Skip to content

How to Enforce BitLocker Encryption on Removable Drives

Richard
Written by
Richard
Feb 1, 2026 Updated Apr 2, 2026 4 min read
How to Enforce BitLocker Encryption on Removable Drives

You can enforce BitLocker encryption on removable drives in Windows 11 by changing some Group Policy settings.

This process makes sure all USB drives and portable storage devices connected to your computer automatically use BitLocker encryption. That way, unauthorized access to sensitive data is prevented.

Specifically, you’ll navigate to the “Removable Data Drives” section within the Group Policy Editor to enable the required encryption options.

This policy prevents users from saving unencrypted data to removable media, offering a robust layer of security for your files.

⚡ Quick Answer

Configure BitLocker encryption for removable drives via Group Policy. Navigate to Computer Configuration > Administrative Templates > Windows Components > BitLocker Drive Encryption > Removable Data Drives. Double-click “Enforce drive encryption type on removable data drives” and select your preferred encryption method.

What is BitLocker Encryption on Removable Drives?

BitLocker encryption for removable drives is a way to keep your files safe on things like USB sticks or external hard drives. It scrambles your data so only you can read it, adding a strong layer of security for your important information when you’re on the go.

  • Full Encryption: Encrypts the entire drive, even the empty space. This takes longer but is very secure.
  • Used Space Only Encryption: Encrypts only the parts of the drive where you have saved files. This is faster but encrypts less data.

By default, Windows will ask you which encryption type you want when you first set up BitLocker for a removable drive.

How to Enforce One Encryption Type Using Group Policy

You can make sure BitLocker always uses the same encryption type for removable drives by using the Group Policy Editor. This stops people from being asked which type to use each time, ensuring a consistent security setting across your computers.

  1. Press the Start button, type Edit group policy, and open the Local Group Policy Editor.
  2. Go to this folder path: Computer Configuration > Administrative Templates > Windows Components > BitLocker Drive Encryption > Removable Data Drives
  3. On the right side, double-click Enforce drive encryption type on removable data drives.
  4. Choose one of these options:
    • Not Configured (or Disabled): Windows will ask you which encryption type to use every time.
    • Enabled: You pick one encryption type below, and Windows will not ask users anymore.
  5. Select Full encryption to always encrypt the whole drive.
  6. Select Used space only encryption to encrypt only the used space.
  7. Disabled: Same as Not Configured; user chooses encryption type.
  8. Click OK to save.
  9. Restart your PC to apply the change.
Group Policy Editor - Enforce Encryption Type on Removable Drives

How to Enforce Encryption Type Using the Windows Registry

Forcing a specific BitLocker encryption type on removable drives can also be done using the Windows Registry Editor. This method is an alternative to Group Policy and lets you set the encryption standard directly in your system’s settings.

  1. ⚠️ Admin privileges required: Press Start, type regedit, and open the Registry Editor (run as administrator).
  2. Navigate to this key: HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\FVE
  3. Look for a value named RDVEncryptionType. If it doesn’t exist, create it:
    • Right-click in the right pane → NewDWORD (32-bit) Value
    • Name it RDVEncryptionType
  4. Double-click RDVEncryptionType and set its value data to:
    • 1 to enforce Full encryption
    • 2 to enforce Used space only encryption
  5. Click OK and close the Registry Editor.
  6. Restart your computer to apply the change.
Windows Registry Editor - Enforce BitLocker Encryption Type
Windows Registry Editor - Enforce BitLocker Encryption Type

If you want to go back to normal (where Windows asks which encryption type to use), delete the RDVEncryptionType value you created.

Summary

  • BitLocker protects your data on removable drives by encrypting it.
  • You can choose between full encryption or encrypting only used space.
  • You can force a specific encryption type so users won’t be asked every time by using Group Policy or the Registry Editor.
  • These steps help keep your data safer with the encryption method you prefer.

BitLocker encryption is a great way to protect your data on removable drives, offering choices like full or used-space-only encryption. You can also set a specific encryption type using Group Policy or the Registry Editor to keep things consistent and secure.

Can BitLocker be applied to removable drives?

BitLocker To Go is BitLocker Drive Encryption on removable data drives. This feature includes the encryption of: USB flash drives. SD cards.

How to enable BitLocker on a removable drive?

In the Windows search bar, type Bitlocker, and then click Manage BitLocker. Under Removable data drives – BitLocker To Go, locate and select the removable drive that you want to encrypt. Click Turn on BitLocker. BitLocker will initiate the drive and this might take several minutes.

What is removable data drive BitLocker to go?

BitLocker To Go —a feature of Windows 10— is a full-disk encryption protection technology for removable storage devices that are connected to one of the USB ports on your computer (referred as either USB drive or drive hereafter).

Was this guide helpful?

Tags: #Windows 11
Was this helpful?
Richard

About the Author

Richard

Tech Writer, IT Professional

Richard, a writer for Geek Rewind, is a tech enthusiast who loves breaking down complex IT topics into simple, easy-to-understand ideas. With years of hands-on experience in system administration and enterprise IT operations, he’s developed a knack for offering practical tips and solutions. Richard aims to make technology more accessible and actionable. He's deeply committed to the Geek Rewind community, always ready to answer questions and engage in discussions.

No comments yet — be the first to share your thoughts!

Leave a Comment

Your email address will not be published. Required fields are marked *

Exit mobile version