Skip to content
Follow
Windows

How to Verify Device Encryption Support in Windows 11

Richard
Written by
Richard
Feb 19, 2024 Updated Oct 5, 2026 5 min read
How to Send and Receive Text Messages on Windows 11
How to Send and Receive Text Messages on Windows 11

Device encryption in Windows 11 scrambles the files on your hard drive to protect your personal data if your laptop or desktop goes missing. Nobody can read your files without your password or sign-in details. It works much like BitLocker (a built-in Windows security feature that locks whole drives). Checking whether your PC can run it takes less than 60 seconds, and you don’t need to install anything.

Advertisement

You can check in two places: the System Information tool or the Settings app. Both show whether your hardware meets the system requirements. Windows Security also lists the hardware pieces involved, such as the security processor, on its device security screen. This guide covers all three.

⚡ Quick Answer

Check your system information by running msinfo32 and looking for “Automatic Device Encryption Support.” Alternatively, go to Settings Privacy & security Device encryption to see if the feature is available and enabled.

Advertisement

Prerequisites for Device Encryption

Device encryption on Windows 11 needs specific hardware inside your computer. You must have a Trusted Platform Module (TPM) 2.0 chip (a security chip built into your motherboard). You also need UEFI firmware (a modern replacement for traditional motherboard firmware) with Secure Boot turned on, and Modern Standby support (a power state that keeps essential background tasks running). You also need a Microsoft account, because Windows uses it to save your recovery key.

If any one of these is missing, Windows will not turn on automatic encryption. Most PCs sold with Windows 11 already meet the first two requirements. Modern Standby is the one that most often rules out older or desktop machines.

  • A TPM 2.0 chip (Trusted Platform Module). This is the chip that stores the encryption keys safely.
  • UEFI firmware with Secure Boot enabled. Secure Boot can be switched off in the firmware settings, so a PC with UEFI may still fail this check.
  • A Microsoft Account (for automatic recovery key backup). Keep the recovery key available. You will need it if Windows ever asks for it after a hardware or firmware change.
  • Modern Standby support (for automatic encryption).
Warning: Always back up your recovery key to your Microsoft account before enabling encryption. If you lose this key, you will be permanently locked out of your files. Visit Microsoft Account Recovery to manage your keys.

Device Encryption vs. BitLocker

Device Encryption is a streamlined version of BitLocker. It is built for standard users and runs automatically on compatible hardware, so there is very little to configure. Standard BitLocker is for Windows 11 Pro, Enterprise, or Education users and offers more advanced configuration tools. With it you get deeper control over how drives lock and how security settings are managed.

In practice, Home users get Device Encryption only. Pro users can use either, and the extra controls are the main reason to choose full BitLocker.

Advertisement

Check Support Using System Information

The built-in System Information tool shows your device encryption compatibility. You can use it to see whether your PC meets the hardware requirements without installing anything extra. Open the Start menu, search for System Information, right-click it, and pick Run as administrator. Then look near the bottom of the summary page for the Automatic Device Encryption Support line to find your status.

The steps below walk through it one at a time.

  1. Click the Start menu and type msinfo32. System Information should appear at the top of the search results.
  2. Right-click System Information and select Run as administrator. (Requires admin privileges) If a User Account Control prompt appears, click Yes. If you are on a standard account, you will be asked for an administrator password. The System Information window then opens on the System Summary page.
Windows search for msinfo32
Windows search for msinfo32
  1. Scroll down the list in the right pane until you see Automatic Device Encryption Support. It sits near the bottom, below items such as Secure Boot State and Virtualization-based security.
  2. Read the value next to it. If your computer is ready, it will say "Meet prerequisites" (some builds word it as "Meets prerequisites"). If not, it will explain why. The reason usually points to the missing piece, such as a TPM that is not usable, Secure Boot being off, or no Modern Standby. Once you know the cause, you can check the matching setting in your firmware or ask the PC maker whether the hardware supports it.
Automatic Device Encryption meets prerequisites in Windows 11
Automatic Device Encryption meets prerequisites in Windows 11
Automatic Device Encryption doesn't meet
Automatic Device Encryption doesn't meet

Check Support Using Windows Settings

The Settings app also shows your current encryption status. Press the Windows key plus I to open Settings, click Privacy & security on the left side, and then click the Device encryption tile. If your hardware is compatible, you can turn the feature on or off from this screen.

The Device encryption tile only appears on PCs that support it. If you can't find it, the hardware check above will usually tell you why. On some Pro, Enterprise, or Education systems, encryption is managed through BitLocker settings instead.

Advertisement
  1. Open the Settings app by pressing the Windows key + I. The Settings window opens on the System page.
Windows Privacy and security button in Settings
Windows Privacy and security button in Settings
  1. Click Privacy & security on the left menu. The privacy and security options now fill the right side of the window.
  2. Click the Device encryption tile on the right. It is listed under the Security section. If it isn't there, your PC does not currently meet the requirements.
Windows Device encryption tile
Windows Device encryption tile
  1. Check the page that opens. Here, you can see if the feature is available and toggle it on or off. If you turn it off, Windows decrypts the drive, which can take some time. Turn it back on the same way if you change your mind.
Device encryption settings in Windows 11
Device encryption settings in Windows 11

Summary

Device Encryption remains a vital security feature for Windows 11. It protects your data through the TPM 2.0 chip and Secure Boot. Checking the support status in System Information or Settings confirms your hardware is ready. Backing up your recovery key to your Microsoft account prevents lockout if Windows ever asks for it.

Reference: Microsoft Official Documentation

Was this guide helpful?

Tags: #Windows 11
Was this helpful?
Richard

About the Author

Richard

Tech Writer, IT Professional

Richard is a writer at Geek Rewind who turns complex IT tasks into clear, step-by-step guides. He draws on years of hands-on experience in system administration and enterprise IT operations, focusing on Windows, Linux and WordPress: the problems people actually run into, and the fixes that work. His server and WordPress guides come from systems he runs himself. Richard builds and maintains the platform behind Geek Rewind, from its Ubuntu servers and Nginx configuration to its custom WordPress plugins. Many new tutorials start with readers' questions, and he's always glad to answer them in the comments.

Advertisement

📚 Related Tutorials

How to Enable Device Encryption in Windows 11
Windows How to Enable Device Encryption in Windows 11
How to Check Secure Boot On Windows 11
Windows How to Check Secure Boot On Windows 11
How to Change BitLocker Encryption in Windows 11
Windows How to Change BitLocker Encryption in Windows 11
How to Open the Settings App in Windows 11
Windows How to Open the Settings App in Windows 11

1 Comment

Leave a Comment

Your email address will not be published. Required fields are marked *