Skip to content
Follow
Windows

How to Enable BitLocker with PIN and USB Key in Windows 11

Richard
Written by
Richard
Dec 3, 2022 Updated Sep 16, 2026 2 min read
How to Enable or Disable Closing Warnings in Windows Terminal
How to Enable or Disable Closing Warnings in Windows Terminal

BitLocker device encryption locks your Windows 11 hard drive so nobody can read your files if your PC gets lost or stolen. You can make this security even stronger by setting up a startup PIN and a USB key, which forces you to plug in a specific flash drive and type a secret code every time you turn on your computer.

Advertisement

This two-step startup check gives you much better protection than a standard Windows password or a basic hardware chip alone. Windows 11 Pro, Enterprise, and Education editions support this setup, while Windows 11 Home users need to upgrade first.

⚡ Quick Answer

Enable BitLocker with a PIN and USB key by navigating to Control Panel System and Security BitLocker Drive Encryption. Click ‘Change how drive is unlocked at startup’, select ‘Enter a PIN (recommended)’, and then ‘Insert a USB flash drive’. Ensure your TPM is enabled or configure Group Policy if needed.

Advertisement

Prerequisites and TPM Requirements

Before proceeding, verify that the motherboard has a TPM 2.0 chip enabled in the UEFI firmware (the foundational system firmware). Devices lacking a TPM require a specific Group Policy tweak to permit BitLocker operation without one.

Common Errors: The device cannot use a Trusted Platform Module

Encountering the “device cannot use a Trusted Platform Module” error indicates a missing or disabled TPM in the BIOS. Bypassing this roadblock involves enabling the “Require additional authentication at startup” policy inside the Group Policy Editor.

Configuring Group Policy for BitLocker

Configuring Group Policy for BitLocker lets you set up extra startup security like a PIN or a USB key on Windows 11. You need to open the Local Group Policy Editor using the Run command to find and change the startup controls before you can turn on these features.

1. Press Win+R, type gpedit.msc, and press Enter.
2. Navigate to: Computer Configuration\Administrative Templates\Windows Components\BitLocker Drive Encryption\Operating System Drives.
3. Double-click Require additional authentication at startup.
4. Select Enabled and ensure ‘Allow BitLocker without a compatible TPM’ is checked if needed.
5. Click Apply and OK.

Advertisement

Enable a PIN to Unlock BitLocker

To enable a BitLocker PIN on Windows 11, you need to use the Control Panel to change how your drive unlocks at startup. This adds an extra layer of security by making you type a numeric sequence between 6 and 20 digits long every time you turn on your computer.

Open the Control Panel and go to Control Panel\System and Security\BitLocker Drive Encryption. Click 'Change how drive is unlocked at startup'.

windows 11 change how dirve is unlocked at startup
windows 11 change how dirve is unlocked at startup

Select 'Enter a PIN (recommended)'.

windows 11 choose how to unlock your drive at startup enter pin
windows 11 choose how to unlock your drive at startup enter pin

Input a numeric sequence between 6 and 20 digits long. Confirm the entry and click 'Set PIN'.

Advertisement
windows 11 enter a pin to unlock bitlocker at startup
windows 11 enter a pin to unlock bitlocker at startup

Unlock with a USB Drive at Startup

📝NoteThese steps require admin privileges.

Return to the BitLocker menu and select 'Insert a USB flash drive'.

windows 11 change how dirve is unlocked at startup
windows 11 change how dirve is unlocked at startup

Choose the target USB drive from the dropdown list and click 'Save'.

choose how to unlock your drive at startup insert usb drive windows 11
choose how to unlock your drive at startup insert usb drive windows 11

Keep the flash drive connected during the subsequent reboot to validate the configuration.

Advertisement
windows 11 save your startup key on usb bitlocker
windows 11 save your startup key on usb bitlocker

Command Line Configuration

Power users can manage these parameters through PowerShell or Command Prompt. Launching these command-line tools as an Administrator grants full control over drive encryption features.

💻Code
manage-bde -protectors -add C: -TPMAndPIN

Summary

With the PIN and USB key configured, your Windows 11 machine now demands physical and numerical authentication before booting.

Was this guide helpful?

Tags: #Windows 11
Was this helpful?
Richard

About the Author

Richard

Tech Writer, IT Professional

Richard is a writer at Geek Rewind who turns complex IT tasks into clear, step-by-step guides. He draws on years of hands-on experience in system administration and enterprise IT operations, focusing on Windows, Linux and WordPress: the problems people actually run into, and the fixes that work. His server and WordPress guides come from systems he runs himself. Richard builds and maintains the platform behind Geek Rewind, from its Ubuntu servers and Nginx configuration to its custom WordPress plugins. Many new tutorials start with readers' questions, and he's always glad to answer them in the comments.

Advertisement

📚 Related Tutorials

How to Manage Windows Hello Facial Recognition in Windows 11
Windows How to Manage Windows Hello Facial Recognition in Windows 11
How to Enable or Disable Windows Hello Fingerprint
Windows How to Enable or Disable Windows Hello Fingerprint
How to Turn On BitLocker for Your Windows 11 Operating System Drive
Windows How to Turn On BitLocker for Your Windows 11 Operating System Drive
How to Enable or Disable BitLocker to Unlock OS Drive with PIN or USB at Startup in Windows 11
Windows How to Enable or Disable BitLocker to Unlock OS Drive with PIN or USB at Startup in Windows 11

0 Comments

Leave a Comment

Your email address will not be published. Required fields are marked *