Skip to content
Follow
Windows

How to Suspend and Resume BitLocker in Windows 11

Richard
Written by
Richard
May 13, 2024 Updated Oct 5, 2026 6 min read
BitLocker drive encrytion featured image
BitLocker drive encrytion featured image

BitLocker is the Windows tool that encrypts your drive so nobody can read your files without the right key. That protection can get in the way when you update the system BIOS or swap hardware, because BitLocker may see the change and demand your recovery key at the next boot. Suspending BitLocker in Windows 11 pauses protection for one restart or for a set number of restarts. You can finish your maintenance without waiting hours to decrypt the whole drive and encrypt it again afterwards.

Advertisement

You can pause protection from Control Panel or from Windows Terminal, and you can resume it from Control Panel , File Explorer or Windows Terminal. On the operating system drive, Windows turns protection back on automatically after the next reboot. You can also resume it by hand as soon as your work is done.

Edition note: the BitLocker management pages described here are part of Windows 11 Pro, Enterprise and Education. Windows 11 Home usually has only a simpler Device encryption switch, so the Suspend protection option may be missing there.

⚡ Quick Answer

Navigate to Control Panel , then BitLocker Drive Encryption, and click “Suspend protection” or “Resume protection” for your desired drive. Alternatively, use PowerShell commands like manage-bde -protectors -disable C: to suspend or manage-bde -protectors -enable C: to resume.

Advertisement

Why Suspend BitLocker?

Hardware swaps, firmware (BIOS/UEFI) updates and operating system upgrades are the usual reasons to pause disk protection. Suspend BitLocker before you start, finish the work, then confirm protection is back on. Do not leave the drive unprotected longer than you have to.

What Happens When You Suspend BitLocker?

While BitLocker is suspended, the volume is not shielded. Windows keeps the data encrypted on disk but stores the key in the clear, so anyone with access to the drive can read it. How protection comes back depends on the type of drive:

  • Operating system drive: protection turns back on automatically after specific system triggers, usually the next restart.
  • Secondary (data) drives: they stay suspended until you resume them manually, even across reboots.

How to Suspend or Resume BitLocker in Windows

Method 1Using Control Panel

  1. Open open the Control Panel and go to System and Security BitLocker Drive Encryption You should see a list of your drives and their BitLocker status.
  2. Find the drive you want to suspend under Operating system drive. A drive that is protected shows BitLocker on. If you see BitLocker off instead, there is nothing to suspend.
  3. Click the Suspend protection link next to that drive. If the link is missing, check that you are signed in with an administrator account and that your edition of Windows 11 supports BitLocker management.
BitLocker Drive Encryption Control Panel suspend protection link
BitLocker Drive Encryption Control Panel suspend protection link
  1. Read the pop-up window that appears, then click Yes to confirm. The drive status changes to suspended, and the link next to the drive now reads Resume protection.

To suspend BitLocker from Control Panel , open the BitLocker Drive Encryption settings and click the Suspend protection link next to your drive. This turns off protection temporarily, so you can change hardware or install updates without triggering recovery screens. Protection turns back on automatically when you restart your computer. If you are not finished after one restart, suspend it again or use the PowerShell method below to set a higher restart count.

Advertisement

Secondary drives stay unprotected even after you restart the computer. To secure the data again, you have to turn protection back on yourself.

How to Resume BitLocker Using Control Panel

  1. Follow the same path as before: Control Panel System and Security BitLocker Drive Encryption
  2. Click Resume protection for the drive you want to protect again. The link goes away and the drive shows BitLocker on once protection is active.
Resume BitLocker suspension
Resume BitLocker suspension

Method 2Using File Explorer

  1. Open File Explorer and click This PC so your drives are listed.
  2. Right-click the drive you want to resume.
  3. Select Show more options. This opens the classic context menu, which is where the BitLocker entries live in Windows 11. Holding Shift while you right-click opens the same menu directly.
  4. Click Resume BitLocker protection in the menu. If the entry is not there, the drive is probably already protected, or BitLocker is not enabled on it.
Resume BitLocker protection from context menu
Resume BitLocker protection from context menu

How to Suspend or Resume BitLocker Using PowerShell

Windows PowerShell gives you more control over BitLocker, including how many restarts the suspension lasts. You need administrator rights for these commands to work. If you see an access denied error, the window was not opened as administrator.

  1. Open Windows Terminal as administrator and select the PowerShell tab. Right-clicking the Start button and choosing Terminal (Admin) is the quickest way. Click Yes if User Account Control asks for permission.

Suspend BitLocker for One Drive

Run the command below in the administrator window. Before you press Enter, replace the placeholder shown here:

[drive_letter]

Use the letter of the volume you want to suspend, followed by a colon. If you are not sure which letter that is, check This PC in File Explorer first.

Advertisement
💻Code
manage-bde -protectors -disable <drive letter>:

Example:

💻Code
manage-bde -protectors -disable C:

Resume BitLocker for One Drive

Run this command in the same administrator window and press Enter. If PowerShell returns to the prompt or prints the volume details without an error, the command worked.

💻Code
manage-bde -protectors -enable C:

Suspend BitLocker for All Drives

Run this command next and press Enter. Read any error message in red before moving on, as it usually names the problem, such as a wrong drive letter or a missing administrator token.

⬛PowerShell
Get-BitLockerVolume | Suspend-BitLocker

Resume BitLocker for All Drives

Run this command and press Enter. You can check the result afterwards in Control Panel, where the drive status should match what you just did.

Advertisement
⬛PowerShell
Get-BitLockerVolume | Resume-BitLocker

Suspend BitLocker for Your Main Drive with Restart Limits

You can keep BitLocker suspended on your main drive for more than one restart by adding a counter to the PowerShell command. Open PowerShell as an administrator and type Suspend-BitLocker -MountPoint "C:" -RebootCount followed by a number between 0 and 15. Protection stays paused through that many reboots. This helps when an update needs several restarts to finish.

💻Code
Suspend-BitLocker -MountPoint "C:" -RebootCount <restarts #>

Replace <restarts #> with a value from 0 to 15. This number sets how many reboots happen before BitLocker turns itself back on. Keep it as low as the job allows.

Example:

💻Code
Suspend-BitLocker -MountPoint "C:" -RebootCount 0

Setting the count to 0 keeps the drive unprotected until you resume it manually. Only use 0 if you will remember to turn protection back on yourself, because Windows will not do it for you.

Advertisement

Summary

BitLocker Drive Encryption is the built-in Windows tool that scrambles your files so others cannot read them. Sometimes you need to turn it off temporarily during hardware upgrades or system updates. Suspending BitLocker leaves your data unprotected until you restart your computer or turn protection back on manually. Doing this first helps stop Windows from locking you out of your own device with a recovery key prompt.

Suspending BitLocker helps during major hardware swaps or software migrations. Installing memory modules or upgrading to version 23H2 are common cases that call for a temporary suspension. Firmware and BIOS updates are another good reason, since they can change the measurements BitLocker uses to decide whether the system is trusted.

What happens when suspended? The volume stays unprotected until protection resumes. Boot drives usually turn protection back on automatically, while secondary drives need you to resume them by hand.

You can manage BitLocker states through Control Panel, File Explorer or PowerShell. Administrators often prefer PowerShell because it lets you set the restart count and is easy to script across several machines.

Important reminder: Re-enable BitLocker protection as soon as you finish the maintenance work. Then check the drive status once more to confirm it shows protection is on.

Was this guide helpful?

Tags: #Windows 11
Was this helpful?
Richard

About the Author

Richard

Tech Writer, IT Professional

Richard is a writer at Geek Rewind who turns complex IT tasks into clear, step-by-step guides. He draws on years of hands-on experience in system administration and enterprise IT operations, focusing on Windows, Linux and WordPress: the problems people actually run into, and the fixes that work. His server and WordPress guides come from systems he runs himself. Richard builds and maintains the platform behind Geek Rewind, from its Ubuntu servers and Nginx configuration to its custom WordPress plugins. Many new tutorials start with readers' questions, and he's always glad to answer them in the comments.

Advertisement

📚 Related Tutorials

How to Enable or Disable BitLocker to Unlock OS Drive with PIN or USB at Startup in Windows 11
Windows How to Enable or Disable BitLocker to Unlock OS Drive with PIN or USB at Startup in Windows 11
How to Open Windows Terminal as Admin Automatically
Windows How to Open Windows Terminal as Admin Automatically
How to Access Control Panel in Windows 11
Windows How to Access Control Panel in Windows 11
How to Turn On BitLocker to Protect a Data Drive in Windows 11
Windows How to Turn On BitLocker to Protect a Data Drive in Windows 11

No comments yet — be the first to share your thoughts!

Leave a Comment

Your email address will not be published. Required fields are marked *