Skip to main content

Encrypting a Windows PC Using BitLocker

Why?

Full-Disk Encryption such as BitLocker protects a user’s data from theft. Even if a hard drive is stolen and placed in another computer, the contents are unreadable without the user’s password or a recovery key.

Note: As long as the machine has been joined to the domain BEFORE activating Bitlocker, they key will be automatically backed up to the domain. We no longer need to manually save copies of the key / back them up. If you’re getting a prompt to do so, then the machine still needs joined to the domain. See Windows Reimaging Guide for instructions on joining a machine to the domain.

Enabling Bitlocker

  • Search for ‘BitLocker’ in the search bar or launch “Manage BitLocker” from the Control Panel.
  • Launch the BitLocker screen, then click “Turn on BitLocker” to enable BitLocker.
  • Select “Encrypt used disk space only” and hit “Next.”
  • Select “New encryption mode” and hit “Next.”
  • Hit “Start Encrypting” and BitLocker will encrypt.