-
Knowing how to encrypt a hard drive on Windows is one of the most important security steps a computer user can take. Without encryption, anyone who gains physical access to your computer — or its storage drive — can read every file on it, regardless of your Windows login password. A thief who steals a laptop can remove the hard drive, connect it to another computer, and access everything on it in minutes if the drive is not encrypted. Learning how to encrypt a hard drive makes this scenario impossible: an encrypted drive without the correct password or recovery key contains nothing but unreadable data. This guide covers how to encrypt a hard drive on Windows 10 and 11 using both BitLocker (built-in to Windows Pro) and VeraCrypt (free, open source, works on all Windows editions), with step-by-step instructions and guidance on recovery key management. For a broader walkthrough, our Complete Guide to Windows Software is a good next read.
Before starting the process of how to encrypt a hard drive, back up your important data. While encryption rarely causes data loss when the process completes successfully, a power failure or hardware fault during encryption could leave a partially encrypted drive in an unusable state. A current backup means that even in the worst case, your data is recoverable. Our guide on the best backup software for Windows covers the tools for creating this safety net before you begin.
How to Encrypt a Hard Drive Using BitLocker (Windows Pro and Enterprise)
BitLocker is Microsoft’s built-in full disk encryption — available on Windows 10 and 11 Pro, Enterprise, and Education editions. It encrypts the entire Windows drive, integrates with the device’s TPM chip for transparent decryption at startup, and is the simplest way to encrypt a hard drive for most Windows Pro users. Here is how to encrypt a hard drive with BitLocker:
- Open File Explorer and right-click the drive you want to encrypt (usually C: for the system drive)
- Select Turn on BitLocker. If this option does not appear, your Windows edition does not include BitLocker — use VeraCrypt instead (instructions below)
- BitLocker will ask how you want to unlock the drive at startup. The default option — TPM only — decrypts automatically on each startup using the device’s TPM chip, requiring no password. This is the most convenient but provides weaker protection if the TPM can be extracted. For stronger protection, select TPM + PIN to require a PIN at every startup in addition to the TPM
- Save your recovery key — this step is critical. BitLocker presents several options: Save to Microsoft account, Save to a file, Save to a USB drive, or Print. Choose at least one option — ideally saving to your Microsoft account for easy recovery AND printing a physical copy stored separately from the device. Losing the recovery key without a backup means permanent data loss if the TPM fails or Windows needs to be reinstalled
- Choose whether to encrypt used disk space only (faster, appropriate for new drives) or entire drive (slower but more thorough, appropriate for drives with existing data)
- Select New encryption mode (XTS-AES 128-bit) for fixed internal drives — this is the most secure and most performant option for encrypting a hard drive on Windows 10/11
- Click Start encrypting. For a system drive, BitLocker will ask for a restart to begin encryption. Encryption runs in the background during normal use and may take from 30 minutes to several hours depending on drive size and data amount
After BitLocker encryption completes, the drive is fully encrypted. The process is transparent in daily use — you will not notice any difference unless the TPM configuration is changed or the drive is moved to another machine, at which point the recovery key is required.
How to Encrypt a Hard Drive Using BitLocker on USB Drives (BitLocker To Go)
BitLocker also encrypts USB drives and external hard drives through a feature called BitLocker To Go. This is one of the most important applications of how to encrypt a hard drive for users who carry sensitive data on portable storage. Here is how to encrypt a hard drive (USB or external) with BitLocker To Go: If you only need to lock down a single folder rather than a whole drive, our guide to password-protecting a folder in Windows covers the lighter-weight options.
- Insert the USB drive and open File Explorer
- Right-click the USB drive and select Turn on BitLocker
- Choose Use a password to unlock this drive and enter a strong password — this password will be required on any computer that opens the encrypted drive
- Save the recovery key as described above
- Choose the encryption mode — for USB drives used on multiple PCs, select Compatible mode rather than New encryption mode, as this ensures the encrypted drive can be unlocked on older Windows versions
- Click Start encrypting
The encrypted USB drive can be unlocked on any Windows computer by entering the password. On Windows 10/11 machines, the encrypted drive icon in File Explorer shows a padlock, and the drive prompts for the password when accessed.
How to Encrypt a Hard Drive Using VeraCrypt (All Windows Editions)
VeraCrypt is the best option for encrypting a hard drive on Windows Home edition (which lacks BitLocker), for users who want open-source encryption whose code is publicly auditable, and for creating encrypted containers that can be stored in cloud storage. Here is how to encrypt a hard drive with VeraCrypt:
- Download VeraCrypt from the official VeraCrypt website and install it
- Open VeraCrypt and click Create Volume
- For full system drive encryption: select Encrypt the system partition or entire system drive, click Next, select Normal, choose whether to encrypt the Windows system partition or the entire drive, and click Next
- Select Single-boot if this PC boots only Windows; select Multi-boot if it has multiple operating systems
- Accept the default AES encryption algorithm — it provides excellent security and good performance for encrypting a hard drive on modern hardware
- Set a strong password — this will be required at every startup before Windows loads. Choose a memorable but strong passphrase of at least 20 characters
- VeraCrypt will ask you to move your mouse randomly to generate encryption keys — continue until the bar is full
- Create the Rescue Disk — VeraCrypt requires a rescue disk (ISO file) that can decrypt the drive if the VeraCrypt bootloader is damaged. Save this ISO and optionally burn it to a USB drive. Do not skip this step
- Run the pre-encryption test — VeraCrypt restarts to verify the bootloader works before encrypting. Enter your password at the VeraCrypt boot screen
- After successful test boot, VeraCrypt begins encryption. This runs in the background and can take hours for large drives
How to Encrypt a Hard Drive: Recovery Key Management
The most critical aspect of how to encrypt a hard drive safely — beyond the technical steps — is managing the recovery key or password. If you lose access to the encryption credential and have no recovery key, the encrypted data is permanently unrecoverable. No tool, no support team, and no technical expertise can decrypt a properly encrypted drive without the correct key. Follow these practices:
- BitLocker: Store the recovery key in at least two locations — your Microsoft account AND a printed copy kept somewhere physically secure and separate from the device
- VeraCrypt: Store the rescue disk image and your password in a secure password manager. Print the passphrase and store it securely offline
- Test recovery before you need it — verify you can actually access the recovery key from your stored location before relying on it
- Update stored credentials if you ever change the encryption password
Our guide on the best encryption software for Windows covers VeraCrypt and BitLocker in the broader context of Windows data protection tools, and our article on the best password manager covers the tools for storing encryption passwords and recovery keys securely.
Encrypting a Hard Drive on Windows: BitLocker and Beyond
Learn how to encrypt a hard drive on Windows using BitLocker and VeraCrypt — with step-by-step instructions for full disk encryption, USB drive encryption, and how to recover access if something goes wrong.






