Zum Inhalt springen

Tech Guides
By Egodget Tech Team
•
Updated: October 2026

How to Set Up BitLocker on Windows 10 Pro

How to Set Up BitLocker on Windows 10 Pro

Short answer: To set up BitLocker on Windows 10 Pro, sign in as an administrator, select Start, type BitLocker, open Manage BitLocker, and select Turn on BitLocker next to drive C:. Save the recovery key somewhere that is not on this PC, choose how much of the drive to encrypt, and start. The wizard takes a few minutes; the encryption itself runs in the background and can take from minutes to hours. The one step that matters most is the recovery key: lose it and you can lose everything on the drive.

Applies to: Windows 10 Pro, Enterprise and Education. The steps are the same on Windows 11 Pro. BitLocker is not available on Windows Home. Windows 10 reached end of support on October 14, 2025.

What you need

Requirement Detail How to check
Windows edition Pro, Enterprise or Education. Microsoft states it is not available on Home. Settings > System > About > Edition
TPM Version 1.2 or later for the standard setup Press Windows + R, run tpm.msc
Administrator account Needed to turn BitLocker on Settings > Accounts > Your info
Somewhere to keep the recovery key A Microsoft account, a USB drive, or a printer Decide before you start

If the PC runs Windows 10 Home, the edition is what is missing, not the hardware. Home has to be upgraded first: see how to upgrade Windows 10 Home to Pro.

A TPM is a security chip, or a function built into the processor, that holds the encryption key and releases it only when the PC starts up unmodified. That is what lets BitLocker unlock the drive automatically at startup without asking you for anything.

Understand the recovery key first

The recovery key is a 48-digit number that BitLocker creates when you turn it on. Windows asks for it when it cannot unlock the drive the usual way, for example after a motherboard replacement, a firmware update, or moving the drive to another PC.

There is no back door. Neither Microsoft nor anyone else can open an encrypted drive without the key. So before you start, decide where it will live:

Option Good for Watch out for
Save to your Microsoft account Easy to retrieve from any device by signing in Only offered if you sign in to Windows with a Microsoft account
Save to a USB flash drive Keeps it offline Do not leave that USB drive in the laptop bag
Save to a file Storing in a password manager or on another PC Windows will not let you save it to the drive being encrypted
Print it A copy that cannot be hacked Paper gets lost. Keep it with other important documents.

Use two of these, not one.

Where to keep the BitLocker recovery key: Microsoft account, USB drive, file, or printout

How to set up BitLocker on Windows 10 Pro

  1. Back up your important files to another drive. Encryption is reliable, but any operation that rewrites the whole drive deserves a backup.
  2. Plug a laptop into power.
  3. Sign in with an administrator account.
  4. Select Start, type BitLocker, and select Manage BitLocker. It is also in Control Panel > System and Security > BitLocker Drive Encryption.
  5. Next to Operating system drive (C:), select Turn on BitLocker.
  6. Choose how to back up the recovery key, and complete at least one option. Then select Next.
  7. Choose how much to encrypt:
    • Encrypt used disk space only for a new PC or a freshly installed drive. It is faster.
    • Encrypt entire drive for a PC that has been in use, so that deleted files still recoverable from free space are covered too.
  8. Choose the encryption mode. Keep New encryption mode for an internal drive that will stay in this PC.
  9. Leave Run BitLocker system check ticked and select Continue.
  10. Restart when asked. Encryption begins after the restart and runs in the background.

You can keep using the PC while it encrypts. Avoid shutting it down by force until it finishes; a normal shutdown or sleep is fine, and it resumes where it stopped.

On a PC with a TPM, that is all. The drive now unlocks by itself each time the PC starts, and you sign in to Windows as usual. You are not asked for a BitLocker password at startup.

To encrypt a second internal drive or an external drive, select Turn on BitLocker next to it on the same page. For removable drives this is called BitLocker To Go, and you set a password for the drive.

How to set up BitLocker on Windows 10 Pro: Manage BitLocker, Turn on BitLocker, save the recovery key, encrypt

Check that the drive is encrypted

Open Manage BitLocker again. Drive C: should read BitLocker on. While it is still working, it reads BitLocker Encrypting.

For the detail, open Command Prompt as administrator and run:

manage-bde -status C:

Look at three lines:

  • Conversion Status should be Fully Encrypted, or Used Space Only Encrypted if you chose that option.
  • Percentage Encrypted should be 100.0%.
  • Protection Status should be Protection On.

In File Explorer, an encrypted drive shows a padlock on its icon. An open padlock means the drive is encrypted and currently unlocked, which is normal for the drive Windows is running from.

If the PC has no TPM

If the wizard says “This device can’t use a Trusted Platform Module”, check first whether the TPM is only switched off. Restart into the firmware settings and look for Intel PTT, AMD fTPM or Security Device Support, enable it, and try again.

If the PC really has none, BitLocker can still work, with trade-offs. Microsoft’s documentation says that without a TPM you must save a startup key on a removable drive, which then has to be plugged in every time the PC starts. A startup password is the other option, and Microsoft discourages it because there is no lockout against repeated guessing. Neither gives the startup integrity check that a TPM provides.

To allow it:

  1. Press Windows + R, run gpedit.msc.
  2. Go to Computer Configuration > Administrative Templates > Windows Components > BitLocker Drive Encryption > Operating System Drives.
  3. Open Require additional authentication at startup, set it to Enabled, and tick Allow BitLocker without a compatible TPM.
  4. Select OK, then run the BitLocker wizard again and choose Insert a USB flash drive.

Living with BitLocker

Situation What to do
Before a firmware (BIOS/UEFI) update or a hardware change In Manage BitLocker, select Suspend protection. Resume it afterward. This avoids a recovery key prompt.
The PC asks for the recovery key at startup Enter the 48-digit key. If it was saved to a Microsoft account, sign in at account.microsoft.com/devices/recoverykey from another device.
You want another copy of the key Manage BitLocker > Back up your recovery key
Selling or giving away the PC Reset Windows with Remove everything. Encrypted data on the old drive is unreadable without the key.
You want to remove encryption Manage BitLocker > Turn off BitLocker. Decryption takes as long as encryption did.

BitLocker protects the drive when the PC is off or locked: a thief cannot read it by removing the drive or starting from a USB stick. It does not protect against malware running while you are signed in, and it is not a backup. A failed encrypted drive is as lost as a failed unencrypted one.

If something goes wrong

Problem Likely cause What to do
There is no BitLocker option at all Windows 10 Home Upgrade to Pro
“This device can’t use a Trusted Platform Module” TPM off or absent Enable it in the firmware settings, or use the no-TPM policy above
BitLocker is managed by your organization A work PC with a policy applied Ask your IT department. On managed PCs they hold the recovery keys.
Encryption seems stuck It pauses on battery power and when the PC is busy Plug in and leave it. Check progress with manage-bde -status.
Recovery key requested after every restart A firmware setting changed, or a USB device affects startup Unplug extra devices, then suspend and resume protection once

Related: Windows 11 Home vs Pro covers what else Pro adds. The keys we sell for Pro: Windows 10 Pro and Windows 11 Pro.

What BitLocker protects and what it does not: stolen drive yes, malware and drive failure no

Need Windows 10 Pro for BitLocker?

BitLocker is not included in Home. One key for one PC.

Microsoft Windows 10 Pro OEM Key

1 PC • Lifetime License

$15.99

Get Your License Key


Email Delivery in 1 to 12 Hours • 90-Day Money-Back Guarantee

Leave a Reply