Windows 10 Pro Encryption Guide: BitLocker, EFS & Recovery Keys
Windows 10 Pro includes several built-in encryption tools that can help protect files and drives if a computer or storage device is lost, stolen or accessed without authorisation.
The main encryption options are BitLocker Drive Encryption for whole drives and Encrypting File System (EFS) for individual files and folders. Some compatible Windows devices can also use the simpler Device Encryption feature.
Important in 2026: normal Microsoft support for Windows 10 ended on 14 October 2025. Encryption can protect stored data, but it does not make an unsupported operating system secure again.
Eligible Windows 10 version 22H2 personal PCs can enrol in Microsoft's Consumer Extended Security Updates programme for critical and important security updates through 12 October 2027.
Quick answer: For most Windows 10 Pro users who want to protect an entire PC or drive, BitLocker is the main built-in encryption tool. Before enabling it, make sure you know where the 48-digit BitLocker recovery key will be stored. Use EFS only when you specifically need individual file or folder encryption and understand how its encryption keys are protected.
What Does Windows Encryption Actually Protect?
Encryption converts stored information into data that cannot normally be read without the appropriate decryption key.
This is particularly useful if:
- A laptop is lost or stolen.
- A hard drive or SSD is removed from the computer.
- An external drive containing sensitive files is lost.
- Someone attempts to access data without the authorised Windows environment.
Encryption mainly protects data at rest. If somebody is already signed into your unlocked Windows account, encryption does not stop them opening files that your account is permitted to access.
Encryption is only one part of PC security
You should still use:
- A strong Windows password or PIN.
- Windows Hello where supported.
- Current security updates.
- Supported antivirus and security protection.
- Secure backups.
- Appropriate user-account permissions.
Encryption complements these protections rather than replacing them.
BitLocker Drive Encryption vs Device Encryption
Microsoft now describes BitLocker as having two related forms of protection.
Device Encryption
A simpler encryption feature available on a wider range of compatible Windows devices, including some Windows Home PCs.
On suitable hardware it can automatically encrypt the operating-system and fixed drives.
BitLocker Drive Encryption
The full manual drive-encryption management feature available on Windows Pro, Enterprise and Education.
Windows 10 Pro users can manually manage operating-system drives, fixed data drives and removable drives.
Windows Home can therefore have encryption without having the full Manage BitLocker interface. Seeing an encrypted Home PC does not mean that Home includes all of the BitLocker management features found in Pro.
What Does Windows 10 Pro Add?
Windows 10 Pro provides the full BitLocker Drive Encryption management interface.
This allows you to manage encryption for:
- The Windows operating-system drive.
- Additional internal drives.
- External data drives.
- USB flash drives using BitLocker To Go.
If full manual BitLocker management is one of the reasons you need Windows Pro, see our Windows 10 Home vs Pro comparison.
How to Check Whether BitLocker Is Already Enabled
Do not automatically turn encryption on again before checking the current status.
Method 1: Manage BitLocker
- Select the Windows Start button.
- Type BitLocker.
- Select Manage BitLocker.
The BitLocker Drive Encryption window will show the drives attached to the PC and their current encryption status.
Method 2: Check Device Encryption
On compatible Windows devices, Device Encryption settings may also be available.
The exact location can vary by Windows version and device configuration.
Before making changes, confirm whether the drive is already encrypted and where its recovery key is stored. Do not disable and re-enable encryption unnecessarily.
How to Turn On BitLocker in Windows 10 Pro
Before enabling BitLocker, save your work and make sure important files are backed up.
Step 1: Open Manage BitLocker
- Select Start.
- Search for BitLocker.
- Select Manage BitLocker.
Step 2: Choose the drive
Find the drive you want to protect.
Select:
Turn on BitLocker
Step 3: Follow the unlock options shown by Windows
The options Microsoft displays depend on the type of drive, hardware and Windows configuration.
Follow the supported BitLocker setup wizard for that drive.
Step 4: Back up the recovery key
This is one of the most important parts of the entire process.
Windows will provide options for saving the BitLocker recovery information.
Depending on your configuration, this can include:
- Your Microsoft account.
- A work or school account.
- A USB flash drive.
- A file stored somewhere appropriate.
- A printed copy.
Do not continue until the recovery key is safe
A BitLocker recovery key is a unique 48-digit number that can unlock the encrypted drive when Windows cannot unlock it normally.
Microsoft Support cannot retrieve, provide or recreate a lost BitLocker recovery key.
EcoKeys cannot retrieve or recreate your personal BitLocker recovery key either.
Step 5: Start encryption
Continue through Microsoft's BitLocker wizard and select the encryption options appropriate for the drive.
Windows will then begin encrypting it.
The encryption process can take some time depending on:
- The size of the drive.
- The amount of data stored.
- The speed of the SSD or hard drive.
- The encryption option selected.
You can normally continue using Windows while encryption progresses.
Do not deliberately interrupt the encryption process. Keep a laptop connected to power where practical and allow Windows to complete the operation.
Your BitLocker Recovery Key Is Critical
BitLocker may request the recovery key if Windows cannot automatically confirm that the computer is being accessed normally.
This can happen following certain:
- Hardware changes.
- Firmware or BIOS/UEFI changes.
- TPM changes.
- Security configuration changes.
- Drive moves or other unusual access conditions.
Being asked for the recovery key does not automatically mean the drive or Windows licence is faulty. BitLocker is deliberately preventing access until the recovery information is supplied.
Find a BitLocker recovery key stored in your Microsoft account
If the key was backed up to your Microsoft account, Microsoft's recovery-key page is:
Work or school computer
If the device is or was managed by an organisation, the recovery key may be stored in the organisation's work or school account or management system.
Contact the organisation's IT administrator if necessary.
Check other locations
The key may also have been:
- Printed.
- Saved as a file.
- Stored on a USB drive.
- Saved by the administrator who originally configured BitLocker.
If the recovery key cannot be found, there may be no way to recover the encrypted data. Microsoft warns that resetting the device as a recovery option removes files.
BitLocker Recovery Key vs Windows Product Key
These are completely different.
Windows product key
A 25-character licence key used for Windows activation.
Example format:
XXXXX-XXXXX-XXXXX-XXXXX-XXXXX
BitLocker recovery key
A 48-digit recovery number used to unlock an encrypted drive when BitLocker enters recovery mode.
Your Windows 10 Pro licence cannot unlock a BitLocker-encrypted drive. Entering or replacing a Windows product key will not recover encrypted files.
Encrypting a USB Drive With BitLocker To Go
Windows 10 Pro can also encrypt compatible removable storage using BitLocker To Go.
This can be useful for USB drives carrying:
- Business documents.
- Customer information.
- Financial files.
- Backups.
- Other confidential information.
Turn on BitLocker for a removable drive
- Connect the USB or removable drive.
- Open Manage BitLocker.
- Find the drive under the removable-drive section.
- Select Turn on BitLocker.
- Choose the supported unlock method offered by Windows.
- Back up the recovery key.
- Follow the remaining encryption prompts.
Keep the recovery information separate from the encrypted USB. Saving the only recovery information on the drive it is supposed to unlock defeats the purpose if that drive becomes inaccessible.
Encrypt Individual Files and Folders With EFS
Windows also includes Encrypting File System, usually shortened to EFS.
EFS is different from BitLocker.
BitLocker
Designed to encrypt an entire drive.
EFS
Designed to encrypt selected files or folders on an NTFS volume.
Microsoft's file-encryption feature is not available in Windows Home, making it another feature associated with Pro-level Windows editions.
How to encrypt a file or folder
- Right-click the file or folder.
- Select Properties.
- Select Advanced.
- Tick Encrypt contents to secure data.
- Select OK.
- Select Apply.
- Complete the Windows prompts.
EFS requires careful key management. The encryption is tied to the appropriate Windows encryption certificate and private key. Losing access to the required key can make encrypted files inaccessible.
Should you use EFS?
EFS can be useful when only specific files need additional protection, but for many ordinary users BitLocker whole-drive encryption is easier to understand and manage.
Use EFS only when you understand:
- Which Windows user encrypted the files.
- How access is controlled.
- How the encryption certificate and key are backed up.
- What will happen if the Windows user profile is lost or damaged.
Do not use EFS as your only backup strategy. Encryption protects confidentiality; it does not protect against drive failure, accidental deletion or file corruption.
How to decrypt an EFS file or folder
While signed into the authorised Windows account:
- Right-click the encrypted file or folder.
- Select Properties.
- Select Advanced.
- Clear Encrypt contents to secure data.
- Select OK.
- Select Apply.
Is Windows Hello an Encryption Feature?
No.
This is an important correction to the original version of this article.
Windows Hello is an authentication technology. It can let an authorised user sign into Windows using supported methods such as:
- A PIN.
- Fingerprint recognition.
- Facial recognition.
Windows Hello can improve sign-in security, but it is not a replacement for BitLocker or EFS.
Windows Hello
Helps establish who is signing into Windows.
BitLocker
Encrypts drive contents to protect stored data from unauthorised offline access.
Using Windows Hello and BitLocker together can therefore provide different layers of protection.
Does TPM 2.0 Encrypt Your Files?
Not by itself.
A Trusted Platform Module (TPM) is security hardware that Windows and BitLocker can use to protect cryptographic information and verify the system environment.
TPM can therefore play an important role in BitLocker, but:
TPM, BitLocker and encryption are not interchangeable terms. Having a TPM does not automatically tell you which drives are currently encrypted.
Check the actual BitLocker or Device Encryption status in Windows.
Does Secure Boot Encrypt the Drive?
No.
Secure Boot is a firmware security feature designed to help ensure trusted software starts during the boot process.
It complements features such as BitLocker but does not itself encrypt documents or drives.
How to Turn BitLocker Off
If you genuinely need to remove BitLocker protection:
- Open Manage BitLocker.
- Find the encrypted drive.
- Select Turn off BitLocker.
- Confirm the action.
- Allow Windows to decrypt the drive completely.
Turning BitLocker off decrypts the drive. This is different from temporarily suspending BitLocker protection.
Suspend BitLocker vs turn BitLocker off
Suspend protection
The drive remains encrypted, but BitLocker protection is temporarily suspended so an authorised system change can take place.
Turn off BitLocker
Windows decrypts the drive and removes BitLocker protection.
Some manufacturer firmware or TPM updates may instruct you to suspend BitLocker first.
Follow the PC or motherboard manufacturer's instructions rather than disabling encryption unnecessarily.
Normal Windows updates do not generally require users to manually disable BitLocker. Only suspend protection when there is a specific reason or supported instruction to do so.
Which Windows Encryption Option Should You Use?
BitLocker
Best for protecting an entire Windows drive, internal data drive or compatible removable drive.
Device Encryption
Useful on compatible devices where Windows provides the simplified automatic encryption experience.
EFS
Useful for advanced users who specifically need individual NTFS file or folder encryption and understand key management.
Windows Hello
Use for authentication and convenient secure sign-in. It complements encryption rather than replacing it.
Encryption Mistakes to Avoid
Not saving the recovery key
The BitLocker recovery key may be essential after a hardware or security change.
Confusing the Windows key with the BitLocker key
A 25-character Windows licence key cannot unlock encrypted data.
Keeping the only recovery copy on the encrypted drive
Store recovery information somewhere separately accessible.
Using EFS without backing up encryption credentials
Losing the required certificate/private key can make files inaccessible.
Assuming encryption replaces backups
Encryption does not protect against disk failure or accidental deletion.
Turning BitLocker off for routine updates
Follow supported manufacturer or Microsoft instructions rather than decrypting drives unnecessarily.
Windows 10 Encryption After End of Support
BitLocker and EFS do not stop functioning simply because Windows 10 reached end of support.
However, security needs to be considered as a complete system.
Normal Windows 10 support ended on:
14 October 2025
Microsoft no longer provides normal Windows 10:
- Security updates.
- Feature updates.
- Bug fixes.
- Technical support.
An encrypted but unpatched operating system can still contain security vulnerabilities. BitLocker protects stored data against particular types of access; it does not patch Windows vulnerabilities.
Windows 10 Consumer ESU
Eligible personal Windows 10 version 22H2 PCs can enrol in Microsoft's Consumer Extended Security Updates programme.
Microsoft currently provides critical and important security updates through:
12 October 2027
ESU does not provide new Windows features or normal technical support.
Should you move to Windows 11?
If the PC fully supports Windows 11 and there is no specific Windows 10 compatibility requirement, Windows 11 is normally the better long-term security choice.
You can check your computer using our:
Windows 10 Encryption Checklist
Check the Windows edition
Full BitLocker management requires Windows Pro, Enterprise or Education.
Check whether encryption is already active
Do not change settings before knowing the current state.
Back up important files
Encryption is not a replacement for a normal backup.
Protect the recovery key
Make sure you know where your 48-digit BitLocker recovery key is stored.
Use BitLocker for whole-drive protection
This is normally the easiest option for Windows 10 Pro users.
Use EFS carefully
Only encrypt individual files or folders when you understand certificate and key recovery.
Keep Windows security in context
Encryption does not change the Windows 10 end-of-support position.
Consider Windows 11
A compatible modern PC should normally use a currently supported Windows version.
Related Windows Guides
Frequently Asked Questions
Does Windows 10 Pro include BitLocker?
Yes. Windows 10 Pro includes the full BitLocker Drive Encryption management feature for supported operating-system, fixed and removable drives.
Does Windows 10 Home have encryption?
Some compatible Windows Home devices can use Microsoft's simpler Device Encryption feature. Windows Home does not include the full Manage BitLocker functionality available in Windows Pro.
How do I turn on BitLocker in Windows 10 Pro?
Search Windows for Manage BitLocker, select the drive and choose Turn on BitLocker. Follow Microsoft's setup wizard and make sure the recovery key is backed up before relying on the encrypted drive.
What is a BitLocker recovery key?
It is a unique 48-digit number that can unlock a BitLocker-protected drive when Windows cannot unlock it automatically.
Can Microsoft recover a lost BitLocker recovery key?
No. Microsoft states that its support team cannot retrieve, provide or recreate a lost BitLocker recovery key.
Can EcoKeys recover my BitLocker key?
No. A BitLocker recovery key belongs to the encrypted device and its owner or managing organisation. It is separate from the Windows product key supplied for Windows activation.
Is a BitLocker recovery key the same as my Windows 10 product key?
No. A Windows product key contains 25 characters and is used for Windows activation. A BitLocker recovery key contains 48 digits and is used to unlock an encrypted drive.
Can Windows 10 Pro encrypt USB drives?
Yes. BitLocker To Go can encrypt compatible removable drives such as USB flash drives from the Manage BitLocker interface.
What is EFS in Windows 10 Pro?
Encrypting File System is a Windows feature that encrypts selected files or folders on supported NTFS volumes rather than encrypting an entire drive.
Is Windows Hello an encryption feature?
No. Windows Hello is an authentication technology for signing into Windows using methods such as a PIN, fingerprint or facial recognition. It can complement BitLocker but does not replace drive encryption.
Should I turn BitLocker off before Windows updates?
Not normally. Routine supported Windows updates generally do not require users to decrypt their drives. Some manufacturer firmware or TPM updates may specifically instruct you to suspend BitLocker protection temporarily.
Does BitLocker make Windows 10 safe after end of support?
No. BitLocker protects stored data, but Windows 10 itself is outside normal support. Eligible Windows 10 22H2 personal PCs can use Consumer ESU for critical and important security updates through 12 October 2027.