Prerequisites and compatibility
Before you start, confirm the following:
Quick walkthrough
- A USB flash drive, external hard drive, or SD card is connected and appears in File Explorer with a drive letter, such as
E:. - You are signed in with an administrator account, or can provide administrator credentials when prompted.
- The drive is not needed by another program. Close any files opened from it.
- The drive uses a file system BitLocker To Go supports, including NTFS, FAT32, exFAT, or FAT16.
- You have a secure place separate from the USB drive to store a recovery key.
Warning: Encryption protects against someone reading the drive without its password; it does not back up the files. Copy irreplaceable files elsewhere before beginning. Do not disconnect the drive, force-restart Windows, or remove power while encryption is running.
BitLocker To Go does not require a TPM because the USB drive is unlocked with a password, smart card where configured, or its 48-digit recovery password.
For a drive you will use only on modern Windows 10 or Windows 11 PCs, use the default or recommended encryption choice offered by the wizard. If the wizard asks you to choose an encryption mode and you need the drive to work with older Windows computers, choose Compatible mode.
Encrypt the USB drive with BitLocker To Go
- Connect the USB drive and identify the correct drive letter.
Open File Explorer and select This PC. Under Devices and drives, note the name, capacity, and drive letter of the removable drive you intend to encrypt.
Confirm carefully that it is the external drive, not an internal disk or a recovery partition. - Start BitLocker To Go.
Use the method appropriate for your Windows version: - Windows 11: Open File Explorer > This PC, right-click the USB drive, and select Show more options if needed. Select Turn on BitLocker.
- Windows 10: Open File Explorer > This PC, right-click the USB drive, and select Turn on BitLocker.
If you prefer Control Panel on either version, open Control Panel > System and Security > BitLocker Drive Encryption. Find the removable drive under BitLocker To Go and select Turn on BitLocker.
Windows may take a moment to initialize the drive and open the BitLocker setup wizard.
- Choose how the drive will be unlocked.
For a typical personal USB drive, select Use a password to unlock the drive.
Enter a strong, unique password twice. Use a password you can enter on another computer if necessary; avoid a password that is used for your Windows sign-in, email, or other accounts.
If your work or school provides a smart card and requires it, choose Use my smart card to unlock the drive instead. Follow the organization’s instructions because smart-card use may rely on certificates and organizational policies.
Select Next. - Save the recovery key before proceeding.
The recovery key is the emergency method for opening the drive if you forget the password. Depending on your Windows edition, account type, and organizational policy, the wizard can offer one or more ways to save it, such as saving it to a file, printing it, or saving it to an approved account or organization-managed location.
Choose a recovery-key destination that is secure and available if the USB drive is lost: - Save it to an encrypted internal drive or reputable secure cloud storage.
- Print it and keep the printout in a secure location.
- If this is a managed work or school PC, follow the required organization-approved key backup method.
Warning: Do not save the recovery-key file on the USB drive being encrypted. If the drive is lost or locked, the key stored on it is unavailable. Do not store the password and recovery key together in an unprotected note or email.
Verify that the saved or printed key includes the recovery password and its identifier. Then select Next.
- Choose how much of the drive to encrypt.
The wizard may offer these options: - Encrypt used disk space only — Faster for a new or empty USB drive. New data written to the drive is encrypted after BitLocker is enabled.
- Encrypt entire drive — Recommended for a drive that has been used before, especially if it previously stored sensitive files. It encrypts both current data and unused space that could contain remnants of deleted files.
For a brand-new drive with no sensitive history, choose Encrypt used disk space only. For a drive that has already held personal, financial, work, or other sensitive files, choose Encrypt entire drive.
Select Next.
- Choose a compatible encryption mode if Windows asks.
Some versions of the wizard present an encryption-mode page. - Choose Compatible mode if the USB drive might be opened on an older Windows PC.
- Choose the newer/default mode only when you know the drive will stay with compatible current Windows systems and the wizard recommends it.
Select Next.
On organization-managed computers, this page may not appear because a BitLocker policy has already selected the encryption type or mode.
- Review the selections and begin encryption.
Confirm that the correct removable drive is listed, then select Start encrypting.
Expected result: Windows begins encrypting the removable drive. You may see a progress window or a BitLocker status indicator. You can usually continue using the PC, but leave the USB drive connected until encryption reaches 100%.
A restart is not normally required to encrypt a BitLocker To Go drive. - Wait for encryption to complete.
Encryption time depends on the drive’s capacity, speed, connection type, amount of existing data, and whether you chose used-space-only or full-drive encryption. A small, new USB drive can finish quickly; a large, previously used external drive can take much longer.
Keep the drive connected directly to the PC if possible. Avoid unstable USB hubs, loose cables, sleep, shutdown, and drive removal until the process reports completion.
Verify that the drive is protected
- Open Control Panel > System and Security > BitLocker Drive Encryption.
- Under BitLocker To Go, locate the removable drive.
- Confirm its status is BitLocker on or On. The management options should include items such as changing the password, backing up the recovery key, or turning off BitLocker.
- For a more detailed check, open Windows Terminal (Admin), PowerShell (Admin), or Command Prompt (Admin) and run the following command, replacing
E:with the USB drive’s actual letter:
manage-bde -status E:
Expected result: The report identifies the volume as a data/removable drive and shows details including Conversion Status, Percentage Encrypted, Encryption Method, Protection Status, Lock Status, and Key Protectors. For a completed, connected drive, look for encryption at 100% and protection enabled. - Test the unlock process safely.
Close files stored on the USB drive. In File Explorer, right-click the drive and select Eject, then unplug it. Reconnect the drive.
Expected result: Windows shows the drive as locked or prompts you to enter its BitLocker password when you try to open it. Enter the password and select Unlock.
If you are using the drive only on this trusted PC, Windows may offer Automatically unlock on this PC after you unlock it. Enable this only if the PC itself is protected with a strong sign-in method and is not shared with untrusted users. Do not enable automatic unlock on a shared, public, or temporary computer.
Alternate method: Enable BitLocker from an elevated command line
The File Explorer wizard is the best beginner method because it guides you through password and recovery-key storage. The command line is useful when the context-menu option is unavailable but BitLocker is installed and allowed by policy.
- Connect the drive and confirm its letter in File Explorer > This PC.
- Open Windows Terminal (Admin).
- Run the following command, replacing
E:with the correct removable-drive letter:
manage-bde -on E: -pw - Enter and confirm a password when prompted.
- Immediately check the drive’s status:
manage-bde -status E:
For most users, return to Control Panel > System and Security > BitLocker Drive Encryption afterward to confirm protection and back up the recovery key. Do not rely on a password alone; a recovery method is essential if the password is forgotten.
Troubleshooting and rollback
“Turn on BitLocker” is missing
First, confirm the Windows edition:
- Windows 11: Settings > System > About > Windows specifications > Edition
- Windows 10: Settings > System > About > Windows specifications > Edition
If the PC runs Windows Home, the BitLocker To Go creation controls may not be available. Use a supported Pro, Enterprise, or Education PC to encrypt the drive, or use an alternative encryption product approved for your needs.
If this is a work or school device, BitLocker may also be controlled by policy. An administrator can prevent users from applying BitLocker protection to removable drives, require a specific password policy, force recovery-key escrow, or prohibit certain USB devices. Contact the organization’s IT administrator rather than attempting to bypass policy.
The USB drive is read-only or BitLocker cannot start
Check whether Windows reports the drive as read-only, has an active hardware write-protect switch, or is affected by a corporate removable-storage policy.
- Safely eject and reconnect the drive.
- Try a different USB port; avoid a passive hub during encryption.
- Ensure no files on the drive are open.
- If the drive contains needed data, copy it elsewhere before considering a reformat.
Warning: Formatting removes all data on the USB drive. Do not format it as a BitLocker troubleshooting step unless you have verified backups and intend to erase the drive.
If the drive is failing, disconnecting intermittently, or reporting file-system errors, replace it after copying recoverable files. Encryption cannot make an unreliable drive dependable.
The password option is unavailable or rejected
A work or school policy may require a smart card, enforce a password length or complexity rule, or prohibit password protectors for removable drives. Use the available approved method or contact IT.
On an unmanaged PC, retry with a stronger password that meets the requirements shown by the wizard. Do not weaken security merely to make the password easier to remember; use a password manager or securely stored recovery key instead.
Encryption is taking a long time or appears stuck
Large drives and Encrypt entire drive take significantly longer than encrypting used space only. Leave the drive connected and check progress with:
manage-bde -status E:
If the percentage continues to change over time, encryption is still running. Avoid sleep and do not remove the drive.
If progress does not change, Windows reports disk errors, or the USB connection repeatedly drops, copy any accessible files to another location and test the drive on a different port or computer. A failing flash drive or cable is a common cause of interrupted encryption.
You forgot the password
Use the 48-digit recovery password you saved during setup. When Windows displays the BitLocker recovery prompt, match the recovery-key identifier shown on screen to the identifier on your stored recovery key, then enter the corresponding 48-digit recovery password.
If the recovery key was backed up by your workplace or school, contact its IT support team. If you have neither the password nor a valid recovery key, the encrypted data cannot be recovered through a Windows reset, password reset, or drive reformat. Formatting can make the drive usable again, but it permanently destroys the encrypted files.
The drive will not open on another Windows computer
Connect it directly, wait for Windows to recognize it, then open the drive in File Explorer and enter the BitLocker password. If the computer is older, use a compatible encryption mode when creating the drive in the future.
If the destination PC is running Windows Home, it can commonly unlock an existing BitLocker To Go drive but cannot provide full BitLocker management. If it cannot unlock the drive, use a supported and fully updated Windows system, then copy needed files after unlocking.
Roll back: remove BitLocker encryption from the USB drive
Warning: Turning off BitLocker decrypts the drive and leaves its contents unprotected. Keep the drive connected until decryption finishes, and do not use this process as a substitute for securely erasing sensitive data.
- Unlock the USB drive with its password or recovery key.
- Open Control Panel > System and Security > BitLocker Drive Encryption.
- Under BitLocker To Go, find the drive and select Turn off BitLocker.
- Confirm Turn off BitLocker when prompted.
- Leave the drive connected until decryption completes.
- Run the following command to verify the rollback, replacing
E:as needed:
manage-bde -status E:
Expected result: Conversion Status shows fully decrypted and Protection Status indicates BitLocker is off.