits.

IMPORTANT WARNING

Do not lose your BitLocker recovery information.

Microsoft explicitly warns that BitLocker is designed so encrypted data cannot simply be recovered without the required authentication. If the system enters recovery mode and no valid recovery password or recovery key is available, the encrypted information may be inaccessible.


Where Can a BitLocker Recovery Key Be Stored?

Depending on how the computer is configured, recovery information may be stored in locations such as:

  • Microsoft account
  • Microsoft Entra ID
  • Active Directory Domain Services
  • A file
  • USB storage
  • A printed copy
  • An organization-managed recovery system

Microsoft supports centralized storage of recovery information in Microsoft Entra ID and Active Directory Domain Services (AD DS) for managed environments.

Recommended Practice

Before making significant BIOS, UEFI, TPM, disk, boot or hardware changes to a BitLocker-protected computer, make sure that the required recovery information is available.

Do not wait until Windows displays the BitLocker Recovery screen to start looking for it.


Why Does Windows Suddenly Ask for a BitLocker Recovery Key?

A recovery request does not automatically mean that the computer has been hacked.

BitLocker recovery can be triggered when BitLocker cannot use its normal unlock mechanism or detects certain changes in the expected startup environment.

Potential scenarios can involve changes to:

  • TPM configuration
  • BIOS or UEFI configuration
  • Secure Boot
  • Boot configuration
  • Boot components
  • Hardware
  • Firmware
  • Security policies

A recovery request should therefore be investigated in context rather than automatically treated as malware.


What Should You Do Before Changing BIOS or TPM Settings?

If BitLocker is enabled, be careful before modifying:

  • TPM settings
  • Secure Boot
  • UEFI/BIOS settings
  • Boot order or boot configuration
  • Motherboard-related security settings
  • Certain firmware configurations

Recommended Procedure

  1. Check whether BitLocker is enabled.
  2. Verify that the recovery information is safely backed up.
  3. Record which drives are encrypted.
  4. Follow the hardware manufacturer's and Microsoft's supported procedure for the intended change.
  5. Where appropriate, suspend BitLocker protection before an authorized firmware or hardware operation.
  6. Resume protection afterward.

Never clear or reset the TPM merely as a trial-and-error troubleshooting step without understanding the consequences and confirming recovery information first.


Does BitLocker Protect Against Viruses and Ransomware?

No.

BitLocker is primarily data-at-rest encryption, not antivirus software.

Once Windows has started normally and the BitLocker volume is unlocked, applications running under Windows can access data according to their permissions.

Therefore, malware or ransomware operating with sufficient access may still:

  • Read files
  • Modify files
  • Delete files
  • Encrypt files
  • Steal accessible information

You still need appropriate security controls such as:

  • Microsoft Defender or another reputable endpoint-security product
  • Regular security updates
  • Secure user permissions
  • Strong authentication
  • Reliable backups
  • Phishing protection
  • Application security

BitLocker complements these protections; it does not replace them.


Does BitLocker Replace Backup?

No.

This distinction is extremely important.

BitLocker protects information primarily from unauthorized access.

A backup protects information from loss.

BitLocker does not by itself protect you from:

  • Accidental deletion
  • SSD failure
  • Hard-drive failure
  • File corruption
  • Ransomware
  • Accidental formatting
  • Application/database corruption
  • Loss of the computer

For important systems, use both:

Encryption + Backup

not:

Encryption instead of Backup


Does BitLocker Slow Down a Computer?

BitLocker encryption adds cryptographic work to storage operations, but the real-world effect depends on hardware, workload and Windows configuration.

Modern processors and storage platforms are designed with encryption workloads in mind. Microsoft has also introduced hardware-accelerated BitLocker capabilities on supported modern platforms, including cryptographic offloading and hardware-protected keys.

For typical modern business computers with SSDs, security benefits generally outweigh the potential performance impact.

Performance-sensitive enterprise workloads should still be tested using the actual hardware, storage configuration and applications involved rather than relying on a universal performance percentage.


BitLocker Encryption Methods

Microsoft BitLocker uses AES encryption and supports configurable encryption settings.

Depending on Windows version and policy, BitLocker can use configurations including:

  • XTS-AES 128-bit
  • XTS-AES 256-bit
  • AES-CBC 128-bit
  • AES-CBC 256-bit

Microsoft states that AES-128 is the default in relevant BitLocker configurations, while administrators can configure encryption methods through policy. Device Encryption currently uses XTS-AES 128-bit by default unless policy specifies otherwise.

For most users, changing the default encryption algorithm without a specific security or organizational requirement is unnecessary.


Used Space Only vs Full Drive Encryption

When enabling BitLocker manually, Windows may offer options such as encrypting only used disk space or encrypting the entire drive.

Encrypt Used Disk Space Only

Generally faster when setting up a new computer or newly formatted drive because only currently used areas need to be encrypted initially.

Encrypt Entire Drive

Encrypts the full volume, including currently unused space.

This can be appropriate for an existing drive that has previously contained sensitive information.

The correct choice depends on how the drive has been used and the organization's security requirements.


BitLocker To Go for USB Drives

BitLocker is not limited to internal Windows drives.

BitLocker To Go provides encryption for removable storage devices.

For example, suppose an employee carries confidential customer information on an external USB drive.

Without encryption:

Lost USB → Potentially readable data

With BitLocker To Go:

Lost USB → Encrypted data requiring authorized unlocking

Microsoft supports BitLocker To Go for removable media such as USB flash drives, SD cards and external drives.

This can be particularly valuable for businesses where staff regularly transport confidential information.


Can BitLocker Protect a Drive Removed from the Computer?

Yes—this is one of its primary purposes.

If an encrypted SSD or hard disk is removed from the original computer and connected to another system, its protected information remains encrypted unless valid unlocking or recovery information is supplied.

This helps defend against attacks where someone physically steals:

  • A laptop
  • A desktop computer
  • An SSD
  • A hard disk
  • A removable encrypted drive

Physical possession of the storage device alone should not provide readable access to properly protected BitLocker data.


Is BitLocker Recommended for Business Computers?

In many environments, yes.

BitLocker can be particularly valuable on systems containing:

  • Accounting information
  • Customer databases
  • Financial records
  • Employee records
  • Business email
  • Confidential documents
  • Intellectual property
  • Personally identifiable information
  • Company credentials or locally cached information

Laptops deserve particular attention because they are easier to lose or steal.

Organizations should combine BitLocker with properly managed recovery keys, backups, endpoint security, access control and documented recovery procedures.


BitLocker Best Practices

For reliable BitLocker deployment, consider these practices:

  1. Back up recovery information before you need it.
  2. Prefer TPM-based protection on compatible modern computers.
  3. Verify recovery-key storage for every important device.
  4. Do not store the only recovery copy solely on the encrypted computer.
  5. Keep independent backups of important information.
  6. Check BitLocker status before major BIOS, TPM or hardware changes.
  7. Use centralized recovery-key management for business computers where practical.
  8. Document which computers and drives are encrypted.
  9. Restrict access to stored recovery information.
  10. Test organizational recovery procedures before an emergency occurs.

For business deployments, centralized recovery management through Active Directory, Microsoft Entra ID or appropriate device-management policies is preferable to depending on employees to manually keep recovery information.


Advantages and Limitations of BitLocker

Advantages Limitations
Protects data at rest Does not replace antivirus
Helps protect stolen computers Does not replace backups
Encrypts complete volumes Recovery information must be protected
Integrates with Windows Some BitLocker management capabilities depend on Windows edition
Works with TPM Incorrect system changes can trigger recovery
Supports fixed drives Encryption does not prevent all attacks while Windows is unlocked
BitLocker To Go protects removable media Lost recovery information can create serious data-access problems
Supports enterprise management Requires planning in managed environments

Is BitLocker Safe?

BitLocker is a mature Windows security technology designed specifically to protect data stored on encrypted volumes. Microsoft supports it across current Windows client and Windows Server platforms.

The bigger operational risk for many users is not the encryption technology itself—it is poor recovery-key management.

Before enabling encryption on important business systems, establish:

  • Where recovery information will be stored
  • Who is authorized to access it
  • How it will be recovered during an emergency
  • How important files are separately backed up

Encryption without recovery planning can create unnecessary operational risk.


FAQ

What is BitLocker in simple words?

BitLocker is a Windows security feature that encrypts a drive so that its stored information cannot easily be accessed without proper authorization if the computer or storage device is lost, stolen or removed.

Is BitLocker free?

BitLocker is included with supported Windows editions rather than sold as a separate standalone encryption application. Traditional BitLocker enablement is supported on editions such as Windows Pro, Enterprise and Education. Device Encryption has different Windows availability and hardware requirements.

Does Windows 11 have BitLocker?

Yes. Windows 11 supports BitLocker, although available management features and Device Encryption behavior depend on Windows edition and device configuration.

Is BitLocker available in Windows Home?

Traditional BitLocker enablement licensing is associated with supported editions such as Pro, Enterprise and Education. However, Device Encryption can be available on qualifying Windows devices and uses BitLocker technology.

What is the BitLocker recovery key?

In common Windows terminology, it usually refers to the 48-digit recovery password used to regain access to an encrypted BitLocker volume when its normal unlocking mechanism cannot be used. Microsoft also defines a separate recovery-key file that can be stored on removable media.

Why is my computer asking for a BitLocker recovery key?

BitLocker may enter recovery mode when it cannot use its normal unlocking mechanism or when security-related startup conditions have changed. This can occur after certain TPM, firmware, Secure Boot, boot or hardware changes.

Can Microsoft recover BitLocker data without the recovery key?

BitLocker is intentionally designed to prevent unauthorized decryption. Microsoft states that when the drive is in recovery mode, valid recovery information is required to unlock the encrypted drive.

Can BitLocker protect an external hard drive?

Yes. Removable storage can be protected using BitLocker To Go.

Does BitLocker protect against ransomware?

Not directly. BitLocker protects data at rest against unauthorized offline access. It does not prevent ransomware running inside an already unlocked Windows session from modifying accessible files.

Does BitLocker replace antivirus?

No. BitLocker and antivirus software address different security risks.

Does BitLocker replace backup?

No. Encryption protects confidentiality; backups protect availability and recoverability. Important information should still be backed up independently.

Should I disable BitLocker?

Normally, BitLocker should not be disabled simply because encryption is unfamiliar. If you have a legitimate technical or operational reason to disable it, first confirm that important information is backed up and understand the security implications of leaving the drive unencrypted.

Should I save my BitLocker recovery key?

Yes. Recovery information should be stored securely somewhere that remains accessible if the encrypted computer itself cannot start.


FINAL RECOMMENDATION / CONCLUSION

BitLocker is one of the most important built-in Windows security technologies for protecting information stored on computers and drives.

For laptops, business computers and systems containing confidential information, properly configured drive encryption can significantly reduce the risk of data exposure if the computer or storage device is lost or stolen.

The most important rule is simple:

Do not enable or manage BitLocker without having a reliable recovery-key strategy.

Before making major BIOS, UEFI, TPM, Secure Boot, boot or hardware changes, verify your BitLocker status and ensure the necessary recovery information is safely available.

For business environments, BitLocker should form part of a broader security strategy that includes TPM, strong authentication, endpoint protection, software updates, access controls, secure recovery-key management and reliable backups.

 

#BitLocker #WindowsBitLocker #BitLockerEncryption #DriveEncryption #DiskEncryption #WindowsEncryption #DataEncryption #DataProtection #WindowsSecurity #CyberSecurity #BitLockerRecovery #RecoveryKey #BitLockerRecoveryKey #TPM #TPM20 #TrustedPlatformModule #Windows11 #Windows10 #MicrosoftWindows #DeviceEncryption #BitLockerToGo #USBEncryption #ExternalDrive #SSDEncryption #HardDriveEncryption #FullDiskEncryption #FullVolumeEncryption #DataSecurity #LaptopSecurity #BusinessSecurity #ITSecurity #InformationSecurity #WindowsTips #WindowsGuide #TechGuide #TechnicalSupport #WindowsSupport #SystemAdministrator #ITAdministrator #PowerShell #ManageBDE #AES #XTSAES #SecureBoot #UEFI #MicrosoftSecurity #EndpointSecurity #DataAtRest #SecurityBestPractices #Knowledgebase

YOUR FEEDBACK

Was this guide useful?

Your answer helps us keep BISONKB accurate and practical.

THE BISON BRIEF

Practical IT knowledge, once a week.

New troubleshooting guides, scripts and infrastructure notes. No noise.

By subscribing, you agree to our privacy policy.