Skip to content
Follow
Windows 🟡 Intermediate

How to Encrypt USB Drives in Windows 11 with BitLocker

Richard
Written by
Richard
Jul 22, 2021 Updated Aug 1, 2026 8 min read
How to Encrypt USB Drives in Windows 11 with BitLocker
How to Encrypt USB Drives in Windows 11 with BitLocker

BitLocker for removable data drives in Windows 11 encrypts your files, making them unreadable to anyone without your password or recovery key.

BitLocker To Go, a feature for portable drives like USB flash drives and SD cards, scrambles data on these drives. This process creates a strong lock protecting your sensitive information if the drive is lost or stolen.

When you save a document to a BitLocker-protected USB drive, the document gets locked automatically. If you move that document to another computer, the document unlocks so you can access it, but the original USB drive remains secured.

Remember, BitLocker encryption is available on Windows 11 Pro, Enterprise, and Education editions, not on Windows 11 Home.

⚡ Quick Answer

Enable BitLocker To Go via Settings System Storage Advanced storage settings Disks & volumes. Expand your USB drive, click Properties, then Turn on BitLocker. Enter and confirm a password, save your recovery key, and follow the prompts to encrypt the drive.

Step 1Get Your Drive Ready

Before you encrypt your USB drive or external hard drive with BitLocker in Windows 11, plug the removable drive into your computer. Copying important files from the removable drive to another safe place, like your computer's hard drive, is also smart. This backup process ensures your data is safe in case anything unexpected happens during the encryption process.

Step 2Find and Turn On BitLocker

To turn on BitLocker for your USB drive in Windows 11, open File Explorer by pressing ⊞ Win+E or clicking the folder icon. Then, go to ‘This PC’ in the left sidebar and find the drive you want to protect. Right-click on that drive, and then select ‘Turn on BitLocker’ from the menu that pops up.

  • Open File Explorer. You can press the Windows key + E on your keyboard, or click the folder icon on your taskbar.
  • In File Explorer, click on "This PC" in the left sidebar. This shows all drives connected to your computer.
  • Find the USB drive or external hard drive you want to encrypt.
  • Right-click on the drive.
  • A menu will appear. You might need to click "Show more options" if you don't see BitLocker right away. This is common in newer Windows 11 setups.
  • Click "Turn on BitLocker."
Turn on BitLocker for removable data drive in Windows 11
Turn on BitLocker for removable data drive in Windows 11
💡Tip
If you don't see "Turn on BitLocker" when you right-click, your Windows 11 version might not support it, or the drive might be formatted in a way BitLocker cannot use. BitLocker works with most common formats like NTFS, FAT16, FAT32, and exFAT.

Step 3Choose How to Unlock Your Drive

After you choose to turn on BitLocker, you'll pick how you want to unlock your drive. The most common way is using a password. You'll create a password that you'll need to type in every time you connect the drive to a computer to get to your files. Make sure to choose a strong password that's at least 8 characters long.

  • Use a password: This is the most common way. You will create a password that you need to enter every time you plug this drive into a computer and want to access your files. Make sure it's a strong password – at least 8 characters long, with a mix of letters, numbers, and symbols.
  • Use a smart card: If your workplace uses smart cards for security, you might see this option. You will need to insert your smart card and enter its PIN to unlock the drive.
BitLocker unlock style for removable data drive encryption
BitLocker unlock style for removable data drive encryption

For most personal users, using a password is the best choice. Type your password into the box and click "Next."

If you forget your BitLocker password, you cannot recover your files. Write down your BitLocker password and store it in a very safe place, or use one of the backup methods described in the next step.

Step 4Back Up Your Recovery Key – This is Crucial!

The BitLocker recovery key is a long number sequence that helps you unlock your drive if you forget your password or encounter a problem. Windows 11 offers options to save this key, such as to your Microsoft account or by printing it. Saving the BitLocker recovery key in at least one safe place is crucial.

You will see options for backing up this key. Choose at least one, and ideally more than one, for maximum safety:

  • Save to your Microsoft account: If you are signed into Windows 11 with a Microsoft account, this is a very easy option. Your recovery key will be uploaded securely to your Microsoft account online. You can access it by going to account.microsoft.com/devices/recoverykey from any web browser.
  • Save to a file: This lets you save the recovery key as a text file (.txt) on your computer's hard drive or another storage device. Do NOT save it to the drive you are currently encrypting. You will be asked to choose a location for this file. Save it somewhere safe and easy to remember.
  • Print the recovery key: This option sends the recovery key to your printer. You will get a paper copy that you should store in a very secure physical location, like a safe or a locked filing cabinet.

After choosing how to back up your recovery key, click "Next."

💡Tip
Seriously, do not skip this step! Losing your recovery key means losing access to your encrypted data forever. Saving it to your Microsoft account is often the safest option for most people.

Step 5Choose How Much to Encrypt

When encrypting your drive with BitLocker in Windows 11, you can choose how much of it to protect. You can select 'Encrypt used disk space only,' which is faster and only covers the parts of the drive with data, or 'Encrypt entire drive,' which protects every single part of the drive, even empty space.

  • Encrypt used disk space only: This is faster and only encrypts the space on the drive that currently has data. It's a good option if the drive is new or you have already deleted most of the old data.
  • Encrypt entire drive: This encrypts every bit of space on the drive, whether it's used or not. This is the more secure option, especially if the drive has held sensitive data in the past that you have deleted. It takes longer, but it is recommended for the best protection.
Choose how much of your drive to encrypt with BitLocker
Choose how much of your drive to encrypt with BitLocker

For the best security, select "Encrypt entire drive" and click "Next."

Step 6Select the Encryption Mode

You'll need to select an encryption mode for your BitLocker drive. The 'New encryption mode (XTS-AES)' is the modern and stronger option, best for newer Windows computers. If you need to use the drive with older versions of Windows, choose 'Compatible mode (AES-CBC)' for better compatibility.

  • New encryption mode (XTS-AES): This is the modern, stronger encryption method. It is best if you plan to use this drive only with Windows 10 or Windows 11 computers.
  • Compatible mode (AES-CBC): This is an older encryption method that ensures your drive can still be read on older versions of Windows (like Windows 7 or 8) if needed. If you are only using the drive with your current Windows 11 PC, the "New encryption mode" is better.

Choose the mode that best fits how you will use the drive and click "Next."

Choose BitLocker encryption mode for removable data drive
Choose BitLocker encryption mode for removable data drive

Note: You might not see this option if you've previously adjusted advanced settings (most users don't). In that case, BitLocker will automatically select the encryption method.

Step 7Start the Encryption Process

On the final confirmation screen, review all your BitLocker settings for the USB drive. When you're sure everything is correct, click the 'Start encrypting' button. The encryption process will then begin, and you'll see a progress bar showing how much time is left. You can still use your computer while this happens.

The BitLocker encryption process for your removable data drive will begin. A progress bar will display the encryption's completion status, showing how far along it is. This process can take between a few minutes to several hours, depending on your drive's size and the amount of data stored on it.

Tip: You can continue using your computer for other tasks while BitLocker encrypts your drive in the background. However, it is best not to remove the drive or shut down your PC until the process is complete.

Step 8Encryption Complete!

After BitLocker finishes encrypting your removable drive, a confirmation message will appear in Windows 11. You can then click 'Close' to dismiss the message. Your USB drive or external hard drive is now protected by BitLocker. The next time you connect the drive, Windows 11 will ask for the password you set and show a padlock icon next to the drive in File Explorer.

Your USB drive or external hard drive is now encrypted with BitLocker. The next time you connect the encrypted drive to any computer, you will enter the password you created to access your files.

You will also see a small padlock icon next to the drive in File Explorer, showing that it is protected by BitLocker.

Summary

BitLocker is a great tool in Windows 11 for protecting your data on USB drives and external hard drives. By following the steps, you can encrypt your drive using a password and make sure you have a recovery key saved safely, like in your Microsoft account. This helps keep your files secure when you use removable drives.

Does 🪟 Windows 11 automatically turn on BitLocker?

You overbend the screen or you do simple things like add memory add a hard drive. While this was a minor thing in the past.

Can BitLocker encrypt USB?

Insert the USB drive you want to encrypt - this can be a new drive, or one that already has data stored on it. Open File Explorer, right-click on the USB drive then select Turn on BitLocker… from the pop-up menu. The BitLocker wizard launches and BitLocker prepares the USB drive for encryption.

How do I enable BitLocker Drive Encryption in 🪟 Windows 11?

To enable BitLocker in Windows 11, click on the Windows “Start” button and type “Manage BitLocker” into the search bar. Open the result and click “Turn on BitLocker”. Select the method to save the recovery key and click “Next”. Select one of the volume encryption options.

Was this guide helpful?

📬 Get new Windows tips in your inbox
One email when we publish something worth your time. No spam, unsubscribe anytime.
Tags: #Windows 11
Was this helpful?
Richard

About the Author

Richard

Tech Writer, IT Professional

Richard, a writer for Geek Rewind, is a tech enthusiast who loves breaking down complex IT topics into simple, easy-to-understand ideas. With years of hands-on experience in system administration and enterprise IT operations, he’s developed a knack for offering practical tips and solutions. Richard aims to make technology more accessible and actionable. He's deeply committed to the Geek Rewind community, always ready to answer questions and engage in discussions.

2774 articles → Twitter

📚 Related Tutorials

How to Enforce BitLocker Encryption Types on Windows 11 Drives
Windows How to Enforce BitLocker Encryption Types on Windows 11 Drives
How to Access Settings in Windows 11
Windows How to Access Settings in Windows 11
How to turn On or Off Dynamic Lock to Automatically Lock Windows 11
Windows How to turn On or Off Dynamic Lock to Automatically Lock Windows 11
How to Check Your Computer Specifications in Windows 11
Windows How to Check Your Computer Specifications in Windows 11

11 Comments

Leave a Comment

Your email address will not be published. Required fields are marked *