Use Bitlocker Windows 10 Home

  
Use Bitlocker Windows 10 Home Rating: 5,0/5 532 votes

When you store sensitive data on your computer, it's crucial that you take the necessary steps to protect that data (especially if you use a laptop or tablet). This is not just to stop the NSA from accessing your files, but it's more about preventing your private data from falling into the wrong hands in the slightly change you lose your device, or it gets stolen.

BitLocker feature is not available in the Windows 10 Home Edition, are you still want to encrypt volumes with BitLocker in Windows 10 Home? This tutorial will teach you how to enable BitLocker for Windows 10 Home Edition with Hasleo BitLocker Anywhere. Jul 28, 2016  BitLocker on Windows 10 Home edition Dear community, I would like to use BitLocker to encrypt my hard drive, but I have the standard 8.1 version, which will become Windows 10 Home.

On way you can protect your data is by using encryption. Briefly, encryption is basically the process of making any type of data unreadable by anyone without proper authorization. If you use encryption to scramble your data, it will continue to be unreadable even after sharing it with other people. In other words, only you with the right encryption key can make the data readable again.

Windows 10, similar to previous versions, includes BitLocker Drive Encryption, a feature that allows you to use encryption on your PC's hard drive and on removable drives to prevent prying eyes from snooping into your sensitive data.

Bitlocker Windows 10 Home Premium

In this Windows 10 guide, we'll walk you through the steps to set up BitLocker on your PC to make sure your sensitive data stays secure.

Things to know before diving into this guide

  • BitLocker Drive Encryption is available only on Windows 10 Pro and Windows 10 Enterprise.
  • For best results your computer must be equipped with a Trusted Platform Module (TPM) chip. This is a special microchip that enables your device to support advanced security features.
  • You can use BitLocker without a TPM chip by using software-based encryption, but it requires some extra steps for additional authentication.
  • Your computer's BIOS must support TPM or USB devices during startup. If this isn't the case, you'll need to check your PC manufacturer's support website to get the latest firmware update for your BIOS before trying to set up BitLocker.
  • Your PC's hard drive must contain two partitions: a system partition, which contains the necessary files to start Windows, and the partition with the operating system. If your computer doesn't meet the requirements, BitLocker will create them for you. Additionally, the hard drive partitions must be formatted with the NTFS file system.
  • The process to encrypt an entire hard drive isn't difficult, but it's time-consuming. Depending the amount of data and size of the drive, it can take a very long time.
  • Make sure to keep your computer connected to an uninterrupted power supply throughout the entire process.

Important: While BitLocker is a stable feature on Windows 10, as any significant change you make to your computer has its risks. It's always recommended that you make a full backup of your system before proceeding with this guide.

How to check if your device has a TPM chip

  1. Use the Windows key + X keyboard shortcut to open the Power User menu and select Device Manager.
  2. Expand Security devices. If you have a TPM chip, one of the items should read Trusted Platform Module with the version number.

Note: Your computer must have a TPM chip version 1.2 or later to support BitLocker.

Alternatively, you can also check your PC manufacturer's support website to find out if your device includes the security chip, and for instructions to enable the chip in the BIOS (if applicable).

Devices, such as Surface Pro 3, Surface Pro 4, or Surface Book come with the TMP chip to support BitLocker encryption.

How to ensure you can turn on BitLocker without TPM

If your computer doesn't include a Trusted Platform Module chip, you won't be able to turn on BitLocker on Windows 10. In this is your case, you can still use encryption, but you'll need to use the Local Group Policy Editor to enable additional authentication at startup.

  1. Use the Windows key + R keyboard shortcut to open the Run command, type gpedit.msc, and click OK.
  2. Under Computer Configuration, expand Administrative Templates.
  3. Expand Windows Components.
  4. Expand BitLocker Drive Encryption and Operating System Drives.
  5. On the right side, double-click Require additional authentication at startup.

  6. Select Enabled.
  7. Make sure to check the 'Allow BitLocker without a compatible TPM (requires a password or a startup key on a USB flash drive)' option.
  8. Click OK to complete this process.

How to turn on BitLocker on the Operating system drive

Once you made sure BitLocker can be properly enabled on your computer, follow these steps:

  1. Use the Windows key + X keyboard shortcut to open the Power User menu and select Control Panel.
  2. Click System and Security.
  3. Click BitLocker Drive Encryption.

  4. Under BitLocker Drive Encryption, click Turn on BitLocker.

  5. Choose how you want to unlock your drive during startup: Insert a USB flash drive or Enter a password. For the purpose of the guide, select Enter a password to continue.

  6. Enter a password that you'll use every time you boot Windows 10 to unlock the drive, and click Next to continue. (Make sure to create a strong password mixing uppercase, lowercase, numbers, and symbols.)

  7. You will be given the choices to save a recovery key to regain access to your files in case you forget your password. Options include:

    • Save to your Microsoft account
    • Save to a USB flash drive
    • Save to a file
    • Print the recovery

    Select the option that is most convenient for you, and save the recovery key in a safe place.

    Quick Tip: If you trust the cloud, you can choose to save your recovery key in your Microsoft account using the Save to your Microsoft account option. In which case, you can retrieve your encryption key at this location: https://onedrive.live.com/recoverykey.

  8. Click Next to continue.

  9. Select the encryption option that best suits your scenario:

    • Encrypt used disk space only (faster and best for new PCs and drives)
    • Encrypt entire drive (slower but best for PCs and drives already in use)
  10. Choose between the two encryption options:

    • New encryption mode (best for fixed drives on this device)
    • Compatible mode (best for drives that can be moved from this device)

      On Windows 10 version 1511, Microsoft introduced support for XTS-AES encryption algorithm. This new encryption method provides additional integrity support and protection against new attacks that use manipulating cipher text to cause predictable modifications in clear text. BitLocker supports 128-bit and 256-bit XTS AES keys.

  11. Click Next to continue.

  12. Make sure to check the Run BitLocker system check option, and click Continue.

  13. Finally, restart your computer to begin the encryption process.
  14. On reboot, BitLocker will prompt you to enter your encryption password to unlock the drive. Type the password and press Enter.

After rebooting, you'll notice that your computer will quickly boot to the Windows 10 desktop. However, if you go to Control Panel > System and Security > BitLocker Drive Encryption, you'll see that BitLocker is still encrypting your drive. Depending on the option you selected and the size of the drive, this process can take a long time, but you'll still be able to work on your computer.

Once the encryption process completes, the drive level should read BitLocker on.

You can verify that BitLocker is turned on by the lock icon on the drive when you open This PC on File Explorer.

BitLocker Drive Encryption options

When BitLocker is enabled on your main hard drive, you'll get a few additional options, including:

  • Suspend protection: When you're suspending protection your data won't be protected. Typically, you would use this option when applying a new operating system, firmware, or hardware upgrade. If you don't resume the encryption protection, BitLocker will resume automatically during the next reboot.
  • Back up your recovery key: If you lose your recovery key, and you're still signed into your account, you can use this option to create a new backup of the key with the options mentioned on step 6.
  • Change password: You can use this option to create a new encryption password, but you'll still need to supply the current password to make the change.
  • Remove password: You can't use BitLocker without a form of authentication. You can remove a password only when you configure a new method of authentication.
  • Turn off BitLocker: In the case, you no longer need encryption on your computer, BitLocker provides a way to decrypt all your files. However, make sure to understand that after turning off BitLocker your sensitive data will no longer be protected. In addition, decryption may take a long time to complete its process depending on the size of the drive, but you can still use your computer.

How to turn on BitLocker To Go

BitLocker is not an encryption feature that you can enable globally on every drive connected to your computer at once. It has two part: you can use BitLocker Drive Encryption to encrypt your sensitive data on the main hard drive of your PC, and then you can use BitLocker To Go. This last feature will help you to use encryption on remove drives and secondary hard drives connected to your computer.

To turn on BitLocker To Go on a removable drive do the following:

  1. Connect the drive you want to use with BitLocker.
  2. Use the Windows key + X keyboard shortcut to open the Power User menu and select Control Panel.
  3. Click System and Security.
  4. Click BitLocker Drive Encryption.

  5. Under BitLocker To Go, expand the drive you want to encrypt.
  6. Click the Turn on BitLocker link.

  7. Check the Use a password to unlock the drive option, and create a password to unlock the drive. (Make sure to create a strong password mixing uppercase, lowercase, numbers, and symbols.)
  8. Click Next to continue.

  9. You will be given the choices to save a recovery key to regain access to your files in case you forget your password. Options include:

    • Save to your Microsoft account
    • Save to a file
    • Print the recovery

    Select the option that is most convenient for you, and click Next.

  10. Choose the encryption option that best suits your scenario:

    • Encrypt used disk space only (faster and best for new PCs and drives)
    • Encrypt entire drive (slower but best for PCs and drives already in use)
  11. Select between the two encryption options:

    • New encryption mode (best for fixed drives on this device)
    • Compatible mode (best for drives that can be moved from this device)

      In this step is recommended that you select the 'Compatible mode,' as it will ensure you can unlock the drive if you move it to another computer running a previous version of the operating system.

  12. Click Start encrypting Tomtom ireland map download. to finish the process.

When encrypting a storage try to start with an empty removable media, as it'll speed up the process, then new data will encrypt automatically.

In addition, similar to BitLocker Drive Encryption, you will get the same additional options using BitLocker To Go, plus a few more, including:

  • Add smart card: This option will allow you to configure a smart card to unlock the removable drive.
  • Turn on auto-unlock: Instead of having to type a password every time you re-connect the removable drive, you can enable auto-unlock to access your encrypted data without entering a password.

Quick access to manage your BitLocker drive

Whether you turn on BitLocker for your system hard drive or removable drive, you can always get quick access to the BitLocker settings for a particular drive using the following steps:

  1. Use the Windows key + E keyboard shortcut to open File Explorer.
  2. Click This PC from the left pane.
  3. Right-click the encrypted drive and select Manage BitLocker.

Wrapping things up

While Microsoft only includes BitLocker on Windows 10 Pro and Enterprise, this is one of those features that should be standard in every edition, including on Windows 10 Home. Even more, considering that we continue to move into a digital world, where every day, we're creating more sensitive data on our computers than ever before, and data encryption is crucial to protect our data from prying eyes.

It's worth pointing out that enabling data encryption may slightly slow down the performance of your device due to the encryption process that will continue to run in the background. However, it's a feature worth using to keep your sensitive data secure.

Do you use data encryption on your computer? Tell us in the comments below.

More Windows 10 resources

For more help articles, coverage, and answers on Windows 10, you can visit the following resources:

We may earn a commission for purchases using our links. Learn more.

Windows 10 sometimes uses encryption by default, and sometimes doesn’t—it’s complicated. Here’s how to check if your Windows 10 PC’s storage is encrypted and how to encrypt it if it isn’t. Encryption isn’t just about stopping the NSA—it’s about protecting your sensitive data in case you ever lose your PC, which is something everyone needs.

Unlike all other modern consumer operating systems—macOS, Chrome OS, iOS, and Android—Windows 10 still doesn’t offer integrated encryption tools to everyone. You may have to pay for the Professional edition of Windows 10 or use a third-party encryption solution.

Get Bitlocker Windows 10 Home

If Your Computer Supports It: Windows Device Encryption

RELATED:Windows 8.1 Will Start Encrypting Hard Drives By Default: Everything You Need to Know

Many new PCs that ship with Windows 10 will automatically have “Device Encryption” enabled. This feature was first introduced in Windows 8.1, and there are specific hardware requirements for this. Not every PC will have this feature, but some will.

There’s another limitation, too—it only actually encrypts your drive if you sign into Windows with a Microsoft account. Your recovery key is then uploaded to Microsoft’s servers. This will help you recover your files if you ever can’t log into your PC. (This is also why the FBI likely isn’t too worried about this feature, but we’re just recommending encryption as a means to protect your data from laptop thieves here. If you’re worried about the NSA, you may want to use a different encryption solution.)

Device Encryption will also be enabled if you sign into an organization’s domain. For example, you might sign into a domain owned by your employer or school. Your recovery key would then be uploaded to your organization’s domain servers. However, this doesn’t apply to the average person’s PC—only PCs joined to domains.

Bitlocker

To check if Device Encryption is enabled, open the Settings app, navigate to System > About, and look for a “Device encryption” setting at the bottom of the About pane. If you don’t see anything about Device Encryption here, your PC doesn’t support Device Encryption and it’s not enabled. If Device Encryption is enabled—or if you can enable it by signing in with a Microsoft account—you’ll see a message saying so here.

For Windows Pro Users: BitLocker

RELATED:Should You Upgrade to the Professional Edition of Windows 10?

If Device Encryption isn’t enabled—or if you want a more powerful encryption solution that can also encrypt removable USB drives, for example—you’ll want to use BitLocker. Microsoft’s BitLocker encryption tool has been part of Windows for several versions now, and it’s generally well regarded. However, Microsoft still restricts BitLocker to Professional, Enterprise, and Education editions of Windows 10.

BitLocker is most secure on a computer that contains Trusted Platform Module (TPM) hardware, which most modern PCs do. You can quickly check whether your PC has TPM hardware from within Windows, or check with your computer’s manufacturer if you’re not sure. If you built your own PC, you may able to add a TPM chip to it. Search for a TPM chip that’s sold as an add-on module. You’ll need one that supports the exact motherboard inside your PC.

RELATED:How to Use BitLocker Without a Trusted Platform Module (TPM)

Install Bitlocker Windows 10 Home

Windows normally says BitLocker requires a TPM, but there’s a hidden option that allows you to enable BitLocker without a TPM. You’ll have to use a USB flash drive as a “startup key” that must be present every boot if you enable this option.

If you already have a Professional edition of Windows 10 installed on your PC, you can search for “BitLocker” in the Start menu and use the BitLocker control panel to enable it. If you upgraded for free from Windows 7 Professional or Windows 8.1 Professional, you should have Windows 10 Professional.

If you don’t have a Professional edition of Windows 10, you can pay $99 to upgrade your Windows 10 Home to Windows 10 Professional. Just open the Settings app, navigate to Update & security > Activation, and click the “Go to Store” button. You’ll gain access to BitLocker and the other features that Windows 10 Professional includes.

Security expert Bruce Schneier also likes a proprietary full-disk encryption tool for Windows named BestCrypt. It’s fully functional on Windows 10 with modern hardware. However, this tool costs $99—the same price as an upgrade to Windows 10 Professional—so upgrading Windows to take advantage of BitLocker may be a better choice.

For Everyone Else: VeraCrypt

RELATED:3 Alternatives to the Now-Defunct TrueCrypt for Your Encryption Needs

Spending another $99 just to encrypt your hard drive for some additional security can be a tough sell when modern Windows PCs often only cost a few hundred bucks in the first place. You don’t have to pay the extra money for encryption, because BitLocker isn’t the only option. BitLocker is the most integrated, well-supported option—but there are other encryption tools you can use.

The venerable TrueCrypt, an open-source full-disk encryption tool that is no longer being developed, has some issues with Windows 10 PCs. It can’t encrypt GPT system partitions and boot them using UEFI, a configuration most Windows 10 PCs use. However, VeraCrypt—an open-source full-disk encryption tool based on the TrueCrypt source code—does support EFI system partition encryption as of versions 1.18a and 1.19.

In other words, VeraCrypt should allow you to encrypt your Windows 10 PC’s system partition for free.

RELATED:How to Secure Sensitive Files on Your PC with VeraCrypt

TrueCrypt’s developers did famously shut down development and declare TrueCrypt vulnerable and unsafe to use, but the jury is still out on whether this is true. Much of the discussion around this centers on whether the NSA and other security agencies have a way to crack this open-source encryption. If you’re just encrypting your hard drive so thieves can’t access your personal files if they steal your laptop, you don’t have to worry about this. TrueCrypt should be more than secure enough. The VeraCrypt project has also made security improvements, and should potentially be more secure than TrueCrypt. Whether you’re encrypting just a few files or your entire system partition, it’s what we recommend.

Bitlocker Windows 10 Home Unlock

We’d like to see Microsoft give more Windows 10 users access to BitLocker—or at least extend Device Encryption so it can be enabled on more PCs. Modern Windows computers should have built-in encryption tools, just like all other modern consumer operating systems do. Windows 10 users shouldn’t have to pay extra or hunt down third-party software to protect their important data if their laptops are ever misplaced or stolen.

Truecrypt

READ NEXT
  • › Protect Your Home Minecraft Server From DDOS Attacks with AWS
  • › How to Copy and Paste Text at Linux’s Bash Shell
  • › How to Remove Activation Lock on an iPhone
  • › How to Set Up a Smarthome Without the Cloud
  • › How to Quickly Create Your Own Chrome Browser Theme