What is BitLocker? Definition from SearchEnterpriseDesktop (2024)

What is BitLocker? Definition from SearchEnterpriseDesktop (1)

By

  • Alexander S. Gillis,Technical Writer and Editor

BitLocker Drive Encryption, or BitLocker, is a Microsoft Windows security and encryption feature that is included with certain newer versions of Windows. BitLocker enables users to encrypt everything on the drive Windows is installed on, protecting that data from theft or unauthorized access.

Microsoft BitLocker improves file and system protections by mitigating unauthorized data access. It uses the Advanced Encryption Standard algorithm with 128- or 256-bit keys. BitLocker combines the on-disk encryption process and special key management techniques.

Although BitLocker first debuted with Windows Vista in 2007, beginning with Windows 10 version 1511, Microsoft updated BitLocker, introducing new encryption algorithms, new group policy settings, new operating system (OS) drives and removable data drives. This update applies to Windows 11, 10 and Server 2016 and above. BitLocker itself works on Pro, Enterprise and Education editions of Windows.

How does BitLocker work?

BitLocker uses a specialized chip called a Trusted Platform Module (TPM). The TPM stores Rivest-Shamir-Adleman encryption keys specific to the host system for hardware authentication. The TPM is installed by the original computer manufacturer and works with BitLocker to protect user data.

This article is part of

CrowdStrike outage explained: What caused it and what’s next

  • Which also includes:
  • Is today's CrowdStrike outage a sign of the new normal?
  • BitLocker workaround may offer aid for CrowdStrike customers
  • Microsoft: Faulty CrowdStrike update affected 8.5M devices

In addition to a TPM, BitLocker can also lock the startup process until the user inputs a PIN or inserts a removable device like a flash drive that has a startup key. BitLocker also creates a recovery key for the user's hard drive -- in case the user forgets or loses their password.

Computers that do not have a TPM installed can still use BitLocker to encrypt Windows OS drives. But this implementation requires a USB startup key to turn on the computer or resume from hibernation. Microsoft, however, states that there is more pre-startup system integrity verification when BitLocker is paired with a TPM.

BitLocker Recovery Password Viewer and BitLocker Drive Encryption Tools are two additional tools used to manage BitLocker. BitLocker Recovery Password Viewer enables users to locate BitLocker recovery passwords that are backed up to Active Directory (AD) Domain Services. This tool is used to recover data stored on an already encrypted drive. BitLocker Drive Encryption Tools are a combination of command-line tools, the BitLocker cmdlets for Windows PowerShell as well as manage-bde and repair-bde. Repair-bde, for example, is used in disaster recovery attempts where BitLocker-protected drives cannot be unlocked normally or using the recovery console. The Manage-bde command-line tool turns BitLocker on or off. Turning off BitLocker will decrypt all of the files on the drive when that data no longer needs to be protected.

How to use BitLocker

BitLocker is enabled by default. But if it is turned off, a user can go to the Windows search bar and search for Manage BitLocker. If BitLocker is on the device, it will show up in the control panel, with one of the options being to turn on BitLocker. Other options include suspend protection, back up your recovery key and turn off BitLocker.

What is BitLocker? Definition from SearchEnterpriseDesktop (2)

After turning BitLocker on, Windows begins checking system settings. The user must create a password, which is needed every time they access their PC or drive. The user then selects Recovery key settings. After clicking on Next, the user can select how much of their drive they wish to encrypt. The two-volume encryption options are to encrypt used disk space only or to encrypt the entire drive. Encrypt used disk space refers to only the disk space that contains data, while encrypt the entire drive means that the entire storage volume, including free space, is encrypted.

After clicking on this, the user can run a BitLocker system check which ensures that BitLocker can access the recovery and encryption keys before anything is encrypted. After the system check, the BitLocker Drive Encryption Wizard restarts the computer to begin the endpoint encryption process. Protection is only enabled after user sign-on and the device is registered to an AD domain.

To decrypt and turn off BitLocker, the user should search for Manage BitLocker in their Windows Search bar, select the option that appears and then turn off BitLocker; the process of decrypting data will begin.

BitLocker system requirements

BitLocker requires the following:

  • TPM 1.2 or later must be installed.
  • If not using a TPM, a startup key stored on a removable device is required.
  • If using a TPM, a Trusted Computing Group-compliant BIOS or unified extensible firmware interface (UEFI) is needed for a chain of trust for the OS startup.
  • BIOS or UEFI must support the USB mass storage device class.
  • Storage drives must have two or more partitions.
  • The OS drive must be formatted with NT File System (NTFS)
  • System drives that use UEFI-based firmware must be formatted with the File Allocation Table 32 file system.
  • System drives that use BIOS firmware must be formatted with NTFS.

Learn more about the CrowdStrike outage and its effects on the IT industry:

Defective CrowdStrike update triggers mass IT outages

BitLocker workaround offers relief for some CrowdStrike customers

What is the blue screen of death (BSOD)?

CrowdStrike outage underscores software testing dilemmas

CrowdStrike chaos casts a long shadow on cybersecurity

What is a BitLocker recovery key?

A BitLocker recovery key is a 48-digit numerical password that is used to unlock a user's system when BitLocker detects a possible unauthorized access attempt. The key serves as an extra security measure to keep a user's data safe. Windows may also ask for the BitLocker recovery key if changes are made in the system's hardware, software or firmware.

How to find a BitLocker recovery key

If the recovery key is lost, the only option is to reinstall Windows. To avoid this, BitLocker recovery keys can be backed up to the following locations:

  • The user's Microsoft account. If the user signs into their Microsoft account on another device, they can view their key from there.
  • A USB flash drive. A USB flash drive can store the key, which can be inserted into the locked PC to unlock it. If the key is stored as a text file, the user can plug it into another PC to read the password.
  • The user's Microsoft Azure Active Directory (AD) account. The key may be stored in a larger Azure AD account associated with the user's device.
  • A system administrator's system. A system admin may have the recovery key if the user's device is connected to a domain.
  • The user's possession. The user may have printed or written the code out on paper.

Learn how BitLocker encryption technology has evolved to secure information, such as local and cloud resources.

This was last updated in March 2022

Continue Reading About What is BitLocker?

  • A closer look at new and updated Microsoft security features
  • ProxyShell leads to domain-wide ransomware attack
  • How can I protect my self-encrypting drives?
  • Compare native vs. third-party security tools for Windows 10
  • Network security gets a boost in Windows Server 2022

Related Terms

software patch
A software patch or fix is a quick-repair job for a piece of programming designed to resolve functionality issues, improve ...Seecompletedefinition
What is a device driver?
A device driver, or driver, is a special kind of software program that controls a specific hardware device attached to a computer.Seecompletedefinition
Windows Server Update Services (WSUS)
Windows Server Update Services (WSUS) is a Windows server role that can plan, manage and deploy updates, service packs, patches ...Seecompletedefinition

Dig Deeper on Windows OS and management

  • BitLocker workaround may offer aid for CrowdStrike customersBy: RobWright
  • How endpoint encryption works in a data security strategyBy: MichaelCobb
  • Trusted Platform Module (TPM)By: AlexanderGillis
  • How does Microsoft BitLocker secure local, cloud resources?By: StephenBigelow
What is BitLocker? Definition from SearchEnterpriseDesktop (2024)

FAQs

What does it mean when your computer says BitLocker? ›

If you experiences that the computer shows BitLocker recovery screen after power on, it means that the HDD/SDD has been encrypted.

What is BitLocker in simple terms? ›

BitLocker Drive Encryption, or BitLocker, is a Microsoft Windows security and encryption feature that is included with certain newer versions of Windows. BitLocker enables users to encrypt everything on the drive Windows is installed on, protecting that data from theft or unauthorized access.

Why is my computer asking me for BitLocker? ›

Whenever you connect a drive to your PC and it is detected in the boot list, BitLocker will ask for the recovery key. If you're not connecting any devices and it keeps asking for the recovery key, it is because the boot support for Preboot for TBT and USB-C/TBT is turned on by default.

How to get rid of BitLocker? ›

  1. Type and search [Manage BitLocker] in the Windows search bar①, then click [Open]②.
  2. Click [Turn off BitLocker]③ on the drive that you want to decrypt. ...
  3. Confirm whether you want to decrypt your drive, then select [Turn off BitLocker]④ to start turning off BitLocker, and your drive will not be protected anymore.
Oct 24, 2023

How do I get my computer out of BitLocker mode? ›

To exit the BitLocker recovery screen, you will need to enter the recovery key. The recovery key is a 48-digit code that was provided to you when you first enabled BitLocker on your device. If you don't have the recovery key, you can't enter the drive.

What would trigger BitLocker? ›

Bitlocker recovery mode can be triggered by a number of situations, including: A malicious attempt by a person or software to change the startup environment. Rootkits are one example. Moving the BitLocker-protected drive into a new computer.

Is BitLocker good or bad? ›

Not 100% Secure: While BitLocker provides strong protection against most cyber threats, there are some cases where it can be bypassed by malicious actors with sophisticated techniques.

How to unlock BitLocker? ›

To unlock their drives, users must open “This PC” (or “My Computer”, depending on the version of Windows), right-click on the encrypted drive icons with the locked yellow padlock icon, click "Unlock Drive" and provide the Password.

Why do people use BitLocker? ›

BitLocker helps mitigate unauthorized data access by enhancing file and system protections, rendering data inaccessible when BitLocker-protected devices are decommissioned or recycled.

What causes BitLocker to pop up? ›

When a machine is encrypted it stores the state of the BIOS/UEFI settings. Any changes to this state can cause the BitLocker recovery mode to kick in. This could be something as simple as choosing a different boot device at startup if not configured correctly based on the network requirements of your organization.

How to fix BitLocker problem? ›

Steps to Troubleshoot BitLocker Issues
  1. Step 1: Identifying the issue. ...
  2. Step 2: Gathering information about the issue. ...
  3. Step 3: Verifying the TPM and BitLocker Configuration. ...
  4. Step 4: Checking for updates and applying fixes. ...
  5. Step 5: Testing the solution.
Sep 27, 2023

How do I know if my computer has BitLocker? ›

In Windows Explorer in the left hand column, choose 'This PC' and on the right hand side you should see a padlock icon on the drives that are encrypted. Highlight and right-click on the drive you want to verify the 'BitLocker Options'. If you see the message 'Encryption on', your hard drive is encrypted.

How do I stop BitLocker prompt? ›

Re: Disable BitLocker prompting on boot?
  1. Right click Bitlockered Drive (c:) in file explorer.
  2. Select Manage Bitlocker (this opens BL Drive Encryption)
  3. Click Suspend.
  4. Click Yes.
  5. Reboot.
  6. Repeat steps 1 & 2.
  7. Click Resume Protection.
  8. Reboot.
Jan 25, 2020

How long does it take to turn off BitLocker? ›

Disabling BitLocker

NOTE: Decryption can take anywhere from 20 minutes to a couple of hours. The time depends on the amount of data that has been encrypted, the speed of the computer, and whether the process is interrupted. Interruptions include the computer being turned off or going to sleep.

Is BitLocker turned on by default? ›

That means if you clean install Windows 11 later this year or buy a new PC with 24H2 installed, BitLocker device encryption will be enabled by default. If you just upgrade to 24H2, Microsoft won't enable device encryption automatically. The feature could impact SSD performance on some devices.

How do I unlock BitLocker? ›

To unlock their drives, users must open “This PC” (or “My Computer”, depending on the version of Windows), right-click on the encrypted drive icons with the locked yellow padlock icon, click "Unlock Drive" and provide the Password.

Why is my PC locked by BitLocker? ›

Your drive was encrypted with Bitlocker and you need to locate the key to be able to use it again. That depends how it was setup, Bitlocker is not turned on by default so someone would have turned bitlocker on at some point. It sounds like the Windows update triggered bitlocker to prompt for the drive encryption key.

How to resolve BitLocker issue? ›

Steps to Troubleshoot BitLocker Issues
  1. Step 1: Identifying the issue. ...
  2. Step 2: Gathering information about the issue. ...
  3. Step 3: Verifying the TPM and BitLocker Configuration. ...
  4. Step 4: Checking for updates and applying fixes. ...
  5. Step 5: Testing the solution.
Sep 27, 2023

Top Articles
Crypto will go mainstream within 10 years, according to investors
How Long Can Gasoline Sit In a Car? - Veloce Vault
English Bulldog Puppies For Sale Under 1000 In Florida
Katie Pavlich Bikini Photos
Gamevault Agent
Pieology Nutrition Calculator Mobile
Hocus Pocus Showtimes Near Harkins Theatres Yuma Palms 14
Hendersonville (Tennessee) – Travel guide at Wikivoyage
Compare the Samsung Galaxy S24 - 256GB - Cobalt Violet vs Apple iPhone 16 Pro - 128GB - Desert Titanium | AT&T
Vardis Olive Garden (Georgioupolis, Kreta) ✈️ inkl. Flug buchen
Craigslist Dog Kennels For Sale
Things To Do In Atlanta Tomorrow Night
Non Sequitur
Crossword Nexus Solver
How To Cut Eelgrass Grounded
Pac Man Deviantart
Alexander Funeral Home Gallatin Obituaries
Shasta County Most Wanted 2022
Energy Healing Conference Utah
Geometry Review Quiz 5 Answer Key
Hobby Stores Near Me Now
Icivics The Electoral Process Answer Key
Allybearloves
Bible Gateway passage: Revelation 3 - New Living Translation
Yisd Home Access Center
Home
Shadbase Get Out Of Jail
Gina Wilson Angle Addition Postulate
Celina Powell Lil Meech Video: A Controversial Encounter Shakes Social Media - Video Reddit Trend
Walmart Pharmacy Near Me Open
Marquette Gas Prices
A Christmas Horse - Alison Senxation
Ou Football Brainiacs
Access a Shared Resource | Computing for Arts + Sciences
Vera Bradley Factory Outlet Sunbury Products
Pixel Combat Unblocked
Movies - EPIC Theatres
Cvs Sport Physicals
Mercedes W204 Belt Diagram
Mia Malkova Bio, Net Worth, Age & More - Magzica
'Conan Exiles' 3.0 Guide: How To Unlock Spells And Sorcery
Teenbeautyfitness
Where Can I Cash A Huntington National Bank Check
Topos De Bolos Engraçados
Sand Castle Parents Guide
Gregory (Five Nights at Freddy's)
Grand Valley State University Library Hours
Holzer Athena Portal
Hello – Cornerstone Chapel
Stoughton Commuter Rail Schedule
Selly Medaline
Latest Posts
Article information

Author: Kimberely Baumbach CPA

Last Updated:

Views: 6210

Rating: 4 / 5 (41 voted)

Reviews: 80% of readers found this page helpful

Author information

Name: Kimberely Baumbach CPA

Birthday: 1996-01-14

Address: 8381 Boyce Course, Imeldachester, ND 74681

Phone: +3571286597580

Job: Product Banking Analyst

Hobby: Cosplaying, Inline skating, Amateur radio, Baton twirling, Mountaineering, Flying, Archery

Introduction: My name is Kimberely Baumbach CPA, I am a gorgeous, bright, charming, encouraging, zealous, lively, good person who loves writing and wants to share my knowledge and understanding with you.