How to Verify Device Encryption Support in Windows 11
Device encryption in Windows 11 scrambles the files on your hard drive to protect your personal data if your laptop or desktop goes missing. Nobody can read your files without your password or sign-in details. It works much like BitLocker (a built-in Windows security feature that locks whole drives). Checking whether your PC can run it takes less than 60 seconds, and you don’t need to install anything.
You can check in two places: the System Information tool or the Settings app. Both show whether your hardware meets the system requirements. Windows Security also lists the hardware pieces involved, such as the security processor, on its device security screen. This guide covers all three.
Check your system information by running msinfo32 and looking for “Automatic Device Encryption Support.” Alternatively, go to Settings Privacy & security Device encryption to see if the feature is available and enabled.
Prerequisites for Device Encryption
Device encryption on Windows 11 needs specific hardware inside your computer. You must have a Trusted Platform Module (TPM) 2.0 chip (a security chip built into your motherboard). You also need UEFI firmware (a modern replacement for traditional motherboard firmware) with Secure Boot turned on, and Modern Standby support (a power state that keeps essential background tasks running). You also need a Microsoft account, because Windows uses it to save your recovery key.
If any one of these is missing, Windows will not turn on automatic encryption. Most PCs sold with Windows 11 already meet the first two requirements. Modern Standby is the one that most often rules out older or desktop machines.
- A TPM 2.0 chip (Trusted Platform Module). This is the chip that stores the encryption keys safely.
- UEFI firmware with Secure Boot enabled. Secure Boot can be switched off in the firmware settings, so a PC with UEFI may still fail this check.
- A Microsoft Account (for automatic recovery key backup). Keep the recovery key available. You will need it if Windows ever asks for it after a hardware or firmware change.
- Modern Standby support (for automatic encryption).
Device Encryption vs. BitLocker
Device Encryption is a streamlined version of BitLocker. It is built for standard users and runs automatically on compatible hardware, so there is very little to configure. Standard BitLocker is for Windows 11 Pro, Enterprise, or Education users and offers more advanced configuration tools. With it you get deeper control over how drives lock and how security settings are managed.
In practice, Home users get Device Encryption only. Pro users can use either, and the extra controls are the main reason to choose full BitLocker.
Check Support Using System Information
The built-in System Information tool shows your device encryption compatibility. You can use it to see whether your PC meets the hardware requirements without installing anything extra. Open the Start menu, search for System Information, right-click it, and pick Run as administrator. Then look near the bottom of the summary page for the Automatic Device Encryption Support line to find your status.
The steps below walk through it one at a time.
- Click the Start menu and type
msinfo32. System Information should appear at the top of the search results. - Right-click System Information and select Run as administrator. (Requires admin privileges) If a User Account Control prompt appears, click Yes. If you are on a standard account, you will be asked for an administrator password. The System Information window then opens on the System Summary page.

- Scroll down the list in the right pane until you see Automatic Device Encryption Support. It sits near the bottom, below items such as Secure Boot State and Virtualization-based security.
- Read the value next to it. If your computer is ready, it will say "Meet prerequisites" (some builds word it as "Meets prerequisites"). If not, it will explain why. The reason usually points to the missing piece, such as a TPM that is not usable, Secure Boot being off, or no Modern Standby. Once you know the cause, you can check the matching setting in your firmware or ask the PC maker whether the hardware supports it.


Check Support Using Windows Settings
The Settings app also shows your current encryption status. Press the Windows key plus I to open Settings, click Privacy & security on the left side, and then click the Device encryption tile. If your hardware is compatible, you can turn the feature on or off from this screen.
The Device encryption tile only appears on PCs that support it. If you can't find it, the hardware check above will usually tell you why. On some Pro, Enterprise, or Education systems, encryption is managed through BitLocker settings instead.
- Open the Settings app by pressing the Windows key + I. The Settings window opens on the System page.

- Click Privacy & security on the left menu. The privacy and security options now fill the right side of the window.
- Click the Device encryption tile on the right. It is listed under the Security section. If it isn't there, your PC does not currently meet the requirements.

- Check the page that opens. Here, you can see if the feature is available and toggle it on or off. If you turn it off, Windows decrypts the drive, which can take some time. Turn it back on the same way if you change your mind.

Summary
Device Encryption remains a vital security feature for Windows 11. It protects your data through the TPM 2.0 chip and Secure Boot. Checking the support status in System Information or Settings confirms your hardware is ready. Backing up your recovery key to your Microsoft account prevents lockout if Windows ever asks for it.
Reference: Microsoft Official Documentation
Was this guide helpful?
About the Author
Richard
Tech Writer, IT Professional
Richard is a writer at Geek Rewind who turns complex IT tasks into clear, step-by-step guides. He draws on years of hands-on experience in system administration and enterprise IT operations, focusing on Windows, Linux and WordPress: the problems people actually run into, and the fixes that work. His server and WordPress guides come from systems he runs himself. Richard builds and maintains the platform behind Geek Rewind, from its Ubuntu servers and Nginx configuration to its custom WordPress plugins. Many new tutorials start with readers' questions, and he's always glad to answer them in the comments.
[…] article explains how to check if your device’s “Secure Boot” is enabled, disabled, or not supported on Windows […]