Flamingo Raises $4.5M Seed Round

Skip to content

Updated: October 2026

Turning BitLocker on takes a few clicks. The trouble shows up later, when a firmware update or a swapped motherboard asks for a recovery key nobody saved. Here's how to run BitLocker on Windows 10 and Windows 11 so both halves work: the encryption, and the key you'll need the day the recovery screen shows up.

Device Encryption vs BitLocker

Windows ships two versions of the same idea. Both use the BitLocker engine. They differ in who turns them on and where the key goes.

Device encryption is the automatic version. On a qualifying PC it encrypts the OS drive and fixed drives after setup, then removes the clear key once the recovery key is backed up. On a work device that backup goes to Microsoft Entra ID or Active Directory. On a personal device it goes to the Microsoft account used to sign in. Device encryption is available on every Windows edition, including Home, but it doesn't encrypt USB drives and gives you few settings.

BitLocker is the managed version. It needs Windows Pro, Enterprise or Education. You choose the protectors, the encryption method, used space or full disk, removable drives, and where recovery information must be stored before encryption starts. For company devices, that's the one you want.

Windows 11 24H2 widened the net. Microsoft removed the DMA and HSTI/Modern Standby prerequisites for device encryption, so more PCs now encrypt themselves after a clean install. Worth knowing before you reimage a fleet and wonder why some laptops came back encrypted.

Check the PC Before You Turn It On

BitLocker gets its best protection from a TPM. The TPM checks the boot chain and only releases the key if nothing was tampered with. That needs TPM 1.2 or later, and TPM 2.0 needs native UEFI mode with Legacy and CSM turned off. If a machine says it has no TPM, fix that first. Our guide to TPM device not detected covers firmware settings and the Windows side.

The drive layout matters too. BitLocker needs a small unencrypted system partition next to the OS drive. A normal Windows install creates it, so this only bites on odd images and cloned disks.

Two quick checks tell you where a PC stands. msinfo32 shows "Device Encryption Support" and, if it says "Meets prerequisites," the hardware qualifies. manage-bde -status shows each volume, its encryption method and whether protection is on.

How to Enable BitLocker on Windows 10 and 11

On a single PC, the Control Panel wizard is the fastest route:

  1. Open Manage BitLocker and select Turn on BitLocker next to the OS drive.
  2. Save the recovery key to your Entra ID or Microsoft account, a file on another device, or a printout. Never to the drive you're encrypting.
  3. Choose Encrypt entire drive for any PC that already has data on it.
  4. Pick New encryption mode unless the drive will move to an older Windows version.
  5. Restart and let the system check run.

"Used space only" is faster, but Microsoft is clear about the catch: deleted files look like free space, so they stay unencrypted until something overwrites them. On a new PC that never held data, used space only is fine. On a laptop that's been in use for a year, encrypt the whole drive.

For scripts, PowerShell and manage-bde do the same job:

powershell
# Status of every volume
Get-BitLockerVolume | Format-Table MountPoint, VolumeStatus, ProtectionStatus, EncryptionPercentage

# Turn on BitLocker with a TPM protector and add a recovery password
Enable-BitLocker -MountPoint C: -EncryptionMethod XtsAes128 -TpmProtector
Add-BitLockerKeyProtector -MountPoint C: -RecoveryPasswordProtector

This walkthrough covers what BitLocker protects against and the first setup on a single PC:

TPM Only or TPM Plus PIN

A TPM-only protector unlocks the drive automatically at boot. Users never see it. It stops the "pull the drive and read it elsewhere" attack, which covers the lost-laptop case.

TPM plus a startup PIN adds a second factor before Windows loads. It's the stronger setting for people who carry sensitive data or travel. It's also the setting that breaks silent enrollment, because a PIN needs a person at the keyboard.

A startup key on a USB drive is the option for PCs without a TPM. Password-only protection for the OS drive exists, but Microsoft disables it by default because it has no lockout.

Escrow the Recovery Key Before You Need It

The recovery key is the whole game. BitLocker without an escrowed key is a data-loss feature with a nicer name.

Store keys centrally. For Entra-joined devices, the recovery password lives on the device object in Entra ID. For domain-joined devices, it's a child object of the computer account in AD DS. Set the "Choose how BitLocker-protected operating system drives can be recovered" policy, and turn on Do not enable BitLocker until recovery information is stored. That one setting blocks encryption on any machine that can't reach the escrow target, so you never end up with an encrypted drive and no key.

Machines that were encrypted before they joined your tenant are the usual gap. You can push the key up by hand, or in a remediation script:

powershell
$v = Get-BitLockerVolume -MountPoint C:
$id = ($v.KeyProtector | Where-Object KeyProtectorType -eq 'RecoveryPassword').KeyProtectorId
BackupToAAD-BitLockerKeyProtector -MountPoint C: -KeyProtectorId $id
# Domain-joined instead: Backup-BitLockerKeyProtector -MountPoint C: -KeyProtectorId $id

This r/Intune thread is the case you're trying to avoid: a locked drive, and no key in Entra or Intune.

The replies suggest a remediation script that forces the key into Entra. That only helps while the drive is still unlocked, which is why escrow has to be checked, not assumed.

Turning It On Across a Fleet With Intune

In Intune, BitLocker lives under Endpoint security > Disk encryption, in a BitLocker profile. Microsoft recommends that profile over the Settings Catalog for BitLocker, because the catalog lacks the TPM startup controls silent enablement needs.

Silent encryption, where users see nothing, has a short list of requirements: Entra joined or hybrid joined, a TPM, native UEFI, Secure Boot on and Windows RE available. In the profile, set Require Device Encryption to enabled, Allow Warning For Other Disk Encryption to disabled, and Allow Standard User Encryption to enabled if people don't run as admins. The TPM startup settings must not allow a PIN or startup key. Microsoft warns that the Defender security baseline can turn those on by default and quietly block silent enablement.

Two admin details save a lot of tickets. The Encryption report under Devices > Monitor shows which machines are encrypted and whether their keys reached Entra. And with rotation enabled in policy, the BitLocker key rotation device action issues a new recovery password after one has been read out to a user. More on the rest of the console is in our Microsoft Intune review.

To check a mixed fleet outside Intune, Get-BitLockerVolume returns everything you need in one line per volume. OpenFrame can run it as a script across a client's devices and collect the output, so unencrypted and suspended drives show up in one list.

What Triggers BitLocker Recovery

The recovery screen appears when the TPM sees a boot chain it doesn't recognize. Often that's routine maintenance, not an attack. Microsoft's list of common triggers includes:

  • A BIOS or UEFI firmware upgrade
  • Turning off, clearing or resetting the TPM
  • Changes to the boot manager or the partition table
  • A CD, DVD or PXE entry placed ahead of the disk in the boot order
  • Docking or undocking a laptop
  • Too many wrong PIN entries

Firmware updates are the trigger you can plan for. Suspend BitLocker before you flash, and it resumes on its own after the next restart. For updates that reboot more than once, set a reboot count:

powershell
Suspend-BitLocker -MountPoint C: -RebootCount 2

Suspending doesn't decrypt anything. It leaves the key readable for the reboots you asked for, then reseals it. Our guide to a BIOS update shows where this fits in the update order.

The same rule covers docks, SSDs and network cards. Our guide to updating other firmware walks through each one.

Suspension can also go wrong. In this thread, a firmware update suspended protection and it never resumed. The drive was decrypted and re-encrypted, and the new key wouldn't save to Entra:

The fix the replies point to is the same backup command from the escrow section, plus the BitLocker event log to see why the upload failed.

Finding a Recovery Key, and When There Isn't One

The recovery screen shows a Key ID. Match it to the stored key. In Intune, open the device and select Recovery keys. In Entra, it's on the device object. For domain-joined PCs, look under the computer account in Active Directory. Every lookup in Entra is audit-logged, and Microsoft Entra ID holds up to 200 keys per device, which matters on machines that re-encrypt often.

If there's no key anywhere, there's no way in. That's the design. A data recovery agent certificate helps only if you configured one in policy, and the BitLocker Repair Tool still needs a key package plus a recovery password to salvage a damaged drive. Without those, the answer is a wipe and a restore from backup. Plan the escrow, and this section stays theoretical.

BitLocker, in Short

Use device encryption where it turns itself on, and managed BitLocker on every company PC. Require escrow before encryption, check the Encryption report, and suspend with a reboot count before firmware updates. Have a lookup path ready for the day the recovery screen shows up.

Managing Macs too? FileVault is the Apple equivalent, and the key escrow rules are the same idea on a different platform.

Aliaska Varieva

Aliaska Varieva

Head of Platform

Hi! I’m Aliaska, and I’ve been working as a software engineer (mostly Java + a bit Kotlin) for over 8 years now. I mostly spend my time building backend services, integrating systems, fixing bugs (the fun part 🙃), and making sure things don’t fall apart behind the scenes.

Related Content

Blog Posts

Product Releases

Podcasts

Webinars

Case Studies

Events

Onboarding Guides

Frequently Asked Questions

BitLocker

Both use the same BitLocker engine. Device encryption turns on automatically on qualifying PCs, on every Windows edition including Home, and backs the recovery key up to Entra ID, Active Directory or a Microsoft account. BitLocker is the managed version on Pro, Enterprise and Education, where you choose protectors, encryption method, removable drives and where the key must be stored before encryption starts.
Not the managed version. BitLocker enablement is supported on Windows Pro, Enterprise, Pro Education and Education. Windows Home can use device encryption if the hardware qualifies, which encrypts the OS and fixed drives automatically and stores the recovery key in the Microsoft account used to sign in.
Match the Key ID shown on the recovery screen. For a company PC joined to Microsoft Entra ID, it is on the device in Entra ID and in Intune under the device's Recovery keys. For a domain-joined PC, it is stored under the computer account in Active Directory. For a personal PC, check the Microsoft account used to set it up.
No. Without the recovery password, a recovery key file or a data recovery agent configured in advance, the data can't be read. The BitLocker Repair Tool also needs a key package plus a recovery password. If no key exists, the fix is to wipe the drive and restore from backup, which is why escrowing keys before encryption matters.

About OpenFrame

In the cloud, on US soil. Your data stays stateside.
OpenFrame isn't built to plug into your stack. It replaces it. Instead of duct-taping a dozen tools together (RMM, MDM, SIEM, patching, remote access, each its own login and bill), we bundle it into one unified platform: RMM, MDM, monitoring, automation, remote access, patch management, security monitoring, and ticketing, plus built-in AI copilots. So "does it integrate with X?" usually means: you won't need X anymore.
Most platforms give you one piece and expect you to bolt the rest on. OpenFrame unifies the whole stack in one place, with AI copilots built in. Fewer logins, fewer bills, less duct tape.
Both. It's built for MSPs and MSSPs alike.

MSP AI Agents

On a five-person desk, reported deployments show $78,000 to $130,000 in annual direct labor savings, roughly 30% fewer escalations, and 15% to 20% better SLA compliance. Broader MSP adoption data adds ticket handling time cut by 45% and five to 12 points of margin, all from reclaimed capacity rather than headcount cuts.
Yes. In production MSP shops today, 10% to 25% of tickets close before a human opens them. Thread alone has processed 173 million tickets across 750-plus MSP partners at 96% triage accuracy, handing back 490,000-plus technician hours. Agents own the low-risk, high-volume work (password resets, MFA enrollment, known installs, onboarding and offboarding) and flag anything that touches production data or needs judgment for a human to take.