How to Enable or Disable BitLocker to Unlock OS Drive with PIN or USB at Startup in Windows 11
BitLocker Drive Encryption in Windows 11 scrambles the files on your hard drive to protect your data if your computer gets lost or stolen. You can add a startup PIN or a USB key so your PC requires physical proof of identity before it boots up.
Most modern motherboards include a Trusted Platform Module (TPM) 2.0 security chip to handle these hardware-level checks. This security chip works with Windows 11 Pro, Enterprise, and Education editions to lock down your operating system before the login screen appears.
Enable BitLocker startup authentication by navigating to Computer Configuration Administrative Templates Windows Components BitLocker Drive Encryption Operating System Drives in Group Policy Editor and enabling “Require additional authentication at startup.” Ensure “Allow BitLocker without a compatible TPM” is unchecked unless your PC lacks a TPM.
Enable or Disable BitLocker Settings (Admin Required)
Administrator privileges are needed to perform these steps. If you’re using Windows 11 Pro, you can use the Group Policy Editor.
Using Group Policy Editor
You can configure a BitLocker PIN startup requirement on Windows 11 by using the built-in Group Policy Editor to change how your operating system drive unlocks. This tool lets you turn the startup authentication policy on or off quickly. Follow these steps to set up a PIN or USB startup key for your computer.
1. Press Win+R, type gpedit.msc, and hit Enter.
2. Navigate to: Computer Configuration Administrative Templates Windows Components BitLocker Drive Encryption Operating System Drives.
3. Double-click Require additional authentication at startup.
4. Select Enabled. Ensure the box for Allow BitLocker without a compatible TPM is unchecked unless your PC lacks a TPM.


5. Click OK.
Using Registry Editor (GUI Alternative)
You can configure a BitLocker PIN startup requirement through the Registry Editor if your Windows version does not include the Group Policy Editor. This method uses registry keys to achieve the exact same security settings for your drive. Follow these steps to create and change the right values on your system.
1. Press Win + R, type regedit, and hit Enter.
2. Navigate to: HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\FVE.
3. In the right-hand pane, right-click on an empty space, select 'New' > 'DWORD (32-bit) Value', and then name the new value UseAdvancedStartup. Set its value to 1.
4. Repeat this for the other keys below, setting their values as follows:
EnableBDEWithNoTPMset to 0UseTPMset to 2UseTPMPINset to 2UseTPMKeyset to 2UseTPMKeyPINset to 2
To restore the default behavior, delete the keys created above.
Using Command Line (manage-bde)
Advanced users can also utilize the manage-bde command-line tool. Open Command Prompt as an administrator and type: manage-bde -protectors -add C: -TPMAndPIN. This command sets up the PIN requirement for your C: drive.
Troubleshooting 'PIN Not Available'
If you can't enter a PIN, try using your recovery key to boot, then remove and re-add the PIN protector in the BitLocker settings menu.


Summary
Adding a BitLocker PIN or USB key at startup makes your Windows 11 computer more secure.
Was this guide helpful?
About the Author
Richard
Tech Writer, IT Professional
Richard is a writer at Geek Rewind who turns complex IT tasks into clear, step-by-step guides. He draws on years of hands-on experience in system administration and enterprise IT operations, focusing on Windows, Linux and WordPress: the problems people actually run into, and the fixes that work. His server and WordPress guides come from systems he runs himself. Richard builds and maintains the platform behind Geek Rewind, from its Ubuntu servers and Nginx configuration to its custom WordPress plugins. Many new tutorials start with readers' questions, and he's always glad to answer them in the comments.
No comments yet — be the first to share your thoughts!