Security

BitLocker

Microsoft drive-encryption technology available on supported Windows editions and devices. Keep the recovery key somewhere safe and separate from the encrypted computer.

How it works

BitLocker is Windows drive encryption. It protects stored data by requiring the appropriate unlocking conditions rather than leaving the drive’s contents directly readable. A computer can unlock its system drive during a normal trusted startup, while a changed situation may trigger a request for its recovery key.

A practical example

If a lost laptop’s drive is removed and connected elsewhere, encryption can prevent straightforward reading of its files without the required key. This addresses data at rest. It does not prevent a person already signed in on the unlocked laptop from opening files that their account is authorized to access.

What to check

Check the encryption status of the relevant drive through supported Windows settings; do not infer protection merely from a sign-in password. Confirm the recovery key is available to the rightful owner separately from that drive before firmware, hardware or startup changes. Managed computers may have organization-specific key storage and policies.

Limits and safe use

BitLocker is not a backup, antivirus scanner or guarantee against theft of data from a running compromised system. Availability and configuration depend on the Windows edition and device. Turning protection off changes the security of stored data; arrange maintenance with the responsible administrator instead of disabling encryption just because a recovery prompt appears.

Technical sources

← All glossary terms