Skip to content
Follow
Windows

How to Choose BitLocker Encryption Type On Windows 11 Drives

Richard
Written by
Richard
Feb 1, 2026 Updated Oct 5, 2026 7 min read
How to Choose BitLocker Encryption Type on Windows 11 Drives
How to Choose BitLocker Encryption Type on Windows 11 Drives

BitLocker encryption types on Windows 11 determine how thoroughly your storage drive scrambles data to protect your personal files if your PC gets lost or stolen. Windows 11 gives you 2 choices when you set up drive encryption: “Used space only” or “Full drive encryption”.

Advertisement

“Used space only” locks down active files and finishes the setup process much faster, while “Full drive encryption” scrambles every single sector on the drive, including empty space, to stop anyone from recovering deleted files. The choice is made once, when you turn BitLocker on for a drive. This guide explains the difference, then shows how to make Windows pick one type for you every time.

⚡ Quick Answer

You choose between “Used space only” and “Full drive encryption” when setting up BitLocker. “Full drive encryption” encrypts all sectors for maximum security, while “Used space only” encrypts only existing data for faster setup.

Advertisement

What is BitLocker?

BitLocker is a built-in Windows security feature that scrambles the data on your hard drives so nobody can read it without your password or recovery key. You can turn on BitLocker for your main system drive, extra internal drives, or portable USB sticks to keep your private files safe from snoops if your computer gets lost or stolen.

Keep your recovery key somewhere safe and away from the PC. If you lose both your password and the recovery key, the data on the drive cannot be recovered.

  • External drives like USB sticks
  • Fixed drives inside your computer
  • Your main Windows system drive

Enabling BitLocker on your primary system drive allows it to unlock automatically when the computer boots up. This happens automatically thanks to the Trusted Platform Module (TPM), a dedicated security chip on your motherboard.

Data drives and USB sticks do not get this treatment. You will normally unlock them with a password, a smart card, or an automatic unlock setting tied to your Windows account.

Advertisement

Encryption Types for Fixed Drives

BitLocker gives you two encryption types for fixed internal drives when you set up security. You can choose to encrypt the whole drive including empty space for maximum protection, or you can choose to encrypt only the space currently used by your files to finish the setup process much faster.

The choice only matters at the moment you turn BitLocker on. Once a drive is encrypted, changing the setting later does not re-encrypt it. To switch types, you would have to turn BitLocker off for that drive and set it up again.

  • Full Encryption: Encrypts the entire drive — even empty space. This takes longer but is the safest choice. It is the right pick for a drive that has already been in use, because old deleted files can still sit in the empty space and be recovered with the right tools. On a large drive, expect the process to take a good while.
  • Used Space Only Encryption: Encrypts only the space where your files are stored. This is faster but less complete. It works well on a new, empty drive, since there is no old data hiding in the free space. Files you add later are encrypted as they are written.

How to Make Windows Always Use One Encryption Type

Windows 11 lets you set a default BitLocker encryption type so you do not have to pick your preferred security setting every time you plug in a new drive. Forcing a specific encryption method saves time and ensures every new storage device you connect uses full disk protection right away.

This is a policy setting, so it also stops other people who use the PC from choosing the weaker option by mistake.

Advertisement

You can configure Windows 11 to select full disk encryption for every drive automatically. This default behavior maintains consistent data protection right from the start. If you prefer speed on new drives, you can set the default to used space only instead.

Enforcing a single encryption choice requires creating a system rule using native Windows configuration utilities. Two distinct methods accomplish this goal: the Local Group Policy Editor and the Registry Editor. The Group Policy Editor is the easier and safer of the two, but it is only included in Windows 11 Pro, Enterprise and Education. On Windows 11 Home, use the Registry Editor method.

Method 1Using Local Group Policy Editor

  1. Press the Start button and type Edit group policy, then open the Local Group Policy Editor. If nothing matching appears, you are probably on Windows 11 Home, which does not include this tool.
  2. In the window that opens, go to this folder in the left pane: Computer Configuration > Administrative Templates > Windows Components > BitLocker Drive Encryption > Fixed Data Drives. The policy settings for that folder now appear on the right.
  3. Find Enforce drive encryption type on fixed data drives on the right and double-click it. A settings window opens with three options at the top left.
  4. Choose one of these options:
    • Not Configured (default): Windows will ask you every time which encryption type to use.
    • Enabled: You pick the encryption type below, and Windows will use it automatically without asking.
    • Disabled: Same as Not Configured — Windows asks you each time.
  5. If you selected Enabled, choose either of the following from the drop-down list in the Options box:
    • Full encryption
    • Used space only encryption
  6. Click OK to save, then close the Local Group Policy Editor.
  7. Restart your computer to apply the changes.

Local Group Policy Editor is a built-in Windows tool you can use to force a specific BitLocker encryption type on all fixed data drives. You can change this setting in a few steps if you want Windows to automatically pick full disk encryption without asking you every time.

The policy only affects drives you encrypt after the change. Drives that are already encrypted stay as they are. To undo it, open the same setting again, choose Not Configured, click OK, and restart.

Advertisement
BitLocker encryption type settings in Group Policy Editor
BitLocker encryption type settings in Group Policy Editor

The image above shows the setting window open on the Enabled option, with the encryption type chosen in the Options box. Check that the type shown there is the one you want before you click the save button.

The following configuration options remain available for selection:

Options for enforcing encryption type on fixed drives
Options for enforcing encryption type on fixed drives

Pick Full encryption for older drives or any drive that has held sensitive data. Pick Used space only encryption for brand-new, empty drives where speed matters more.

Method 2Using Windows Registry Editor

Registry Editor is an advanced Windows tool that lets you set a default BitLocker encryption type by changing system registry keys. Exercise caution here, because making a mistake in the registry can cause serious operating system problems if you edit the wrong files. Before you start, consider creating a restore point or exporting the key you are about to change, so you can roll back if something goes wrong. This method works on both Home and Pro editions.

Advertisement
  1. Open the Windows Registry Editor as administrator. Search for regedit in Start, then right-click and choose Run as administrator. ⚠️ Requires admin privileges If Windows shows a User Account Control prompt, click Yes.
  2. Go to this folder in the Registry Editor: HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\FVE. You can paste the path into the address bar at the top of the window. If a folder along the way does not exist, the policy has never been set on this PC.
  3. Look for a value named FDVEncryptionType in the right pane.
  4. If it's not there, right-click on the right side, pick New > DWORD (32-bit) Value, and name it FDVEncryptionType. The new value appears in the right pane with the name you typed.
  5. Double-click FDVEncryptionType and set its value to:
    • 1 for Full encryption
    • 2 for Used space only encryption
  6. Click OK and close the Registry Editor.
  7. Restart your computer to apply changes.
BitLocker encryption type setting in Registry Editor
BitLocker encryption type setting in Registry Editor

As with the Group Policy method, this only applies to drives you encrypt from now on. Drives that are already encrypted keep the type they were set up with.

Restoring the default behavior where Windows prompts for an encryption method requires deleting the FDVEncryptionType value from the registry.

  1. Open the Registry Editor as administrator and go back to the same key you edited earlier.
  2. Right-click the value in the right pane and choose Delete.
  3. Click Yes to confirm. The value disappears from the list.
  4. Restart your computer. Windows will ask you to choose an encryption type again the next time you turn on BitLocker.

Summary

  • BitLocker protects your drives by encrypting them so only authorized users can access your data.
  • You can choose how BitLocker encrypts fixed drives: full drive or used space only. Full drive is slower but safer for drives that have been used before.
  • Using the Group Policy Editor (Pro and above) or Registry Editor (all editions), you can force Windows to always use one encryption type without asking.
  • Remember to restart your computer after making these changes. They only affect drives you encrypt afterward.

BitLocker encryption type settings let you choose how Windows scrambles your data on internal and external drives to keep files secure. You can pick between full drive encryption or used space only, and you can use system tools to make Windows apply your preferred choice automatically.

Was this guide helpful?

Tags: #Windows 11
Was this helpful?
Richard

About the Author

Richard

Tech Writer, IT Professional

Richard is a writer at Geek Rewind who turns complex IT tasks into clear, step-by-step guides. He draws on years of hands-on experience in system administration and enterprise IT operations, focusing on Windows, Linux and WordPress: the problems people actually run into, and the fixes that work. His server and WordPress guides come from systems he runs himself. Richard builds and maintains the platform behind Geek Rewind, from its Ubuntu servers and Nginx configuration to its custom WordPress plugins. Many new tutorials start with readers' questions, and he's always glad to answer them in the comments.

Advertisement

📚 Related Tutorials

How to Turn On BitLocker to Protect a Data Drive in Windows 11
Windows How to Turn On BitLocker to Protect a Data Drive in Windows 11
How to Enable or Disable BitLocker to Unlock OS Drive with PIN or USB at Startup in Windows 11
Windows How to Enable or Disable BitLocker to Unlock OS Drive with PIN or USB at Startup in Windows 11
How to Encrypt USB Drives in Windows 11 with BitLocker
Windows How to Encrypt USB Drives in Windows 11 with BitLocker
Protect Your Windows 11 with Microsoft Security
Windows Protect Your Windows 11 with Microsoft Security

No comments yet — be the first to share your thoughts!

Leave a Comment

Your email address will not be published. Required fields are marked *