Why Is Device Encryption Missing in Windows 11?
Device encryption in Windows 11 scrambles the files on your hard drive so nobody can read them if your PC gets stolen. When this option goes missing from your settings menu, it usually means your computer lacks a Trusted Platform Module (TPM) version 2.0 chip or runs Windows 11 Home instead of the Pro edition.
You need modern hardware that supports modern standby and secure boot to make the encryption settings appear. Check your system info to see if your PC meets these base requirements before you try to turn it on.
The Device Encryption option is missing in Windows 11 because your computer’s security chip, called a TPM, is either not present or turned off in your computer’s basic settings (BIOS/UEFI). To fix this, ensure your TPM is enabled in your BIOS/UEFI settings or check if your device meets other prerequisites in System Information.
How to Check if Your Device Supports Encryption
You can check if your device supports encryption in Windows 11 by opening the System Information app and scrolling to the Device Encryption Support row. If the status says meets prerequisites, your hardware is ready. If it shows reasons for failure, you will see the exact cause why device encryption missing is happening on your computer.
- Open the Start Menu : Click the Windows icon in the bottom-left corner or press the Win on your keyboard.
- Search for “System Information”: Type
System Informationinto the search bar. You will see it appear in the search results.
- Run as Administrator: This is important. Right-click on “System Information” in the search results. Select “Run as administrator.” This gives the program permission to check all system details.

Running System Information as administrator is important for checking all system details. To do this, right-click “System Information” in search results and select “Run as administrator.” This action gives the program permission to access deeper computer functions, which is often needed to see or change system settings.
- Look for Encryption Support: Once System Information opens, you’ll see a lot of data. Keep ‘System Summary’ selected on the left. In the main window to the right, locate a specific line. Scrolling down or using the search function works if available. Look for either
Automatic Device Encryption SupportorDevice Encryption Support.
- Understand the Status: Next to the line you found, there will be a value. This value explains why Device Encryption might be missing.
What the Status Messages Mean
The status message you found in System Information is the key to solving this mystery. Each message explains a different reason why Device Encryption isn’t available.
“Meets prerequisites”
Seeing the meets prerequisites message means your hardware is fully compatible, but device encryption missing problems usually happen because you are signed in with a local user account instead of a Microsoft account. Switch your Windows 11 login to a Microsoft account or a work account, and the encryption option will appear in your settings.
Action: Make sure you are signed into Windows with an administrator account. If you are using a local account, consider switching to a Microsoft account. Device Encryption works best with these. You can usually find this setting under Settings > Accounts > Your info.
"TPM is not usable"
The TPM is not usable error means your Trusted Platform Module (a hardware chip that secures your computer) is turned off in your motherboard settings or missing entirely, which is why device encryption missing issues occur. You need to restart your computer, enter the BIOS settings, and turn on the security chip before Windows can encrypt your drive.
Why it matters: The TPM is essential for safely managing your encryption keys. Without it, the encryption process is not secure.
Your PC needs a Trusted Platform Module (TPM) for device encryption. You can check for the TPM in Device Manager under "Security devices." If the TPM is present but not turned on, restart your computer and enter its BIOS or UEFI settings. This usually requires pressing a key like F2, F10, F12, or DEL right after powering on your PC. Find the option for "TPM," "Security Chip," or "PTT" (for Intel processors) and turn it on.
"WinRE is not configured"
The WinRE is not configured error means the Windows Recovery Environment (built-in repair tools used to fix boot problems) is disabled or your recovery partition is broken, causing device encryption missing errors. Windows requires this recovery partition to safely handle your encryption keys during system startup and repairs.
If the Windows Recovery Environment is missing or not set up, you cannot turn on Device Encryption.
Action: To fix this, make sure your Windows installation is up-to-date and that the recovery partition is working. Sometimes, using the System File Checker tool can help. Open Command Prompt as an administrator (search for cmd, right-click, and select "Run as administrator"). Then, type sfc /scannow and press Enter. This checks for and tries to fix any damaged system files, which might include parts of WinRE.
"PCR7 binding is not supported"
The PCR7 binding is not supported message means Secure Boot is turned off in your system firmware or your computer uses an older hardware setup, which causes device encryption missing warnings. Secure Boot must be active and running in UEFI mode so your computer can measure system files safely during startup.
Why it matters: For Device Encryption to be secure, your computer must start up in a specific, protected way. This requires Secure Boot to be turned on and for certain devices not to be connected when Windows starts.
Action:
- Check Secure Boot: Like the TPM, Secure Boot is usually turned on or off in your computer's BIOS/UEFI settings. You'll need to restart your PC and go into those settings. Look for an option called "Secure Boot" and make sure it's enabled. If Secure Boot is off, enabling it might resolve the issue.
- Disconnect Peripherals: Try unplugging any external devices you don't absolutely need before your computer starts up. This includes things like special network adapters, docking stations, external graphics cards, or even some USB devices. Once Windows is running and Device Encryption is turned on, you can usually plug them back in.
References:
https://support.microsoft.com/en-US/Windows/Security/encryption/device-encryption-in-windows
Summary
Device encryption missing problems in Windows 11 always stem from incompatible hardware settings, a disabled security chip, or a broken recovery partition. You can find the exact blocker by opening the System Information tool, checking your encryption support status, and fixing problems like a turned-off TPM or missing Secure Boot.
Does 🪟 Windows 11 have built-in encryption?
Um you go to privacy. And security. And then you go to device encryption. And if you've signed in with an online account of any kind so this would be work or school or Microsoft.
Was this guide helpful?
About the Author
Richard
Tech Writer, IT Professional
Richard, a writer for Geek Rewind, is a tech enthusiast who loves breaking down complex IT topics into simple, easy-to-understand ideas. With years of hands-on experience in system administration and enterprise IT operations, he’s developed a knack for offering practical tips and solutions. Richard aims to make technology more accessible and actionable. He's deeply committed to the Geek Rewind community, always ready to answer questions and engage in discussions.
No comments yet — be the first to share your thoughts!