Home › Knowledgebase › KB-041

How to encrypt USB drive

Summary

This guide helps you troubleshoot and resolve: How to encrypt USB drive. Follow the steps below to fix the issue.

Quick Tip: Need immediate assistance? đź’» Open a Ticket

Common Causes

Problem

You need to encrypt a USB flash drive to protect sensitive company data in case the drive is lost or stolen.

Why encrypt?

Important warning

  • Do not encrypt USB drives with tools that aren't approved by the company – IT may be unable to recover data if you use unsupported software.
  • Use company‑approved encryption tools when available.
  • Keep your password safe – if you lose it, data cannot be recovered.

Solutions

Method 1: Use BitLocker (recommended for Windows 11)

BitLocker To Go requires Windows Pro, Education or Enterprise and administrative rights. For full‑drive encryption the USB should be formatted as NTFS; BitLocker also supports FAT32 and exFAT, but only file‑level encryption is available on those file systems.

Before using BitLocker, make sure Windows is up to date. See How to update Windows.

Check if BitLocker is available

  1. Right‑click the USB drive in File Explorer.
  2. If you see “Turn on BitLocker”, the feature is available.
  3. If not, your edition of Windows may not support BitLocker To Go.

Encrypt the USB with BitLocker

  1. Insert the USB drive.
  2. Open File Explorer, right‑click the drive and select Turn on BitLocker.
  3. Choose Use a password to protect the drive and enter a strong password (minimum 12 characters, mixed case, numbers and symbols).
  4. Save the recovery key – print it or save to a secure location separate from the USB.
  5. Select Encrypt entire drive (more secure, slower).
  6. Choose Compatible mode to allow use on older Windows versions.
  7. Click Start encrypting and wait for the process to finish.

Using the encrypted USB

  1. Insert the USB into any company computer.
  2. Enter the password when prompted.
  3. Access your files normally.

Method 2: Use Windows built‑in encryption (EFS) – not recommended for removable drives

EFS only works on NTFS‑formatted volumes and the encrypted files are tied to the user account that performed the encryption. Removable drives formatted as FAT32 or exFAT cannot be encrypted with EFS, and the data will not be accessible on other computers.

For USB encryption, use BitLocker or an approved third‑party solution instead.

Method 3: Use company‑approved encryption software

  1. Open the Company Portal (Software Center) and look for approved tools such as “ESET Endpoint Encryption” or “McAfee Complete Data Protection”.
  2. If no tool is listed, Open a Ticket to request the appropriate software.
  3. Follow the vendor’s documentation to encrypt the USB drive.

Method 4: Use 7‑Zip (third‑party option)

  1. Download 7‑Zip from the official website.
  2. Right‑click the files or folders on the USB, choose 7‑Zip → Add to archive.
  3. Set “Archive format” to “zip”.
  4. Enter a password (minimum 12 characters recommended).
  5. Check “Encrypt file names” for additional security.
  6. Click OK to create the encrypted archive.
  7. To access the files, extract the archive and provide the password.

Best practices for USB encryption

What to do if you forget the password

There is no built‑in recovery method for encrypted USB drives. If the password is lost:

  • All data on the encrypted drive will be inaccessible.
  • The USB must be wiped and reformatted.
  • Contact IT via Open a Ticket if the data belongs to the company.

Need more help?

If you need a company‑approved encryption tool, are unsure which method to use, or require assistance with the encryption process, please Open a Ticket.

Still Having Issues?

Need more help? If the issue persists after trying these steps, please open a support ticket and our team will assist you.

đź’» Open a Ticket