Skip to content
Follow
Windows

How to Change BitLocker Encryption in Windows 11

Richard
Written by
Richard
May 12, 2024 Updated Sep 15, 2026 3 min read
BitLocker drive encrytion featured image
BitLocker drive encrytion featured image

BitLocker encryption in Windows 11 locks your entire hard drive so snoopers cannot read your personal files if your PC goes missing. By default, Windows uses a standard 128-bit cipher, but you can switch to a stronger 256-bit XTS-AES encryption for extra data protection on both main system drives and portable USB sticks.

Advertisement

Stronger encryption takes an extra step because Windows hides the setting away from plain view. You can change this setting using the Local Group Policy Editor (a tool that controls system settings) or Command Prompt in just a few minutes if you want maximum security for your private documents.

⚡ Quick Answer

Change BitLocker encryption by opening Local Group Policy Editor and navigating to Computer Configuration Administrative Templates Windows Components BitLocker Drive Encryption. Double-click “Choose drive encryption method and cipher strength” to select your desired algorithm and key strength, then restart your computer.

Advertisement

Why Change Your BitLocker Settings?

Enhanced cipher strength makes volume data significantly harder to compromise. Workloads handling sensitive information benefit immediately from implementing 256-bit protection.

What Happens When You Change These Settings?

Existing files re-encrypt automatically in the background while remaining fully accessible. Newly created data adopts the upgraded cipher right away. A system reboot may be necessary before changes take full effect.

Method 1Use Group Policy Editor

BitLocker encryption Windows 11 settings can be changed using the Local Group Policy Editor, a built-in tool that lets you adjust drive cipher strength safely. You can open this tool from the Start menu and navigate through the system configuration folders to update your security policies without risking your data.

  1. Open the Local Group Policy Editor. Search for “Edit group policy” on your Start menu .
  2. Follow these folders in order:
    • Computer Configuration
    • Administrative Templates
    • Windows Components
    • BitLocker Drive Encryption
  3. On the right side, find “Choose drive encryption method and cipher strength (Windows 10 (Version 1511) and later)”. Double-click it.
Choose drive encryption method and cipher
Choose drive encryption method and cipher
  1. A window opens. You have three choices:
    • Not Configured (this is the default) – BitLocker uses its standard settings
    • Enabled – you pick the encryption type yourself
    • Disabled – BitLocker uses AES with 128-bit or 256-bit strength
Drive encryption method and cipher options
Drive encryption method and cipher options
  1. If you pick Enabled, use the dropdown menu under Options. Choose your encryption method for:
    • Operating system drives (your main drive)
    • Fixed data drives (regular storage)
    • Removable data drives (USB sticks)
  2. Click OK to save. You may need to restart your computer.
Drive and encryption method and cipher settings
Drive and encryption method and cipher settings

Method 2Use Registry Editor

BitLocker encryption Windows 11 options can be updated directly through the Windows Registry Editor, which is a central database of low-level system settings. You need to open the editor and locate the specific policy keys to alter your encryption strength manually, though you must be careful not to change the wrong values.

Advertisement

The Registry houses low-level operating system configurations. Precision matters when altering these keys.

  1. Open the Windows Registry Editor. Search for "regedit" on your Start menu.
  2. Find this path in the left panel:

    HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\FVE
  3. Look at the right side. You should see three items with these names:
    • EncryptionMethodWithXtsOs
    • EncryptionMethodWithXtsFdv
    • EncryptionMethodWithXtsRdv
  4. Double-click each one and change its value:
    • Enter 4 to use AES-CBC 256-bit encryption
    • Enter 7 to use XTS-AES 256-bit encryption
Drive and encryption method and cipher registry editor
Drive and encryption method and cipher registry editor
  1. Don't see these items? Right-click a blank area on the right side. Pick "New" and then "DWORD (32-bit) Value". Create all three items if they're missing, then enter the values above.
  2. To go back to the default XTS-AES 128-bit encryption, delete all three items you created or changed.
  3. Save your changes and restart your computer.

Summary

BitLocker encryption Windows 11 configurations can be managed using either the Group Policy Editor or the Registry Editor depending on your technical comfort level. The Group Policy Editor provides a safer and easier path for most users, while the Registry Editor gives advanced administrators direct control over system-wide drive security.

Two primary configuration paths exist:

  • Group Policy Editor - easier and safer for most people
  • Registry Editor - more advanced, requires admin access

Encryption upgrades apply universally across system volumes, internal disks, and removable media. Rebooting hardware after policy updates forces Windows to apply the new cipher settings.

Higher cipher complexity demands slightly more processor overhead in exchange for superior data defense.

Was this guide helpful?

Tags: #Windows 11
Was this helpful?
Richard

About the Author

Richard

Tech Writer, IT Professional

Richard is a writer at Geek Rewind who turns complex IT tasks into clear, step-by-step guides. He draws on years of hands-on experience in system administration and enterprise IT operations, focusing on Windows, Linux and WordPress: the problems people actually run into, and the fixes that work. His server and WordPress guides come from systems he runs himself. Richard builds and maintains the platform behind Geek Rewind, from its Ubuntu servers and Nginx configuration to its custom WordPress plugins. Many new tutorials start with readers' questions, and he's always glad to answer them in the comments.

Advertisement

📚 Related Tutorials

How to Enforce BitLocker Encryption on Removable Drives
Windows How to Enforce BitLocker Encryption on Removable Drives
How to Enforce BitLocker Encryption Types on Windows 11 Drives
Windows How to Enforce BitLocker Encryption Types on Windows 11 Drives
How to Choose BitLocker Encryption Type On Windows 11 Drives
Windows How to Choose BitLocker Encryption Type On Windows 11 Drives
How to Enable or Disable BitLocker to Unlock OS Drive with PIN or USB at Startup in Windows 11
Windows How to Enable or Disable BitLocker to Unlock OS Drive with PIN or USB at Startup in Windows 11

No comments yet — be the first to share your thoughts!

Leave a Comment

Your email address will not be published. Required fields are marked *