Skip to content
Follow
Windows

How to Enable or Disable BitLocker to Unlock OS Drive with PIN or USB at Startup in Windows 11

Richard
Written by
Richard
May 6, 2026 Updated Sep 15, 2026 2 min read
Laptop secure boot screen glowing lock icon
Laptop secure boot screen glowing lock icon

BitLocker Drive Encryption in Windows 11 scrambles the files on your hard drive to protect your data if your computer gets lost or stolen. You can add a startup PIN or a USB key so your PC requires physical proof of identity before it boots up.

Advertisement

Most modern motherboards include a Trusted Platform Module (TPM) 2.0 security chip to handle these hardware-level checks. This security chip works with Windows 11 Pro, Enterprise, and Education editions to lock down your operating system before the login screen appears.

⚡ Quick Answer

Enable BitLocker startup authentication by navigating to Computer Configuration Administrative Templates Windows Components BitLocker Drive Encryption Operating System Drives in Group Policy Editor and enabling “Require additional authentication at startup.” Ensure “Allow BitLocker without a compatible TPM” is unchecked unless your PC lacks a TPM.

Advertisement

Enable or Disable BitLocker Settings (Admin Required)

Administrator privileges are needed to perform these steps. If you’re using Windows 11 Pro, you can use the Group Policy Editor.

Using Group Policy Editor

You can configure a BitLocker PIN startup requirement on Windows 11 by using the built-in Group Policy Editor to change how your operating system drive unlocks. This tool lets you turn the startup authentication policy on or off quickly. Follow these steps to set up a PIN or USB startup key for your computer.

1. Press Win+R, type gpedit.msc, and hit Enter.

2. Navigate to: Computer Configuration Administrative Templates Windows Components BitLocker Drive Encryption Operating System Drives.
3. Double-click Require additional authentication at startup.
4. Select Enabled. Ensure the box for Allow BitLocker without a compatible TPM is unchecked unless your PC lacks a TPM.

Advertisement
Group Policy Editor window for BitLocker require additional authentication at startup
Group Policy Editor window for BitLocker require additional authentication at startup
BitLocker settings window showing additional authentication options for Windows 11 startup
BitLocker settings window showing additional authentication options for Windows 11 startup

5. Click OK.

Using Registry Editor (GUI Alternative)

You can configure a BitLocker PIN startup requirement through the Registry Editor if your Windows version does not include the Group Policy Editor. This method uses registry keys to achieve the exact same security settings for your drive. Follow these steps to create and change the right values on your system.

1. Press Win + R, type regedit, and hit Enter.
2. Navigate to: HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\FVE.
3. In the right-hand pane, right-click on an empty space, select 'New' > 'DWORD (32-bit) Value', and then name the new value UseAdvancedStartup. Set its value to 1.
4. Repeat this for the other keys below, setting their values as follows:

  • EnableBDEWithNoTPM set to 0
  • UseTPM set to 2
  • UseTPMPIN set to 2
  • UseTPMKey set to 2
  • UseTPMKeyPIN set to 2

To restore the default behavior, delete the keys created above.

Advertisement

Using Command Line (manage-bde)

Advanced users can also utilize the manage-bde command-line tool. Open Command Prompt as an administrator and type: manage-bde -protectors -add C: -TPMAndPIN. This command sets up the PIN requirement for your C: drive.

Troubleshooting 'PIN Not Available'

⚠️WarningIf your PIN isn't working, check that your BIOS/UEFI is set to use UEFI mode and that Secure Boot is enabled.

If you can't enter a PIN, try using your recovery key to boot, then remove and re-add the PIN protector in the BitLocker settings menu.

Settings menu to change how BitLocker unlocks the OS drive
Settings menu to change how BitLocker unlocks the OS drive
Windows 11 BitLocker options for configuring PIN or USB startup authentication
Windows 11 BitLocker options for configuring PIN or USB startup authentication

Summary

Adding a BitLocker PIN or USB key at startup makes your Windows 11 computer more secure.

Was this guide helpful?

Tags: #Windows 11
Was this helpful?
Richard

About the Author

Richard

Tech Writer, IT Professional

Richard is a writer at Geek Rewind who turns complex IT tasks into clear, step-by-step guides. He draws on years of hands-on experience in system administration and enterprise IT operations, focusing on Windows, Linux and WordPress: the problems people actually run into, and the fixes that work. His server and WordPress guides come from systems he runs himself. Richard builds and maintains the platform behind Geek Rewind, from its Ubuntu servers and Nginx configuration to its custom WordPress plugins. Many new tutorials start with readers' questions, and he's always glad to answer them in the comments.

Advertisement

📚 Related Tutorials

How to Back Up Your BitLocker Recovery Key in Windows 11
Windows How to Back Up Your BitLocker Recovery Key in Windows 11
How to Install TeamViewer via Command Line on Ubuntu
Ubuntu Linux How to Install TeamViewer via Command Line on Ubuntu
How to Disable App Installations on Non-System Drives in Windows 11
Windows How to Disable App Installations on Non-System Drives in Windows 11
How to Lock a BitLocker Drive in Windows 11
Windows How to Lock a BitLocker Drive in Windows 11

No comments yet — be the first to share your thoughts!

Leave a Comment

Your email address will not be published. Required fields are marked *