💻/🖥️ Windows 10 - Turn on Full Disk Encryption

TYPE AUDIENCE PRIORITY COMPLEXITY EFFORT COST UPDATED
Preparation 🧑/🏗️ ⭐⭐⭐⭐⭐ ⭐⭐ 🧑 🆓 2021-06-17

Rationale

Without "Full Disk Encryption", a hard drive can simply be placed into another computer, and you wouldn't even need to have the user's windows passwords to access the files. This is undesirable, so we recommend adding "Full Disk Encryption" as a defence against this.

Instructions

What you should know

What you should prepare

Check whether your computer already has encryption turned on:

  1. Open the "Settings" app,
  2. Navigate to System > About
  3. Look for a “Device encryption” setting at the bottom of the About pane.
    Pasted image 20210617185806.png
  4. If you don’t see anything about "Device Encryption" here, your PC does not support built-in Device Encryption, and so it is not enabled. Look at how to 💻-🖥️ Encrypt Internal Drives with VeraCrypt instead.
  5. If Device Encryption is enabled - or if you can enable it by signing in with a Microsoft account — you’ll see a message saying so here.

If encryption is turned on you don't have to complete any further steps, if you can turn it on by signing into your Microsoft account, do so.

What you should do

  1. Search for “BitLocker” in the Start menu and use the BitLocker control panel to enable it.
    Pasted image 20210617190311.png
Troubleshooting
  1. If you get the following warning message - it means you don't have the required hardware component to setup BitLocker without using an additional USB Flash Drive.
    Pasted image 20210617190346.png
  2. Instead you will need to use an external application called VeraCrypt to perform the encrypt process. Follow the steps to 💻-🖥️ Encrypt Internal Drives with VeraCrypt.

Sources : How To Geek