Follow
Windows

How to Change BitLocker Encryption in Windows 11

Richard
Written by
Richard
May 12, 2024 Updated Apr 3, 2026 3 min read
BitLocker drive encrytion featured image
BitLocker drive encrytion featured image

You change BitLocker encryption in Windows 11 by adjusting its encryption algorithm and key strength, typically from the default XTS-AES 128-bit to XTS-AES 256-bit.

BitLocker is a drive encryption feature built into Windows that protects your data from unauthorized access. This means only you or authorized users can view the files stored on your encrypted drives, ensuring your sensitive information remains secure.

You can apply BitLocker protection to your operating system drive, internal storage drives, and even removable drives like USB flash drives. By default, Windows 11 uses XTS-AES 128-bit encryption, but increasing this to 256-bit offers a more robust security level for all your protected drives.

⚡ Quick Answer

Change BitLocker encryption by opening Local Group Policy Editor and navigating to Computer Configuration > Administrative Templates > Windows Components > BitLocker Drive Encryption. Double-click “Choose drive encryption method and cipher strength” to select your desired algorithm and key strength, then restart your computer.

Why Change Your BitLocker Settings?

A stronger encryption code makes your data harder for others to crack. If you work with very sensitive information, using 256-bit encryption gives you extra protection.

What Happens When You Change These Settings?

Your files stay protected with the new, stronger encryption. New files you create will use the new settings right away. Your computer may need to restart for the changes to work.

Method 1Use Group Policy Editor

This method works best if you understand your computer settings.

  1. Open the Local Group Policy Editor. Search for “Edit group policy” on your Start menu.
  2. Follow these folders in order:
    • Computer Configuration
    • Administrative Templates
    • Windows Components
    • BitLocker Drive Encryption
  3. On the right side, find “Choose drive encryption method and cipher strength (Windows 10 (Version 1511) and later)”. Double-click it.
Choose drive encryption method and cipher
Choose drive encryption method and cipher
  1. A window opens. You have three choices:
    • Not Configured (this is the default) – BitLocker uses its standard settings
    • Enabled – you pick the encryption type yourself
    • Disabled – BitLocker uses AES with 128-bit or 256-bit strength
Drive encryption method and cipher options
Drive encryption method and cipher options
  1. If you pick Enabled, use the dropdown menu under Options. Choose your encryption method for:
    • Operating system drives (your main drive)
    • Fixed data drives (regular storage)
    • Removable data drives (USB sticks)
  2. Click OK to save. You may need to restart your computer.
Drive and encryption method and cipher settings
Drive and encryption method and cipher settings

Method 2Use Registry Editor

⚠️ Admin Required – You need administrator access for this method.

The Registry Editor is where Windows stores all its settings. Changing the wrong thing can cause problems. Be careful with this method.

  1. Open the Windows Registry Editor. Search for “regedit” on your Start menu.
  2. Find this path in the left panel:

    HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\FVE
  3. Look at the right side. You should see three items with these names:
    • EncryptionMethodWithXtsOs
    • EncryptionMethodWithXtsFdv
    • EncryptionMethodWithXtsRdv
  4. Double-click each one and change its value:
    • Enter 4 to use AES-CBC 256-bit encryption
    • Enter 7 to use XTS-AES 256-bit encryption
Drive and encryption method and cipher registry editor
Drive and encryption method and cipher registry editor
  1. Don’t see these items? Right-click a blank area on the right side. Pick “New” and then “DWORD (32-bit) Value”. Create all three items if they’re missing, then enter the values above.
  2. To go back to the default XTS-AES 128-bit encryption, delete all three items you created or changed.
  3. Save your changes and restart your computer.

Summary

BitLocker protects your files with encryption. By default, it uses XTS-AES 128-bit encryption. You can make it stronger by switching to 256-bit encryption.

You have two ways to change this:

  • Group Policy Editor – easier and safer for most people
  • Registry Editor – more advanced, requires admin access

You can change encryption for your main drive, storage drives, and removable drives. Always restart your computer after making changes. This lets Windows use the new encryption settings.

Stronger encryption takes a bit more computer power but keeps your data much safer.

Was this guide helpful?

Tags: #Windows 11
Was this helpful?
Richard

About the Author

Richard

Tech Writer, IT Professional

Richard, a writer for Geek Rewind, is a tech enthusiast who loves breaking down complex IT topics into simple, easy-to-understand ideas. With years of hands-on experience in system administration and enterprise IT operations, he’s developed a knack for offering practical tips and solutions. Richard aims to make technology more accessible and actionable. He's deeply committed to the Geek Rewind community, always ready to answer questions and engage in discussions.

📚 Related Tutorials

How to Enforce BitLocker Encryption on Removable Drives
Windows How to Enforce BitLocker Encryption on Removable Drives
How to Enforce BitLocker Encryption Types on Windows 11 Drives
Windows How to Enforce BitLocker Encryption Types on Windows 11 Drives
How to Choose BitLocker Encryption Type on Windows 11 Drives
Windows How to Choose BitLocker Encryption Type on Windows 11 Drives
How to Reset Local Group Policy in Windows 11
Windows How to Reset Local Group Policy in Windows 11

No comments yet — be the first to share your thoughts!

Leave a Comment

Your email address will not be published. Required fields are marked *