How to Encrypt USB Drives in Windows 11 with BitLocker
BitLocker for removable data drives in Windows 11 encrypts your files, making them unreadable to anyone without your password or recovery key.
BitLocker To Go, a feature for portable drives like USB flash drives and SD cards, scrambles data on these drives. This process creates a strong lock protecting your sensitive information if the drive is lost or stolen.
When you save a document to a BitLocker-protected USB drive, the document gets locked automatically. If you move that document to another computer, the document unlocks so you can access it, but the original USB drive remains secured.
Remember, BitLocker encryption is available on Windows 11 Pro, Enterprise, and Education editions, not on Windows 11 Home.
Enable BitLocker To Go via Settings System Storage Advanced storage settings Disks & volumes. Expand your USB drive, click Properties, then Turn on BitLocker. Enter and confirm a password, save your recovery key, and follow the prompts to encrypt the drive.
Step 1Get Your Drive Ready
Before you encrypt your USB drive or external hard drive with BitLocker in Windows 11, plug the removable drive into your computer. Copying important files from the removable drive to another safe place, like your computer's hard drive, is also smart. This backup process ensures your data is safe in case anything unexpected happens during the encryption process.
Step 2Find and Turn On BitLocker
To turn on BitLocker for your USB drive in Windows 11, open File Explorer by pressing ⊞ Win+E or clicking the folder icon. Then, go to ‘This PC’ in the left sidebar and find the drive you want to protect. Right-click on that drive, and then select ‘Turn on BitLocker’ from the menu that pops up.
- Open File Explorer. You can press the Windows key + E on your keyboard, or click the folder icon on your taskbar.
- In File Explorer, click on "This PC" in the left sidebar. This shows all drives connected to your computer.
- Find the USB drive or external hard drive you want to encrypt.
- Right-click on the drive.
- A menu will appear. You might need to click "Show more options" if you don't see BitLocker right away. This is common in newer Windows 11 setups.
- Click "Turn on BitLocker."

Step 3Choose How to Unlock Your Drive
After you choose to turn on BitLocker, you'll pick how you want to unlock your drive. The most common way is using a password. You'll create a password that you'll need to type in every time you connect the drive to a computer to get to your files. Make sure to choose a strong password that's at least 8 characters long.
- Use a password: This is the most common way. You will create a password that you need to enter every time you plug this drive into a computer and want to access your files. Make sure it's a strong password – at least 8 characters long, with a mix of letters, numbers, and symbols.
- Use a smart card: If your workplace uses smart cards for security, you might see this option. You will need to insert your smart card and enter its PIN to unlock the drive.

For most personal users, using a password is the best choice. Type your password into the box and click "Next."
If you forget your BitLocker password, you cannot recover your files. Write down your BitLocker password and store it in a very safe place, or use one of the backup methods described in the next step.
Step 4Back Up Your Recovery Key – This is Crucial!
The BitLocker recovery key is a long number sequence that helps you unlock your drive if you forget your password or encounter a problem. Windows 11 offers options to save this key, such as to your Microsoft account or by printing it. Saving the BitLocker recovery key in at least one safe place is crucial.
You will see options for backing up this key. Choose at least one, and ideally more than one, for maximum safety:
- Save to your Microsoft account: If you are signed into Windows 11 with a Microsoft account, this is a very easy option. Your recovery key will be uploaded securely to your Microsoft account online. You can access it by going to account.microsoft.com/devices/recoverykey from any web browser.
- Save to a file: This lets you save the recovery key as a text file (.txt) on your computer's hard drive or another storage device. Do NOT save it to the drive you are currently encrypting. You will be asked to choose a location for this file. Save it somewhere safe and easy to remember.
- Print the recovery key: This option sends the recovery key to your printer. You will get a paper copy that you should store in a very secure physical location, like a safe or a locked filing cabinet.
After choosing how to back up your recovery key, click "Next."
Step 5Choose How Much to Encrypt
When encrypting your drive with BitLocker in Windows 11, you can choose how much of it to protect. You can select 'Encrypt used disk space only,' which is faster and only covers the parts of the drive with data, or 'Encrypt entire drive,' which protects every single part of the drive, even empty space.
- Encrypt used disk space only: This is faster and only encrypts the space on the drive that currently has data. It's a good option if the drive is new or you have already deleted most of the old data.
- Encrypt entire drive: This encrypts every bit of space on the drive, whether it's used or not. This is the more secure option, especially if the drive has held sensitive data in the past that you have deleted. It takes longer, but it is recommended for the best protection.

For the best security, select "Encrypt entire drive" and click "Next."
Step 6Select the Encryption Mode
You'll need to select an encryption mode for your BitLocker drive. The 'New encryption mode (XTS-AES)' is the modern and stronger option, best for newer Windows computers. If you need to use the drive with older versions of Windows, choose 'Compatible mode (AES-CBC)' for better compatibility.
- New encryption mode (XTS-AES): This is the modern, stronger encryption method. It is best if you plan to use this drive only with Windows 10 or Windows 11 computers.
- Compatible mode (AES-CBC): This is an older encryption method that ensures your drive can still be read on older versions of Windows (like Windows 7 or 8) if needed. If you are only using the drive with your current Windows 11 PC, the "New encryption mode" is better.
Choose the mode that best fits how you will use the drive and click "Next."

Note: You might not see this option if you've previously adjusted advanced settings (most users don't). In that case, BitLocker will automatically select the encryption method.
Step 7Start the Encryption Process
On the final confirmation screen, review all your BitLocker settings for the USB drive. When you're sure everything is correct, click the 'Start encrypting' button. The encryption process will then begin, and you'll see a progress bar showing how much time is left. You can still use your computer while this happens.
The BitLocker encryption process for your removable data drive will begin. A progress bar will display the encryption's completion status, showing how far along it is. This process can take between a few minutes to several hours, depending on your drive's size and the amount of data stored on it.
Tip: You can continue using your computer for other tasks while BitLocker encrypts your drive in the background. However, it is best not to remove the drive or shut down your PC until the process is complete.
Step 8Encryption Complete!
After BitLocker finishes encrypting your removable drive, a confirmation message will appear in Windows 11. You can then click 'Close' to dismiss the message. Your USB drive or external hard drive is now protected by BitLocker. The next time you connect the drive, Windows 11 will ask for the password you set and show a padlock icon next to the drive in File Explorer.
Your USB drive or external hard drive is now encrypted with BitLocker. The next time you connect the encrypted drive to any computer, you will enter the password you created to access your files.
You will also see a small padlock icon next to the drive in File Explorer, showing that it is protected by BitLocker.
Summary
BitLocker is a great tool in Windows 11 for protecting your data on USB drives and external hard drives. By following the steps, you can encrypt your drive using a password and make sure you have a recovery key saved safely, like in your Microsoft account. This helps keep your files secure when you use removable drives.
[…] can protect external, fixed, and operating system drives using BitLocker. When you enable BitLocker to protect the […]
[…] can protect external, fixed, and operating system drives using BitLocker. When you enable BitLocker to protect the […]
[…] can protect external, fixed, and operating system drives using BitLocker. When you enable BitLocker to protect the […]
[…] can protect external, fixed, and operating system drives using BitLocker. When you enable BitLocker to protect the […]
[…] can protect external, fixed, and operating system drives using BitLocker. When you enable BitLocker to protect the […]
[…] can protect external, fixed, and operating system drives using BitLocker. When you enable BitLocker to protect the […]
[…] can protect external, fixed, and operating system drives using BitLocker. When you enable BitLocker to protect the OS […]
[…] can protect external, fixed, and operating system drives using BitLocker. When you enable BitLocker to protect the […]
[…] can protect external, fixed, and operating system drives using BitLocker. When you enable BitLocker to protect the […]
[…] External drives like USB sticks […]
[…] External drives like USB sticks […]