Personal Data Encryption (PDE) (2024)

  • Article
  • Applies to:
    Windows 11

Starting in Windows 11, version 22H2, Personal Data Encryption (PDE) is a security feature that provides file-based data encryption capabilities to Windows.

PDE utilizes Windows Hello for Business to link data encryption keys with user credentials. When a user signs in to a device using Windows Hello for Business, decryption keys are released, and encrypted data is accessible to the user.
When a user logs off, decryption keys are discarded and data is inaccessible, even if another user signs into the device.

The use of Windows Hello for Business offers the following advantages:

  • It reduces the number of credentials to access encrypted content: users only need to sign-in with Windows Hello for Business
  • The accessibility features available when using Windows Hello for Business extend to PDE protected content

PDE differs from BitLocker in that it encrypts files instead of whole volumes and disks. PDE occurs in addition to other encryption methods such as BitLocker.
Unlike BitLocker that releases data encryption keys at boot, PDE doesn't release data encryption keys until a user signs in using Windows Hello for Business.

Prerequisites

To use PDE, the following prerequisites must be met:

  • Windows 11, version 22H2 and later
  • The devices must be Microsoft Entra joined. Domain-joined and Microsoft Entra hybrid joined devices aren't supported
  • Users must sign in using Windows Hello for Business

Important

If you sign in with a password or a security key, you can't access PDE protected content.

Windows edition and licensing requirements

The following table lists the Windows editions that support Personal data encryption (PDE):

Windows ProWindows EnterpriseWindows Pro Education/SEWindows Education
NoYesNoYes

Personal data encryption (PDE) license entitlements are granted by the following licenses:

Windows Pro/Pro Education/SEWindows Enterprise E3Windows Enterprise E5Windows Education A3Windows Education A5
NoYesYesYesYes

For more information about Windows licensing, see Windows licensing overview.

PDE protection levels

PDE uses AES-CBC with a 256-bit key to protect content and offers two levels of protection. The level of protection is determined based on the organizational needs. These levels can be set via the PDE APIs.

ItemLevel 1Level 2
PDE protected data accessible when user has signed in via Windows Hello for BusinessYesYes
PDE protected data is accessible at Windows lock screenYesData is accessible for one minute after lock, then it's no longer available
PDE protected data is accessible after user signs out of WindowsNoNo
PDE protected data is accessible when device is shut downNoNo
PDE protected data is accessible via UNC pathsNoNo
PDE protected data is accessible when signing with Windows password instead of Windows Hello for BusinessNoNo
PDE protected data is accessible via Remote Desktop sessionNoNo
Decryption keys used by PDE discardedAfter user signs out of WindowsOne minute after Windows lock screen is engaged or after user signs out of Windows

PDE protected content accessibility

When a file is protected with PDE, its icon will show a padlock. If the user hasn't signed in locally with Windows Hello for Business or an unauthorized user attempts to access PDE protected content, they'll be denied access to the content.

Scenarios where a user will be denied access to PDE protected content include:

  • User has signed into Windows via a password instead of signing in with Windows Hello for Business biometric or PIN
  • If protected via level 2 protection, when the device is locked
  • When trying to access content on the device remotely. For example, UNC network paths
  • Remote Desktop sessions
  • Other users on the device who aren't owners of the content, even if they're signed in via Windows Hello for Business and have permissions to navigate to the PDE protected content

Differences between PDE and BitLocker

PDE is meant to work alongside BitLocker. PDE isn't a replacement for BitLocker, nor is BitLocker a replacement for PDE. Using both features together provides better security than using either BitLocker or PDE alone. However there are differences between BitLocker and PDE and how they work. These differences are why using them together offers better security.

ItemPDEBitLocker
Release of decryption keyAt user sign-in via Windows Hello for BusinessAt boot
Decryption keys discardedWhen user signs out of Windows or one minute after Windows lock screen is engagedAt shutdown
Protected contentAll files in protected foldersEntire volume/drive
Authentication to access protected contentWindows Hello for BusinessWhen BitLocker with TPM + PIN is enabled, BitLocker PIN plus Windows sign-in

Differences between PDE and EFS

The main difference between protecting files with PDE instead of EFS is the method they use to protect the file. PDE uses Windows Hello for Business to secure the keys that protect the files. EFS uses certificates to secure and protect the files.

To see if a file is protected with PDE or with EFS:

  1. Open the properties of the file
  2. Under the General tab, select Advanced...
  3. In the Advanced Attributes windows, select Details

For PDE protected files, under Protection status: there will be an item listed as Personal Data Encryption is: and it will have the attribute of On.

For EFS protected files, under Users who can access this file:, there will be a Certificate thumbprint next to the users with access to the file. There will also be a section at the bottom labeled Recovery certificates for this file as defined by recovery policy:.

Encryption information including what encryption method is being used to protect the file can be obtained with the cipher.exe /c command.

Recommendations for using PDE

The following are recommendations for using PDE:

  • Enable BitLocker Drive Encryption. Although PDE works without BitLocker, it's recommended to enable BitLocker. PDE is meant to work alongside BitLocker for increased security at it isn't a replacement for BitLocker
  • Backup solution such as OneDrive in Microsoft 365. In certain scenarios, such as TPM resets or destructive PIN resets, the keys used by PDE to protect content will be lost making any PDE-protected content inaccessible. The only way to recover such content is from a backup. If the files are synced to OneDrive, to regain access you must re-sync OneDrive
  • Windows Hello for Business PIN reset service. Destructive PIN resets will cause keys used by PDE to protect content to be lost, making any content protected with PDE inaccessible. After a destructive PIN reset, content protected with PDE must be recovered from a backup. For this reason, Windows Hello for Business PIN reset service is recommended since it provides non-destructive PIN resets
  • Windows Hello Enhanced Sign-in Security offers additional security when authenticating with Windows Hello for Business via biometrics or PIN

Windows out of box applications that support PDE

Certain Windows applications support PDE out of the box. If PDE is enabled on a device, these applications will utilize PDE:

App nameDetails
MailSupports protecting both email bodies and attachments

Next steps

  • Learn about the available options to configure Personal Data Encryption (PDE) and how to configure them via Microsoft Intune or configuration Service Provider (CSP): PDE settings and configuration
  • Review the Personal Data Encryption (PDE) FAQ
Personal Data Encryption (PDE) (2024)
Top Articles
Enable TLS 1.2 support as Microsoft Entra TLS 1.0/1.1 is deprecated - Azure
How to Overclock Your Graphics Card (GPU)
Frases para un bendecido domingo: llena tu día con palabras de gratitud y esperanza - Blogfrases
Celebrity Extra
Hertz Car Rental Partnership | Uber
Paula Deen Italian Cream Cake
Vocabulario A Level 2 Pp 36 40 Answers Key
Umn Biology
Www.paystubportal.com/7-11 Login
Pollen Count Central Islip
今月のSpotify Japanese Hip Hopベスト作品 -2024/08-|K.EG
George The Animal Steele Gif
Labor Gigs On Craigslist
Illinois Gun Shows 2022
Cashtapp Atm Near Me
Craigslist Southern Oregon Coast
Dragger Games For The Brain
Craigslist Battle Ground Washington
Imouto Wa Gal Kawaii - Episode 2
Kimoriiii Fansly
Craigslist Pasco Kennewick Richland Washington
When His Eyes Opened Chapter 3123
Sams Gas Price Sanford Fl
Rural King Credit Card Minimum Credit Score
Bfsfcu Truecar
Renfield Showtimes Near Marquee Cinemas - Wakefield 12
Edward Walk In Clinic Plainfield Il
W B Crumel Funeral Home Obituaries
Best Weapons For Psyker Darktide
Pillowtalk Podcast Interview Turns Into 3Some
Solemn Behavior Antonym
New Gold Lee
Frcp 47
1v1.LOL Game [Unblocked] | Play Online
Craigslist Tulsa Ok Farm And Garden
Discover Wisconsin Season 16
Oppenheimer Showtimes Near B&B Theatres Liberty Cinema 12
Www.craigslist.com Waco
Myrtle Beach Craigs List
Az Unblocked Games: Complete with ease | airSlate SignNow
CrossFit 101
RubberDucks Front Office
Server Jobs Near
Sc Pick 3 Past 30 Days Midday
Mejores páginas para ver deportes gratis y online - VidaBytes
Stephen Dilbeck, The First Hicks Baby: 5 Fast Facts You Need to Know
Wrentham Outlets Hours Sunday
Osrs Vorkath Combat Achievements
Metra Union Pacific West Schedule
Bellin Employee Portal
login.microsoftonline.com Reviews | scam or legit check
Latest Posts
Article information

Author: Edwin Metz

Last Updated:

Views: 5973

Rating: 4.8 / 5 (58 voted)

Reviews: 89% of readers found this page helpful

Author information

Name: Edwin Metz

Birthday: 1997-04-16

Address: 51593 Leanne Light, Kuphalmouth, DE 50012-5183

Phone: +639107620957

Job: Corporate Banking Technician

Hobby: Reading, scrapbook, role-playing games, Fishing, Fishing, Scuba diving, Beekeeping

Introduction: My name is Edwin Metz, I am a fair, energetic, helpful, brave, outstanding, nice, helpful person who loves writing and wants to share my knowledge and understanding with you.