Why Is Device Encryption Missing in Windows 11?
The Device Encryption option missing in Windows 11 prevents you from easily protecting your files with built-in security.
Device Encryption is a Windows feature that scrambles your files, making them unreadable if your PC or laptop is lost or stolen. However, it requires specific hardware and software conditions to show up in settings.
This feature often doesn’t appear because your computer might not meet the minimum requirements. For example, it typically needs a Trusted Platform Module (TPM) version 2.0 chip, which many older machines lack.
It also relies on specific Windows editions, usually Pro or Enterprise versions, not Home editions. If your system doesn’t have these, the option remains hidden.
The Device Encryption option is missing in Windows 11 because your computer’s security chip, called a TPM, is either not present or turned off in your computer’s basic settings (BIOS/UEFI). To fix this, ensure your TPM is enabled in your BIOS/UEFI settings or check if your device meets other prerequisites in System Information.
How to Check if Your Device Supports Encryption
You can check if your Windows 11 device supports encryption by using the built-in System Information tool. This tool shows you if your computer’s hardware and software are ready for Device Encryption. It’s a straightforward way to see why the option might be missing from your settings.
- Open the Start Menu : Click the Windows icon in the bottom-left corner or press the ⊞ Win on your keyboard.
- Search for “System Information”: Type
System Informationinto the search bar. You will see it appear in the search results.
- Run as Administrator: This is important. Right-click on “System Information” in the search results. Select “Run as administrator.” This gives the program permission to check all system details.

Running System Information as administrator is important for checking all system details. To do this, right-click “System Information” in search results and select “Run as administrator.” This action gives the program permission to access deeper computer functions, which is often needed to see or change system settings.
- Look for Encryption Support: Once System Information opens, you'll see a lot of data. Keep 'System Summary' selected on the left. In the main window to the right, locate a specific line. Scrolling down or using the search function works if available. Look for either
Automatic Device Encryption SupportorDevice Encryption Support.
- Understand the Status: Next to the line you found, there will be a value. This value explains why Device Encryption might be missing.
What the Status Messages Mean
The status message you found in System Information is the key to solving this mystery. Each message explains a different reason why Device Encryption isn't available.
"Meets prerequisites"
Seeing the "Meets prerequisites" message means your Windows 11 device has the necessary hardware and software for Device Encryption. If you still can't find the option, make sure you're logged in as an administrator and using a Microsoft account or a work/school account, not a local one.
Action: Make sure you are signed into Windows with an administrator account. If you are using a local account, consider switching to a Microsoft account. Device Encryption works best with these. You can usually find this setting under Settings > Accounts > Your info.
"TPM is not usable"
The "TPM is not usable" message means your computer's security chip, called a Trusted Platform Module (TPM), is either missing or turned off. The TPM is crucial for Device Encryption because it securely stores important keys. If it's not found or enabled in your BIOS/UEFI settings, encryption won't work.
Your PC needs a Trusted Platform Module (TPM) for device encryption. You can check for the TPM in Device Manager under "Security devices." If the TPM is present but not turned on, restart your computer and enter its BIOS or UEFI settings. This usually requires pressing a key like F2, F10, F12, or DEL right after powering on your PC. Find the option for "TPM," "Security Chip," or "PTT" (for Intel processors) and turn it on.
"WinRE is not configured"
If you see "WinRE is not configured," it means the Windows Recovery Environment isn't set up correctly for Device Encryption. WinRE is a set of tools that helps Windows fix itself if it won't start. Device Encryption needs WinRE to perform certain security tasks, especially during startup and recovery.
Action: To fix this, make sure your Windows installation is up-to-date and that the recovery partition is working. Sometimes, using the System File Checker tool can help. Open Command Prompt as an administrator (search for cmd, right-click, and select "Run as administrator"). Then, type sfc /scannow and press Enter. This checks for and tries to fix any damaged system files, which might include parts of WinRE.
"PCR7 binding is not supported"
The "PCR7 binding is not supported" message means your computer's startup process isn't being securely measured in the way Device Encryption requires. This often relates to how Secure Boot is set up and whether certain devices are connected during startup. It's a security check that ensures your system boots correctly and safely.
Why it matters: For Device Encryption to be secure, your computer must start up in a specific, protected way. This requires Secure Boot to be turned on and for certain devices not to be connected when Windows starts.
Action:
- Check Secure Boot: Like the TPM, Secure Boot is usually turned on or off in your computer's BIOS/UEFI settings. You'll need to restart your PC and go into those settings. Look for an option called "Secure Boot" and make sure it's enabled. If Secure Boot is off, enabling it might resolve the issue.
- Disconnect Peripherals: Try unplugging any external devices you don't absolutely need before your computer starts up. This includes things like special network adapters, docking stations, external graphics cards, or even some USB devices. Once Windows is running and Device Encryption is turned on, you can usually plug them back in.
References:
https://support.microsoft.com/en-US/Windows/Security/encryption/device-encryption-in-windows
Summary
If the Device Encryption option is missing in Windows 11, it's usually because of your system's hardware or software setup. You can find the specific reason using the 'System Information' tool and checking the 'Encryption Support' status. Common causes include a disabled TPM, a missing Windows Recovery Environment (WinRE), or incorrect Secure Boot settings.
Does 🪟 Windows 11 have built-in encryption?
Um you go to privacy. And security. And then you go to device encryption. And if you've signed in with an online account of any kind so this would be work or school or Microsoft.
Was this guide helpful?
About the Author
Richard
Tech Writer, IT Professional
Richard, a writer for Geek Rewind, is a tech enthusiast who loves breaking down complex IT topics into simple, easy-to-understand ideas. With years of hands-on experience in system administration and enterprise IT operations, he’s developed a knack for offering practical tips and solutions. Richard aims to make technology more accessible and actionable. He's deeply committed to the Geek Rewind community, always ready to answer questions and engage in discussions.
No comments yet — be the first to share your thoughts!