How to Choose BitLocker Encryption Type on Windows 11 Drives
You choose your BitLocker encryption type on Windows 11 drives to secure your data based on your needs.
BitLocker is a built-in Windows feature that encrypts your entire drive or specific data, protecting it from unauthorized access. This ensures that even if your device is lost or stolen, your sensitive files remain inaccessible.
When setting up BitLocker on a Windows 11 drive, you typically face two main encryption options: “Used space only” and “Full drive encryption.” The “Used space only” option encrypts only the sectors on the drive that currently contain data, which is faster but offers less security for deleted file remnants. “Full drive encryption” encrypts every sector of the drive, providing maximum security.
You choose between “Used space only” and “Full drive encryption” when setting up BitLocker. “Full drive encryption” encrypts all sectors for maximum security, while “Used space only” encrypts only existing data for faster setup.
What is BitLocker?
BitLocker is a built-in Windows feature that helps protect your data by encrypting your drives. It works on:
- External drives like USB sticks
- Fixed drives inside your computer
- Your main Windows system drive
When you use BitLocker on your main Windows drive, it can unlock automatically when your computer starts. This happens thanks to a special security chip called TPM.
Encryption Types for Fixed Drives
When you turn on BitLocker for a fixed data drive (like a secondary hard drive inside your PC), it will ask you to choose one of two encryption types:
- Full Encryption: Encrypts the entire drive — even empty space. This takes longer but is the safest choice.
- Used Space Only Encryption: Encrypts only the space where your files are stored. This is faster but less complete.
How to Make Windows Always Use One Encryption Type
Why would you want this? Because you won’t have to choose every single time you encrypt a drive.
What happens when you set this? Windows will automatically pick one encryption type for you without asking.
If you want Windows to always pick one encryption type, you can set a rule using Windows tools. Here are two ways to do it.
Method 1Using Local Group Policy Editor
- Press the Start button and type
Edit group policy, then open the Local Group Policy Editor. - In the window that opens, go to this folder:
Computer Configuration > Administrative Templates > Windows Components > BitLocker Drive Encryption > Fixed Data Drives - Find
Enforce drive encryption type on fixed data driveson the right and double-click it. - Choose one of these options:
Not Configured(default): Windows will ask you every time which encryption type to use.Enabled: You pick the encryption type below, and Windows will use it automatically without asking.Disabled: Same as Not Configured — Windows asks you each time.
- If you selected
Enabled, choose either:- Full encryption
- Used space only encryption
- Click
OKto save. - Restart your computer to apply the changes.
Here’s what this setting looks like:

And here are the options you can pick:

Method 2Using Windows Registry Editor
If you prefer, you can also make this change using the Registry Editor. Be careful — editing the registry incorrectly can cause issues, so follow these steps exactly.
- Open the Windows Registry Editor as administrator. Search for
regeditin Start, then right-click and chooseRun as administrator. ⚠️ Requires admin privileges - Go to this folder in the Registry Editor:
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\FVE - Look for a value named
FDVEncryptionTypein the right pane. - If it’s not there, right-click on the right side, pick
New > DWORD (32-bit) Value, and name itFDVEncryptionType. - Double-click
FDVEncryptionTypeand set its value to:1for Full encryption2for Used space only encryption
- Click
OKand close the Registry Editor. - Restart your computer to apply changes.

If you want to go back to letting Windows ask which encryption type to use, just delete the FDVEncryptionType value from the registry.
Summary
- BitLocker protects your drives by encrypting them so only authorized users can access your data.
- You can choose how BitLocker encrypts fixed drives: full drive or used space only.
- Using the Group Policy Editor or Registry Editor, you can force Windows to always use one encryption type without asking.
- Remember to restart your computer after making these changes.
Want to learn more or give feedback? Visit the original guide here: How to Turn On BitLocker in Windows 11.
How do I select the encryption type in BitLocker?
Open the Start Menu and search for Edit group policy to open the program. Navigate to Computer Configuration > Administrative Templates > Windows Components > BitLocker Drive Encryption. Double-click Choose drive encryption method and cipher strength (Windows 10 [Version 1511] and later).
Was this guide helpful?
About the Author
Richard
Tech Writer, IT Professional
Richard, a writer for Geek Rewind, is a tech enthusiast who loves breaking down complex IT topics into simple, easy-to-understand ideas. With years of hands-on experience in system administration and enterprise IT operations, he’s developed a knack for offering practical tips and solutions. Richard aims to make technology more accessible and actionable. He's deeply committed to the Geek Rewind community, always ready to answer questions and engage in discussions.
No comments yet — be the first to share your thoughts!