How to enable and use 256-bit BitLocker in Windows 11

How to enable and use 256-bit BitLocker in Windows 11

How to enable 256-bit BitLocker in Windows 11

BitLocker is a built-in encryption tool in Windows 11 that helps protect your data by encrypting your whole operating system and files within it. In case you lose your computer, your data will be protected. However, the feature is exclusive to Pro and Enterprise editions of the Windows operating system.

We strongly recommend specifying the encryption method. By default, BitLocker uses XTS-AES-128. You can opt XTS-AES-256 for stronger security.

If you already have enabled BitLocker on your PC, you will need to unencrypt your drives, enable 256-bit encryption in Windows group policy, and then re-enable BitLocker. If you haven't enabled BitLocker on your PC yet, follow the steps below to enable 256-bit encryption:

  1. Press Windows Key + R to open the Run dialog
  2. Type gpedit.msc and press Enter
  3. Go to Computer Configuration\Administrative Templates\Windows Components\BitLocker Drive Encryption. Look for the "Choose drive encryption method and cipher strength" option for the most recent operating version. For me it was Windows 10 (1511) and double click it.
Make sure you choose the correct options:
It is best to use XTS-AES-256 for operating system drives and fixed drives. Use AES-CBC 256-bit for removable drives so it is more compatible with other devices.


How to Use Bitlocker in Windows 11

Windows 11 allows you to enable BitLocker for operating system drives, fixed drives, as well as removable drives. To turn on Bitlocker on a drive, follow these steps:

Open File Explorer and right-click on the drive you want to encrypt, then select 'Turn on BitLocker' from the context menu.



When you open the BitLocker Drive Encryption wizard, choose how you want to unlock your drive and click 'Next'. You can pick either a password or a smart card to unlock the drive:
Password: Create a password using a mix of capital and lowercase letters, numbers, spaces, and symbols.
Smart Card: You can use a Smart card along with a PIN to unlock the encrypted drive. The card needs to be inserted into your computer every time you want to access the drive.

Select how you want to save your recovery key, which you can use to unlock your drive if you forget your password or lose your smart card. There are a few ways:

  1. Save to Microsoft Account: If you're signed in with a Microsoft account, you can save the recovery key there.
  2. Save to a file: Save the recovery key as a document on your computer.
  3. Print the recovery key: Print the recovery key on paper.
After backing up the recovery key, click 'Next' to continue.

Select how much of the selected drive you want to encrypt and click 'Next'.
  1. Encrypt used disk space only: This is quicker and good for new computers or drives. Only the space with data will be encrypted.
  2. Encrypt the entire drive: This is slower but better if you want to encrypt everything, even unused space. It's best for drives you've been using for a while.
BitLocker will keep encrypting new data as you add it.
Select an encryption mode:
  1. New encryption mode: This is advanced and better for fixed drives on Windows 10 or 11.
  2. Compatible mode: Use this for portable drives you might use on older Windows versions.
If you would like to run a system check before encrypting the drive, check the 'Run BitLocker system check' option and click 'Continue'. This system check ensures whether BitLocker can read the recovery and encryption keys properly.

Click 'Restart now' to continue. After the restart, the system will automatically encrypt the drive.

By the way , if you need Windows 11 Product key to activate your Windows 11 PC, you can get it from the Microsoft Partner Keyingo.com with discounts !

Comments

Popular posts from this blog

How to Find your Windows 11 Product Key

Free SQL Server 2008~2022 Product Key

Visual Studio 2022 Retail Key