Skip to content

Is BitLocker actually on for our laptops?

BitLocker is disk encryption. Without it, someone can unscrew the laptop and read the disk. Not always on by default, even in 2026.

Try this first

  1. 1Per laptop: press Windows key, type 'Manage BitLocker'. See 'BitLocker on' for C: drive? You are done.
  2. 2For central check: Microsoft Intune > Devices > Endpoint security > Disk encryption. Or Entra > Devices > BitLocker keys.
  3. 3Not on? Click 'Turn on BitLocker'. Generates a recovery key, automatically stored in Entra if the laptop is joined there.
  4. 4Disk gets noticeably slower during initial encryption. Do not plan this on a busy workday.
  5. 5For laptops without TPM (older models): this is a real security downgrade. Without TPM you have to enable 'Allow BitLocker without compatible TPM' via Group Policy or Intune, and BitLocker then requires either a USB startup key or a passphrase at every boot. Workable, but the pre-boot factor is mandatory and you lose TPM protection against offline brute-force. For production hardware, replace with a device that has TPM 2.0.

When to bring us in

Whole fleet to BitLocker at once via Intune or GPO? Do not do it solo. One config error and you lock users out. We roll this out in phases with recovery key backup.

See also

None of the above fits?

Describe your situation below. We pass your input plus the steps you already saw to our AI and return tailored next-step advice. If it's too risky to DIY, we'll say so.

Who are you?

For the AI question we need your email and company, so we can follow up if the AI gets stuck, and to prevent abuse.

Limited to 2 questions per hour and 5 per day, kept lean so the AI stays useful. For more, contacting us directly works better for you and us.

Or skip the DIY entirely

Our Managed IT clients do not look these things up. One point of contact, a fixed monthly price, resolved within working hours.