What is BitLocker? Definition from SearchEnterpriseDesktop (2024)

What is BitLocker? Definition from SearchEnterpriseDesktop (1)

By

  • Alexander S. Gillis,Technical Writer and Editor

BitLocker Drive Encryption, or BitLocker, is a Microsoft Windows security and encryption feature that is included with certain newer versions of Windows. BitLocker enables users to encrypt everything on the drive Windows is installed on, protecting that data from theft or unauthorized access.

Microsoft BitLocker improves file and system protections by mitigating unauthorized data access. It uses the Advanced Encryption Standard algorithm with 128- or 256-bit keys. BitLocker combines the on-disk encryption process and special key management techniques.

Although BitLocker first debuted with Windows Vista in 2007, beginning with Windows 10 version 1511, Microsoft updated BitLocker, introducing new encryption algorithms, new group policy settings, new operating system (OS) drives and removable data drives. This update applies to Windows 11, 10 and Server 2016 and above. BitLocker itself works on Pro, Enterprise and Education editions of Windows.

How does BitLocker work?

BitLocker uses a specialized chip called a Trusted Platform Module (TPM). The TPM stores Rivest-Shamir-Adleman encryption keys specific to the host system for hardware authentication. The TPM is installed by the original computer manufacturer and works with BitLocker to protect user data.

This article is part of

CrowdStrike outage explained: What caused it and what’s next

  • Which also includes:
  • Is today's CrowdStrike outage a sign of the new normal?
  • BitLocker workaround may offer aid for CrowdStrike customers
  • Microsoft: Faulty CrowdStrike update affected 8.5M devices

In addition to a TPM, BitLocker can also lock the startup process until the user inputs a PIN or inserts a removable device like a flash drive that has a startup key. BitLocker also creates a recovery key for the user's hard drive -- in case the user forgets or loses their password.

Computers that do not have a TPM installed can still use BitLocker to encrypt Windows OS drives. But this implementation requires a USB startup key to turn on the computer or resume from hibernation. Microsoft, however, states that there is more pre-startup system integrity verification when BitLocker is paired with a TPM.

BitLocker Recovery Password Viewer and BitLocker Drive Encryption Tools are two additional tools used to manage BitLocker. BitLocker Recovery Password Viewer enables users to locate BitLocker recovery passwords that are backed up to Active Directory (AD) Domain Services. This tool is used to recover data stored on an already encrypted drive. BitLocker Drive Encryption Tools are a combination of command-line tools, the BitLocker cmdlets for Windows PowerShell as well as manage-bde and repair-bde. Repair-bde, for example, is used in disaster recovery attempts where BitLocker-protected drives cannot be unlocked normally or using the recovery console. The Manage-bde command-line tool turns BitLocker on or off. Turning off BitLocker will decrypt all of the files on the drive when that data no longer needs to be protected.

How to use BitLocker

BitLocker is enabled by default. But if it is turned off, a user can go to the Windows search bar and search for Manage BitLocker. If BitLocker is on the device, it will show up in the control panel, with one of the options being to turn on BitLocker. Other options include suspend protection, back up your recovery key and turn off BitLocker.

What is BitLocker? Definition from SearchEnterpriseDesktop (2)

After turning BitLocker on, Windows begins checking system settings. The user must create a password, which is needed every time they access their PC or drive. The user then selects Recovery key settings. After clicking on Next, the user can select how much of their drive they wish to encrypt. The two-volume encryption options are to encrypt used disk space only or to encrypt the entire drive. Encrypt used disk space refers to only the disk space that contains data, while encrypt the entire drive means that the entire storage volume, including free space, is encrypted.

After clicking on this, the user can run a BitLocker system check which ensures that BitLocker can access the recovery and encryption keys before anything is encrypted. After the system check, the BitLocker Drive Encryption Wizard restarts the computer to begin the endpoint encryption process. Protection is only enabled after user sign-on and the device is registered to an AD domain.

To decrypt and turn off BitLocker, the user should search for Manage BitLocker in their Windows Search bar, select the option that appears and then turn off BitLocker; the process of decrypting data will begin.

BitLocker system requirements

BitLocker requires the following:

  • TPM 1.2 or later must be installed.
  • If not using a TPM, a startup key stored on a removable device is required.
  • If using a TPM, a Trusted Computing Group-compliant BIOS or unified extensible firmware interface (UEFI) is needed for a chain of trust for the OS startup.
  • BIOS or UEFI must support the USB mass storage device class.
  • Storage drives must have two or more partitions.
  • The OS drive must be formatted with NT File System (NTFS)
  • System drives that use UEFI-based firmware must be formatted with the File Allocation Table 32 file system.
  • System drives that use BIOS firmware must be formatted with NTFS.

Learn more about the CrowdStrike outage and its effects on the IT industry:

Defective CrowdStrike update triggers mass IT outages

BitLocker workaround offers relief for some CrowdStrike customers

What is the blue screen of death (BSOD)?

CrowdStrike outage underscores software testing dilemmas

CrowdStrike chaos casts a long shadow on cybersecurity

What is a BitLocker recovery key?

A BitLocker recovery key is a 48-digit numerical password that is used to unlock a user's system when BitLocker detects a possible unauthorized access attempt. The key serves as an extra security measure to keep a user's data safe. Windows may also ask for the BitLocker recovery key if changes are made in the system's hardware, software or firmware.

How to find a BitLocker recovery key

If the recovery key is lost, the only option is to reinstall Windows. To avoid this, BitLocker recovery keys can be backed up to the following locations:

  • The user's Microsoft account. If the user signs into their Microsoft account on another device, they can view their key from there.
  • A USB flash drive. A USB flash drive can store the key, which can be inserted into the locked PC to unlock it. If the key is stored as a text file, the user can plug it into another PC to read the password.
  • The user's Microsoft Azure Active Directory (AD) account. The key may be stored in a larger Azure AD account associated with the user's device.
  • A system administrator's system. A system admin may have the recovery key if the user's device is connected to a domain.
  • The user's possession. The user may have printed or written the code out on paper.

Learn how BitLocker encryption technology has evolved to secure information, such as local and cloud resources.

This was last updated in March 2022

Continue Reading About What is BitLocker?

  • A closer look at new and updated Microsoft security features
  • ProxyShell leads to domain-wide ransomware attack
  • How can I protect my self-encrypting drives?
  • Compare native vs. third-party security tools for Windows 10
  • Network security gets a boost in Windows Server 2022

Related Terms

software patch
A software patch or fix is a quick-repair job for a piece of programming designed to resolve functionality issues, improve ...Seecompletedefinition
What is a device driver?
A device driver, or driver, is a special kind of software program that controls a specific hardware device attached to a computer.Seecompletedefinition
Windows Server Update Services (WSUS)
Windows Server Update Services (WSUS) is a Windows server role that can plan, manage and deploy updates, service packs, patches ...Seecompletedefinition

Dig Deeper on Windows OS and management

  • BitLocker workaround may offer aid for CrowdStrike customersBy: RobWright
  • How endpoint encryption works in a data security strategyBy: MichaelCobb
  • Trusted Platform Module (TPM)By: AlexanderGillis
  • How does Microsoft BitLocker secure local, cloud resources?By: StephenBigelow
What is BitLocker? Definition from SearchEnterpriseDesktop (2024)

FAQs

What does it mean when your computer says BitLocker? ›

If you experiences that the computer shows BitLocker recovery screen after power on, it means that the HDD/SDD has been encrypted.

What is BitLocker in simple terms? ›

BitLocker Drive Encryption, or BitLocker, is a Microsoft Windows security and encryption feature that is included with certain newer versions of Windows. BitLocker enables users to encrypt everything on the drive Windows is installed on, protecting that data from theft or unauthorized access.

Why is my computer asking me for BitLocker? ›

Whenever you connect a drive to your PC and it is detected in the boot list, BitLocker will ask for the recovery key. If you're not connecting any devices and it keeps asking for the recovery key, it is because the boot support for Preboot for TBT and USB-C/TBT is turned on by default.

How to get rid of BitLocker? ›

  1. Type and search [Manage BitLocker] in the Windows search bar①, then click [Open]②.
  2. Click [Turn off BitLocker]③ on the drive that you want to decrypt. ...
  3. Confirm whether you want to decrypt your drive, then select [Turn off BitLocker]④ to start turning off BitLocker, and your drive will not be protected anymore.
Oct 24, 2023

How do I get my computer out of BitLocker mode? ›

To exit the BitLocker recovery screen, you will need to enter the recovery key. The recovery key is a 48-digit code that was provided to you when you first enabled BitLocker on your device. If you don't have the recovery key, you can't enter the drive.

What would trigger BitLocker? ›

Bitlocker recovery mode can be triggered by a number of situations, including: A malicious attempt by a person or software to change the startup environment. Rootkits are one example. Moving the BitLocker-protected drive into a new computer.

Is BitLocker good or bad? ›

Not 100% Secure: While BitLocker provides strong protection against most cyber threats, there are some cases where it can be bypassed by malicious actors with sophisticated techniques.

How to unlock BitLocker? ›

To unlock their drives, users must open “This PC” (or “My Computer”, depending on the version of Windows), right-click on the encrypted drive icons with the locked yellow padlock icon, click "Unlock Drive" and provide the Password.

Why do people use BitLocker? ›

BitLocker helps mitigate unauthorized data access by enhancing file and system protections, rendering data inaccessible when BitLocker-protected devices are decommissioned or recycled.

What causes BitLocker to pop up? ›

When a machine is encrypted it stores the state of the BIOS/UEFI settings. Any changes to this state can cause the BitLocker recovery mode to kick in. This could be something as simple as choosing a different boot device at startup if not configured correctly based on the network requirements of your organization.

How to fix BitLocker problem? ›

Steps to Troubleshoot BitLocker Issues
  1. Step 1: Identifying the issue. ...
  2. Step 2: Gathering information about the issue. ...
  3. Step 3: Verifying the TPM and BitLocker Configuration. ...
  4. Step 4: Checking for updates and applying fixes. ...
  5. Step 5: Testing the solution.
Sep 27, 2023

How do I know if my computer has BitLocker? ›

In Windows Explorer in the left hand column, choose 'This PC' and on the right hand side you should see a padlock icon on the drives that are encrypted. Highlight and right-click on the drive you want to verify the 'BitLocker Options'. If you see the message 'Encryption on', your hard drive is encrypted.

How do I stop BitLocker prompt? ›

Re: Disable BitLocker prompting on boot?
  1. Right click Bitlockered Drive (c:) in file explorer.
  2. Select Manage Bitlocker (this opens BL Drive Encryption)
  3. Click Suspend.
  4. Click Yes.
  5. Reboot.
  6. Repeat steps 1 & 2.
  7. Click Resume Protection.
  8. Reboot.
Jan 25, 2020

How long does it take to turn off BitLocker? ›

Disabling BitLocker

NOTE: Decryption can take anywhere from 20 minutes to a couple of hours. The time depends on the amount of data that has been encrypted, the speed of the computer, and whether the process is interrupted. Interruptions include the computer being turned off or going to sleep.

Is BitLocker turned on by default? ›

That means if you clean install Windows 11 later this year or buy a new PC with 24H2 installed, BitLocker device encryption will be enabled by default. If you just upgrade to 24H2, Microsoft won't enable device encryption automatically. The feature could impact SSD performance on some devices.

How do I unlock BitLocker? ›

To unlock their drives, users must open “This PC” (or “My Computer”, depending on the version of Windows), right-click on the encrypted drive icons with the locked yellow padlock icon, click "Unlock Drive" and provide the Password.

Why is my PC locked by BitLocker? ›

Your drive was encrypted with Bitlocker and you need to locate the key to be able to use it again. That depends how it was setup, Bitlocker is not turned on by default so someone would have turned bitlocker on at some point. It sounds like the Windows update triggered bitlocker to prompt for the drive encryption key.

How to resolve BitLocker issue? ›

Steps to Troubleshoot BitLocker Issues
  1. Step 1: Identifying the issue. ...
  2. Step 2: Gathering information about the issue. ...
  3. Step 3: Verifying the TPM and BitLocker Configuration. ...
  4. Step 4: Checking for updates and applying fixes. ...
  5. Step 5: Testing the solution.
Sep 27, 2023

Top Articles
What Is an Investment Manager? Roles, Skills, and Salary
Are Real Estate Syndicates a Good Investment?
Hotels Near 6491 Peachtree Industrial Blvd
No Hard Feelings Showtimes Near Metropolitan Fiesta 5 Theatre
Craigslist Pets Longview Tx
Metra Union Pacific West Schedule
Brady Hughes Justified
Citibank Branch Locations In Orlando Florida
Faint Citrine Lost Ark
Affidea ExpressCare - Affidea Ireland
Mr Tire Prince Frederick Md 20678
Craigslist Kennewick Pasco Richland
Nesb Routing Number
Lowes 385
What's New on Hulu in October 2023
Craigslist Phoenix Cars By Owner Only
Progressbook Brunswick
My.doculivery.com/Crowncork
Sams Early Hours
Vcuapi
Bad Moms 123Movies
Best Nail Salon Rome Ga
Justified Official Series Trailer
Idaho Harvest Statistics
St. Petersburg, FL - Bombay. Meet Malia a Pet for Adoption - AdoptaPet.com
Glenda Mitchell Law Firm: Law Firm Profile
Panic! At The Disco - Spotify Top Songs
Shiftselect Carolinas
Theater X Orange Heights Florida
Exl8000 Generator Battery
Kingdom Tattoo Ithaca Mi
Southland Goldendoodles
Rek Funerals
What we lost when Craigslist shut down its personals section
Mississippi Craigslist
His Only Son Showtimes Near Marquee Cinemas - Wakefield 12
Club Keno Drawings
Gina's Pizza Port Charlotte Fl
Petsmart Distribution Center Jobs
Despacito Justin Bieber Lyrics
The 38 Best Restaurants in Montreal
Frank 26 Forum
Kazwire
Sas Majors
Tricare Dermatologists Near Me
Pink Runtz Strain, The Ultimate Guide
Yakini Q Sj Photos
Arch Aplin Iii Felony
Spreading Unverified Info Crossword Clue
Big Brother 23: Wiki, Vote, Cast, Release Date, Contestants, Winner, Elimination
Identogo Manahawkin
Latest Posts
Article information

Author: Kimberely Baumbach CPA

Last Updated:

Views: 6210

Rating: 4 / 5 (41 voted)

Reviews: 80% of readers found this page helpful

Author information

Name: Kimberely Baumbach CPA

Birthday: 1996-01-14

Address: 8381 Boyce Course, Imeldachester, ND 74681

Phone: +3571286597580

Job: Product Banking Analyst

Hobby: Cosplaying, Inline skating, Amateur radio, Baton twirling, Mountaineering, Flying, Archery

Introduction: My name is Kimberely Baumbach CPA, I am a gorgeous, bright, charming, encouraging, zealous, lively, good person who loves writing and wants to share my knowledge and understanding with you.