Skip to content
Rooken

How to set up BitLocker on your work PC

· 6 min read

If your laptop is stolen, the computer itself is rarely the biggest loss. It is the contents: customer lists, accounts, contracts, photos, passwords saved in the browser. Without encryption, a thief can take the disk out, put it in another computer and read everything, without knowing your password.

BitLocker is Windows’ built-in disk encryption. When it is on, the contents of the disk are unreadable to anyone who cannot unlock the computer. It costs nothing, it has no noticeable effect on daily use, and it is one of the most effective single things you can do for your data.

Before you start: two things to know

BitLocker requires Windows Pro. Windows comes in several editions, and full BitLocker ships with the Pro edition, which most work computers are delivered with. If you have the Home edition, your computer may instead have a simpler feature called device encryption, found under Settings, Privacy and security. If you see neither, your computer cannot encrypt with built-in tools.

The recovery key is not optional. During setup you get a recovery key: a long numeric code that can unlock the disk if everything else fails, for example after a hardware fault or a forgotten password. If you lose both your access and the key, the data is gone. Not “hard to recover”, but gone. That is the whole point of encryption. Take the key seriously before switching anything on.

Step 1: Find BitLocker

Press the Start button and search for BitLocker. Choose the item called Manage BitLocker. You get an overview of the computer’s drives, typically with the C drive at the top.

Step 2: Switch encryption on

Click Turn on BitLocker next to the C drive. Windows checks whether the computer meets the requirements. Most newer computers have a built-in security chip (called a TPM) that BitLocker uses, and then the process runs without further ado. If you get an error about a missing TPM, note down the message and ask someone you trust rather than changing advanced settings on your own.

Step 3: Save the recovery key properly

Windows offers several ways to save the key. Choose at least one, preferably two:

  • Save to your Microsoft account: the easiest option. The key can later be found by logging on to the account from another device.
  • Print it: keep the paper somewhere safe that is not the laptop bag. A drawer at home is better than the bag next to the computer.
  • Save as a file: only on a different disk than the one you are encrypting, for example a USB stick stored separately.

Avoid the one trap that makes the key worthless: saving it on the very computer you are encrypting.

Step 4: Let the encryption run

Choose to encrypt the entire drive if asked, and let the computer work. Encryption runs in the background and can take from half an hour to a few hours depending on the size of the disk. You can use the computer meanwhile.

Afterwards: what changes?

In daily use: nothing. You log on as usual, and your files behave as usual. The difference only shows if the computer is stolen or lost; then the disk is an unreadable brick to everyone but you.

One last piece of advice: the encryption is only as strong as the password or PIN that unlocks the computer. An encrypted disk behind the code 1234 is a nice curtain in front of an open door. Use a code that cannot be guessed, and let the screen lock automatically when you leave the computer.