Skip to content Skip to footer

BitLocker Drive Encryption Instructions

This guide provides step-by-step instructions on how to enable the BitLocker feature on Windows operating systems, as well as how to require a PIN upon computer startup.

Enabling BitLocker

  1. Click Start.
  2. Search for and select Control Panel.
  3. Select System and Security.
  4. Go to BitLocker Drive Encryption, and then click Turn on BitLocker.

Selecting full disk encryption

  1. In the encryption method selection window, select the Encrypt entire drive (Fully Encrypted) option.

Recovery key

  1. Select where to save the recovery key. We recommend the Print the recovery key option. The printout should be stored in a secure location, inaccessible to unauthorised individuals.

Requirement to enter PIN after turning on the computer

Run Edit Group Policy

  • Click Start.
  • Search for the Edit group policy (Group Policy Editor) option.
  • In the opened window, navigate to: Computer ConfigurationAdministrative TemplatesWindows ComponentsBitLocker Drive EncryptionOperating System DrivesRequire additional authentication at startup, and enable this option.

Configure TPM Startup PIN

  • In the option selected above, change Configure TPM startup key and PIN to Allow startup key and PIN with TPM.

In the same view, select and enable the Allow enhanced PINs for startup option.


Setting a PIN code

  • Set a PIN for the drive. The PIN should meet the requirements described in the Passwords and Password Managers document. The password can be set from the Start menu → Command Prompt (right-click the icon and select Run as administrator) using the following command: manage-bde -protectors -add C: -TPMAndPIN

Stopka