Home › Knowledgebase › KB-517

How to enable and configure BitLocker encryption on Windows 11 Pro for company laptops

Summary

This guide helps you troubleshoot and resolve: How to enable and configure BitLocker encryption on Windows 11 Pro for company laptops. Follow the steps below to fix the issue.

Quick Tip: Need immediate assistance? 💻 Open a Ticket

Common Causes

BitLocker is a built-in encryption feature in Windows 11 Pro that protects the data on your laptop by encrypting the entire drive. If your device is lost, stolen, or accessed without authorisation, BitLocker ensures that sensitive business information remains unreadable without the correct recovery key. This guide walks you through enabling BitLocker, choosing the right unlock method for your environment, and safely storing the recovery key.

Before You Begin

Before turning on BitLocker, confirm the following prerequisites are met:

If your laptop is managed by your organisation via company policy, BitLocker may already be configured. Check with your administrator before making changes, as group policy settings can override local choices.

Enable BitLocker via Windows Settings

This is the quickest method for most users.

  1. Open Settings by pressing Windows + I.
  2. Navigate to Privacy & security > Device encryption.
    If you do not see Device encryption, your device may not support it or it may be managed by your organisation. Use the Control Panel method below instead.
  3. If the option is available, toggle Device encryption to On.
  4. Follow the prompts to choose how to back up the recovery key (see the next section).
  5. Restart the laptop if prompted. Encryption will begin in the background.

Enable BitLocker via Control Panel

Use this method if the Settings option is unavailable or you need access to advanced settings.

  1. Press Windows + R, type control panel, and press Enter.
  2. Set View by to Large icons or Small icons.
  3. Click BitLocker Drive Encryption.
  4. Next to the drive you wish to encrypt (typically OS (C:)), click Turn on BitLocker.
  5. Wait while Windows checks the system configuration. This can take a minute or two.

Choose an Unlock Method

After the system check, you will be prompted to choose how to unlock the drive at startup.

Use a TPM with a PIN (Recommended for Laptops)

This option uses the laptop's Trusted Platform Module (TPM) chip combined with a PIN you enter before Windows loads. It offers strong protection against physical tampering.

  1. Select Enter a PIN (only available if your device has a compatible TPM).
  2. Enter a PIN of at least 6 characters, then confirm it.
  3. Choose whether to require the PIN at every startup, or only when specific changes are detected (such as a USB device being inserted).

Use a TPM Only (No PIN)

This option unlocks the drive automatically when the TPM verifies the boot environment has not changed. It is more convenient but offers less protection if the laptop is stolen while powered on.

  1. Select Let BitLocker automatically unlock my drive.
  2. Confirm the choice to proceed.

Use a Startup Key on USB

This option requires a USB flash drive to be inserted before the laptop will boot. It is suited to high-security environments but is impractical for mobile staff.

  1. Select Insert a USB flash drive.
  2. Insert a blank or expendable USB drive and follow the prompts.
If you lose the startup USB or forget the PIN, you will need the recovery key to access the drive. Store it somewhere safe and separate from the laptop.

Back Up the Recovery Key

BitLocker generates a 48-digit recovery key during setup. Without it, you can be permanently locked out of the drive after a hardware change or boot failure.

Choose one or more of the following backup options:

For company-issued laptops, your IT team recommends saving the recovery key to both the user's Microsoft account and a printed copy stored with the IT documentation. This ensures the key is recoverable even if the user leaves the organisation.

Choose the Encryption Mode

You will be asked to choose between two encryption modes:

Select the appropriate option and click Next.

Start Encryption

  1. Review the summary screen and click Start encrypting.
  2. Encryption runs in the background. You can continue using the laptop, though performance may be slightly reduced until the process completes.
  3. A small BitLocker icon will appear in the system tray showing the progress.

Encryption time depends on the drive size and amount of data. A typical 500 GB SSD takes between 20 minutes and one hour.

Do not turn off the laptop or interrupt encryption once it has started. Doing so can corrupt the drive and make data unrecoverable.

Verify BitLocker Is Active

Once encryption finishes, confirm it is working correctly:

  1. Open Control Panel > BitLocker Drive Encryption.
  2. Confirm that the drive shows BitLocker on.
  3. Alternatively, open Settings > Privacy & security > Device encryption and confirm the toggle is On.

Troubleshooting

BitLocker option is missing

Encryption fails to start

BitLocker is asking for a recovery key unexpectedly

This usually means the TPM has detected a change in the boot environment, such as a hardware modification or a BIOS update. To resolve this:

Performance is slow after encryption

Suspending or Turning Off BitLocker

If you need to perform hardware changes, update firmware, or troubleshoot boot issues, you can temporarily suspend BitLocker protection:

  1. Open Control Panel > BitLocker Drive Encryption.
  2. Next to the encrypted drive, click Suspend protection.
  3. Choose whether to suspend for a single restart or indefinitely.
  4. After completing your task, return to the same screen and click Resume protection.

To permanently decrypt the drive, click Turn off BitLocker on the same screen and confirm. Decryption can take a similar amount of time to the original encryption process.

Turning off BitLocker leaves the drive fully unprotected. Only do this if the laptop is being decommissioned, wiped, or reassigned within the organisation.

Getting Further Help

If you have followed this guide and BitLocker is still not working as expected, contact your IT support team with the following information:

Do not attempt to force decryption or delete BitLocker protectors without guidance from your IT team, as this can result in permanent data loss.

Still Having Issues?

Need more help? If the issue persists after trying these steps, please open a support ticket and our team will assist you.

💻 Open a Ticket