Device Encryption in Windows 11 and 10: Home vs BitLocker
To check whether your drive is encrypted right now, open Settings and go to Privacy & security, then look for Device encryption. If the switch is there and turned on, your drive is locked. If the section does not appear at all, your hardware does not qualify and you are not encrypted.
That is the answer. Here is the part that catches people, and it is worth knowing before you touch the switch.
On Windows Home, encrypting your drive and handing your recovery key to Microsoft are not two decisions. They are the same switch. Device Encryption on Home completes only when you sign in with a Microsoft account, because that account is the one place it is willing to store the key. Sign in with a local account instead and the encryption does not finish at all.
You cannot have one without the other on Home. That is not a setting buried somewhere you have not found — it is how the feature is built. And since Windows 11 version 24H2, qualifying machines turn this on by themselves during setup, which means a great many people reading this are already encrypted and have never once thought about where their key is.
That is fine. Right up until the morning the machine asks for it.
The Laptop Jake Could Not Save
A customer brought Jake a two-year-old laptop that would not power on. Dead board — a common enough failure and normally an easy conversation, because the drive is a separate component and the data on it is fine. Jake has recovered files from dead laptops hundreds of times. Pull the drive, put it in an enclosure, copy the photos off, hand back a folder and a bill for twenty minutes of work.
He pulled the drive. He plugged it into his bench machine. Windows offered to format it.
The drive was encrypted. Not by the customer, who had never heard the word BitLocker and certainly had never switched anything on. It had encrypted itself during setup, silently, because the laptop qualified and she had signed in with the Microsoft account that came with her email. The key was sitting in that account, waiting, perfectly safe.
She could not remember the password to the account. It was an old address she had stopped using, tied to a phone number she had changed. Microsoft's account recovery asks you to prove ownership, and every proof she had was on the laptop that would not turn on.
Ethan's response, when Jake told him, was not sympathy. It was: "So the encryption worked exactly as designed. That is the uncomfortable part."
He is right, and it is the reason this page exists in the shape it does. Encryption is not a feature that fails you. It is a feature that succeeds against everybody, and the only thing separating you from the thief is a string of numbers you have never looked at. Ten minutes today, and this story cannot happen to you.
Device Encryption and BitLocker Are the Same Engine
People assume Home gets a weaker kind of encryption than Pro. That is not the case, and the difference is worth being precise about, because it changes what you should do.
Both use the same AES encryption. A drive encrypted by Device Encryption on Home is exactly as unreadable to a stranger as a drive encrypted by BitLocker on Pro. What Home does not get is the controls. Microsoft removed the management surface, not the protection.
| Device Encryption (Home) | BitLocker (Pro and above) | |
|---|---|---|
| Encryption strength | AES — identical | AES — identical |
| Microsoft account | Required. The key has nowhere else to go. | Optional. Works with a local account. |
| Where the key is kept | Your Microsoft account, automatically | Your choice: account, file, printout, or a USB startup key |
| What gets encrypted | The system drive, all of it, no choice | Any fixed drive, plus USB sticks via BitLocker To Go |
| Hardware demands | Strict: UEFI, Secure Boot, TPM 2.0, Modern Standby | Looser. Runs without a TPM if you allow a startup PIN. |
| Turning it on | One switch, or automatic during setup | A wizard with choices at each step |
Read the second row again, because it is the whole trade. On Pro, "encrypt my drive" and "let Microsoft hold my key" are two separate questions and you answer them separately. On Home there is one question, and answering yes answers both.
Whether that bothers you depends on your threat model, and it is worth being honest rather than dramatic about it. If what you are worried about is a stolen laptop, having Microsoft hold your key is a benefit, not a risk — it is the reason you will get back in. If what you are worried about is Microsoft, then Home is not the edition for you and no setting on it will change that.
Find Out Whether You Are Already Encrypted
Do this first, on every machine in the house, before you change anything. It takes under a minute and a surprising number of people get an answer they did not expect.
- The quick look. Open Settings, choose Privacy & security, and look for Device encryption. A switch set to On means you are encrypted. No such section at all means your hardware does not qualify, and you are not.
- The definitive answer. Press the Windows key, type
cmd, choose Run as administrator, and runmanage-bde -status. This works on Home as well as Pro, despite Home having no BitLocker panel. - Read two lines. Conversion Status tells you whether the drive is fully encrypted, partly through, or plain. Protection Status tells you whether protection is actually switched on right now. You want Fully Encrypted and Protection On.
- Watch for the odd one. Fully Encrypted with Protection Off means the drive is scrambled but the key is being held in the clear, which happens during firmware updates and after certain repairs. It is not protecting you in that state. Run
manage-bde -protectors -enable C:to switch it back on.
On Pro you have a friendlier route as well: press Windows+R, type control, press Enter, and open BitLocker Drive Encryption. It lists every drive and its state on one screen.
The Microsoft Account Condition, and Why It Exists
It is easy to read the account requirement as a land grab, and plenty of forum posts do. The more useful reading is less exciting: encryption with no saved key is a data-loss machine, and Microsoft has spent years watching people lose everything that way.
So on Home, the feature refuses to complete unless it has somewhere to put the key, and the only place it is offered is your Microsoft account. Where that leaves you depends on how you set the machine up:
Signed in with a Microsoft account. Encryption completes, the key uploads, and you are protected. Your job is to know how to reach that key, which is the next section.
Using a local account on Home. Encryption generally does not finish. Some machines sit in a prepared state with encryption suspended, waiting for an account to appear — which is why manage-bde -status occasionally shows something more complicated than a plain no. Check rather than assume.
On Pro with a local account. Full BitLocker will happily encrypt and let you save the key to a file, a printout, or a USB stick. This is the combination to choose if you want encryption without an account, and it is a genuine reason to pay for the Pro upgrade.
One more piece, because it explains why so many people are encrypted without having decided to be. Since Windows 11 version 24H2, automatic Device Encryption was widened to cover far more machines on clean installs and reinstalls where a Microsoft or work account is used at setup. It does not usually switch itself on when you upgrade an existing installation, and self-built Home PCs frequently escape it because the firmware flag the manufacturer would set is absent. The honest summary: a new laptop bought in the last couple of years and set up the normal way is probably encrypted, and the only way to be sure about your machine is to look.
Where Your Recovery Key Actually Lives
If you do one thing from this page, do this one. Go and find your key now, while the computer is working and you are not under pressure.
- On any device — phone, tablet, another computer — go to account.microsoft.com/devices/recoverykey.
- Sign in with the Microsoft account the PC was set up with. This is the step that catches people, because a household often has several accounts and the key is only under one of them.
- You will see a list of devices, each with a Key ID and a 48-digit recovery key.
- Save it somewhere that is not the encrypted computer. A printout in a drawer, an entry in a password manager, a note in your phone. All fine. A file on the desktop is not, for reasons that become obvious the day you need it.
The Key ID matters more than people realize. When Windows demands a recovery key it shows a short Key ID on the blue screen, and that ID tells you which of your saved keys is the right one. Three PCs in a house means three keys in the list, and typing the wrong 48 digits is a slow way to conclude the key does not work. Our guide on finding your BitLocker encryption key goes through the matching process and the other places a key can be hiding, including work and school accounts.
If the recovery screen turns up out of nowhere after a Windows update rather than a hardware change, that is a known and separate situation with its own causes — we covered why an update can trigger the recovery prompt and what to check before you panic.
Turning It On, on Windows Home
Assuming you have checked and you are not encrypted, and the option exists:
- Make sure you are signed in with a Microsoft account and that you can actually get into that account from your phone. Do this before encrypting, not after.
- Plug the laptop in. The first encryption pass should not be interrupted by a flat battery.
- Open Settings, then Privacy & security, then Device encryption, and turn the switch on.
- Leave it alone. Depending on drive size and how full it is, the first pass runs from around twenty minutes to a few hours. You can keep using the machine, and it will feel slower while it works.
- When it finishes, go and retrieve the recovery key from your account and save it somewhere off the machine.
Step 5 is not optional housekeeping. It is the step that decides whether encryption is protection or a trap, and it is the one everybody skips.
On Pro, You Get Real Choices
Pro replaces the single switch with a wizard, and the choices in it are worth understanding rather than clicking through.
Open Control Panel, then BitLocker Drive Encryption, and choose Turn on BitLocker for the drive you want. The wizard asks three things that matter.
Where to save the recovery key. You can pick your Microsoft account, a file, or a printout, and you can pick more than one. Saving to a file will not let you save it onto the drive being encrypted, which is Windows being sensible on your behalf. Take the printout option even if it feels dated — paper does not need a password.
How much to encrypt. Used disk space only is faster and is right for a new machine. Encrypt entire drive is right for any machine that has been in use, because deleted files leave recoverable traces in the space that "used space only" skips.
Which encryption mode. The new XTS-AES mode is right for a fixed drive in this computer. Choose the compatible mode only for a removable drive you plan to open on an older machine.
Pro also lets you require a PIN at startup, which closes a real gap: with TPM-only protection the machine unlocks itself on boot and the protection only applies once the drive is out of the laptop. On a machine holding anything genuinely sensitive, a startup PIN is worth the daily friction.
When the Option Is Not There at All
Windows hides Device Encryption rather than showing a broken switch, so an absent option is a requirement not being met. These are the four, and which one is biting you is usually easy to work out.
| Requirement | How to check it | If it fails |
|---|---|---|
| TPM 2.0 | Run tpm.msc. It reports the version, or says none is found. | Often present but switched off in firmware, listed as PTT on Intel or fTPM on AMD. Enable it there. |
| UEFI, not legacy BIOS | Run msinfo32 and read BIOS Mode. | Converting from Legacy to UEFI is possible but disruptive. Weigh it against a clean install. |
| Secure Boot on | msinfo32 again, Secure Boot State. | Enable it in firmware. Check your other operating systems boot first if you dual boot. |
| Modern Standby | Run powercfg /a and look for Standby (S0 Low Power Idle). | Not something you can add. This is the one that rules out most desktops and older laptops. |
Modern Standby is the requirement that surprises people, because it has nothing to do with security. It is a power-management capability, and it is simply the line Microsoft drew for which machines get the automatic version of the feature. A perfectly capable desktop with a TPM 2.0 chip and Secure Boot can still be excluded on this basis alone. On Pro this does not matter, because full BitLocker does not ask for it — which is the clearest practical argument for the Pro upgrade on a desktop you want encrypted.
The Three Ways People Lock Themselves Out
Encryption does not lose your data. These three situations do, and every one of them is survivable if you have the key.
| What happens | Why the drive locks | What saves you |
|---|---|---|
| The motherboard dies | The key was sealed to the TPM on that board. A new board is a different chip. | The recovery key, and nothing else. This is Jake's customer. |
| Firmware or boot changes | A BIOS update, a Secure Boot change, or a Linux installer alters what the TPM measures at startup. | The recovery key once, after which it re-seals itself. Suspend protection before planned firmware work. |
| The Microsoft account is lost | The key was only ever in that account, and closing it or losing access takes the key with it. | A copy saved elsewhere. Retrieve every key before closing any account. |
There is a fourth worth naming because it is entirely self-inflicted: turning on encryption on a machine you are about to sell or give away, then wiping it badly. If you are passing a machine on, decrypt it or do a full reset that removes everything, rather than leaving an encrypted drive and a key in an account you are about to abandon.
Before a planned BIOS update, the professional move is one command: manage-bde -protectors -disable C: suspends protection so the firmware change does not trigger the recovery prompt, and it re-enables itself on the next restart. Ethan's rule of thumb, which Jake now has written on a card at the bench: if you are about to change anything the machine checks at boot, suspend first.
What Encryption Does Not Protect You From
This is where a lot of guides oversell, and overselling security is how people end up less safe rather than more.
Drive encryption protects data at rest. That means: the laptop is off, or locked, and somebody has physical possession of it. They cannot pull the drive out and read it on another machine. They cannot boot a live USB and browse your files. For a laptop left in a taxi, that is precisely the right protection and it is genuinely excellent.
It does nothing at all about any of the following, and it is worth being blunt. Malware that runs while you are signed in reads your files exactly as you can, because the drive is unlocked whenever Windows is running. Phishing that takes your password is unaffected. Somebody who sits down at your unlocked machine while you fetch coffee is unaffected. Ransomware is unaffected, and in fact encrypts your already-encrypted files quite happily.
So encryption is one lock among several, and the others still matter: a sign-in you do not reuse elsewhere, two-step verification on the Microsoft account holding your key, and backups kept separately. Our guide to protecting your privacy in Windows covers the surrounding settings, and Windows Hello is the practical way to make the sign-in half both stronger and less annoying.
What This Page Said in 2016
The original version of this post went up in December 2016, and it was accurate for the Windows of that moment. It walked through switching Device Encryption on, explained that Home had it and Pro had the fuller BitLocker, and left it there.
What it could not have told you is everything that has happened since, and the shape of the topic has changed more than the steps have. In 2016 this was a feature you went and enabled, on a machine that probably did not qualify, and most readers arrived wanting to switch something on. Today most readers arrive already encrypted, having never switched anything on, and what they need is not instructions — it is to know where their key is and what will ask for it.
So the emphasis has moved. Finding the key comes before turning the feature on, because for most of you the feature is already on. The requirements have their own section because Modern Standby quietly excludes a lot of machines. And the account condition is stated plainly near the top rather than mentioned in passing, because it is the single fact that most changes what people decide.
The steps from 2016 are still here and still correct. They are just no longer the part of this page that matters most.
Your Questions, Answered Straight
What is the difference between Device Encryption and BitLocker?
They use the same AES encryption underneath, so the protection is equally strong. Device Encryption is the stripped-down version available on Home. It is all or nothing, it encrypts the system drive only, and it requires a Microsoft account. Full BitLocker on Pro adds manual control: you choose what to encrypt, you can encrypt removable drives, you can manage keys yourself, and you can use it with a local account.
Does Windows 11 Home have BitLocker?
It has Device Encryption, which is BitLocker's engine with the controls removed. You will not find the BitLocker management panel or the Manage BitLocker option on Home. What you get is a single on and off switch under Settings, Privacy & security, Device encryption, and it appears only if the hardware qualifies.
How do I check whether my drive is already encrypted?
Open Settings, go to Privacy & security, and look for Device encryption. If the switch is on, you are encrypted. For a definitive answer on any edition, open Command Prompt as administrator and run manage-bde -status. Look at the Conversion Status and Protection Status lines. Protection On means the drive is genuinely protected right now.
Why does Device Encryption require a Microsoft account?
Because Microsoft decided the recovery key must have somewhere safe to live, and on Home the only place offered is your Microsoft account. Encryption without a saved key is how people lose everything, so the account requirement is a safety measure rather than a sales tactic. The consequence is still real: on Home you cannot separate encrypting the drive from uploading the key.
Is my drive encrypted if I use a local account on Windows Home?
Almost certainly not. On Home, Device Encryption completes only when you sign in with a Microsoft account, because that is where it puts the recovery key. Some machines finish setup in a prepared state with encryption suspended, waiting for an account to be added. Run manage-bde -status to see for certain rather than assuming either way.
Where do I find my BitLocker recovery key?
Sign in at account.microsoft.com/devices/recoverykey on any phone or computer, using the same Microsoft account the PC was set up with. Every key saved from that account is listed against a device name and a Key ID. Match the Key ID shown on the blue recovery screen to the entry in that list, because a household with several PCs will have several keys and only one of them opens this drive.
Does Windows 11 24H2 turn on encryption automatically?
On qualifying clean installs and reinstalls where you sign in with a Microsoft or work account, yes. It was expanded in 24H2 to cover more machines than before, including Home. Upgrades from an earlier version generally do not switch it on by themselves, and self-built Home PCs often escape it because the manufacturer flag in firmware is not set. The reliable way to know is to check rather than to reason about it.
Will encryption slow my computer down?
Not noticeably on modern hardware. Any current processor handles AES in dedicated instructions, so the cost is a fraction of a percent on everyday work. You may see a real slowdown during the initial encryption pass, which runs in the background and can take from twenty minutes to a few hours depending on drive size. Leave the machine plugged in while that finishes.
Can I turn Device Encryption off?
Yes. Settings, Privacy & security, Device encryption, and switch it off. Windows then decrypts the drive, which takes a while and should not be interrupted. Think before you do it on a laptop, because the thing encryption protects against is not hacking. It is somebody walking off with the machine and reading the drive on their own computer.
What happens to my encrypted drive if the motherboard dies?
The drive still holds your data, but the key that unlocks it was sealed to the TPM chip on the old board, so the new machine cannot open it. You get in with the recovery key and nothing else. This is the single most common way people lose encrypted data, and it is entirely preventable by knowing where your key is before the hardware fails.
Why is the Device encryption option missing from my Settings?
The hardware does not meet the conditions, so Windows hides the option rather than showing one that cannot work. Device Encryption needs UEFI firmware rather than legacy BIOS, Secure Boot enabled, a TPM 2.0 chip, and Modern Standby support. Modern Standby is the one that most often rules out desktops and older laptops. On Pro you can still use full BitLocker, which is less fussy.
Does encryption protect me if someone steals my signed-in laptop?
Only while it is off or locked. Encryption protects data at rest, which means it stops someone removing the drive or booting another system to read it. Once Windows is running and you are signed in, the drive is unlocked and a thief who gets past your sign-in reads everything normally. Encryption and a strong sign-in are two separate jobs, and you want both.
Should I print my recovery key or save it to a file?
Save it somewhere that is not the encrypted computer. Printed and kept with your documents is genuinely good. A password manager is good. A photo in your phone gallery is acceptable. A text file on the desktop of the drive it unlocks is useless in the exact situation you need it, and that is where a surprising number of people keep it.
What happens to encryption if I delete my Microsoft account?
The keys stored in it go with it, and that is unrecoverable. If you plan to close a Microsoft account or move a PC to a local account, retrieve and save every recovery key listed under it first. Converting the PC to a local account does not decrypt the drive, so the key remains necessary while the copy you relied on is being deleted.
Does encryption cause problems with dual booting Linux?
It complicates things in two directions. Linux cannot read an encrypted Windows partition without the key and some setup, and changes to the boot configuration made by a Linux installer can alter what the TPM measures at startup, which makes Windows demand the recovery key on the next boot. Dual booting with encryption is workable, but keep the key to hand before you start.
Is Device Encryption enough, or do I need something more?
For a laptop that might be lost or stolen, it is the right protection and it is sufficient. It does nothing about malware, phishing, a weak password, or anyone using the machine while you are signed in. Treat it as the lock on the door of an empty house rather than a guard who stays inside while you are home.
Worth Reading Next
- How to find your BitLocker recovery key
Every place a key can be stored, and how to match the Key ID on screen to the right one. - Windows is asking for the recovery key after an update
When the prompt appears without a hardware change — what causes it and what to check first. - Things worth doing to protect your privacy in Windows
The settings around encryption that decide how much of your machine talks to the internet. - What Windows Hello is, and how to set it up
The sign-in half of the job — encryption guards the drive, this guards the session.
Revision note. Originally published December 20, 2016, when this was a feature you went looking for. Rewritten August 22, 2026 for Windows 11 and Windows 10. What changed: finding your recovery key now comes before turning the feature on, because most machines arriving here are already encrypted; the Microsoft account condition is stated up front; the hardware requirements have their own section, since Modern Standby quietly excludes a lot of otherwise capable desktops; and there is an honest section on what encryption does not protect. If your machine behaves differently from what you read here, please write in and tell us what manage-bde -status reported — pages like this stay accurate because readers do that. And if you have landed here because a blue screen is asking for a key right now, take a breath: your files are almost certainly fine, and the key is almost certainly sitting in an account you can still reach.