Device Encryption isn't new, and I've known about it for years. What I never did was check what my own PCs were doing with it. Microsoft switched this on across a huge slice of modern hardware without a dialog box, which means a recovery key exists for millions who have never gone looking for one. So I went looking for mine.
Windows 11 turned on encryption without asking me first
Automatic encryption isn't a recent addition to Windows 11, and Home has supported Device Encryption for years. What changed with version 24H2 and was carried into 25H2 is how many PCs qualify. Older builds only encrypted PCs that passed a strict hardware test, ruling out most desktops and many laptops. Microsoft then dropped the Modern Standby and HSTI checks along with the untrusted DMA test.
Popular Now: Noctua measured over 100 PC cases and found Corsair, NZXT, and Lian Li cooler clearance spec sheets are often wrongWhat's left is simple enough. Your PC needs a TPM, UEFI Secure Boot switched on, and Platform Secure Boot enabled. Sign in with a Microsoft account during setup, and Windows starts encrypting in the background, then uploads the recovery key to that account. However, if you use a local account instead, none of this happens on its own.
There's one exception most coverage skips, though. The new behavior shows up on clean installs, reinstalls, and new PCs going through setup for the first time. If you moved to 24H2 or 25H2 through Windows Update, Windows didn't switch encryption on behind your back, although an OEM may have already done it before the PC reached you.
So the PCs catching people out aren't the ones that just gained the feature. They're ordinary Home desktops that never used to qualify and suddenly do.


Best Deals: SanDisk Ultra Flair USB 3.0 Flash Drive
Prices last scanned 0 minutes ago
7 days ago: $17.42 USD
7 days ago: $18.29 USD
7 days ago: $31.69 CAD
7 days ago: £14.59
Checking takes about a minute, and there are three ways to do it
So where do you stand? The fastest check is Settings > Privacy & security > Device encryption. If the toggle sits at On, your system drive is encrypted. If the page doesn't exist, your hardware never qualified, and you can stop reading here.
I prefer the second method because it covers every drive rather than just the boot volume. Head to Settings > System > Storage > Disks & volumes under Advanced storage settings, select a volume, and open Properties. Encrypted volumes say so under BitLocker. That matters for 25H2, where a clean install can eventually pull in attached NTFS drives too.
Our Latest TweakTown Guides
- I swapped File Explorer for this free file manager and finally got the layout I wanted
- How to tell if someone has been using your Windows PC without your permission
- 6 Task Manager tips for troubleshooting Windows performance problems
- Six File Explorer tips every Windows user should know
- I switched my PC to encrypted DNS in Windows 11, and browsing felt more private


The third way tells you the most. Open Terminal as administrator and run manage-bde -status C:, which reports the conversion status, the encryption method, and whether protection is on. Fully encrypted with protection off is a real state, and not the same as being protected.

Frequently Asked Questions
TweakBot answers common questions about this guide using TweakTown's own coverage from this page and related content from our archive. All answers are generated from TweakTown content and not outside sources. Tap a question to reveal the answer, or type your own below related to this content.
How can I quickly check in Windows 11 whether my system drive is encrypted?
Where does Windows 11 upload the 48‑digit recovery key when Device Encryption is enabled?
What steps let me back up the recovery key on Windows 11 Home and Pro?
How can I tell if a volume beyond the boot drive is encrypted in Windows 11 25H2?
Have a question about this content not listed here? Ask below and TweakBot will answer it.

One naming quirk trips up nearly everyone. Home calls this Device Encryption; Pro calls it BitLocker Drive Encryption, and the underlying technology is identical.
A key you can only reach from the locked PC isn't a backup
Once I confirmed the drive was encrypted, the obvious question followed. Where did the key go? Microsoft stores it at account.microsoft.com/devices/recoverykey, and every entry lists a device name, a key ID, and the 48-digit key itself. Mine sat in an account I sign into maybe twice a year.

The list can get confusing because the OS volume and any fixed data volumes each get their own key, and old PCs linger there for years. The recovery screen shows a key ID at the top, so match the first eight characters against the list to find the right one. An empty page usually means you used a local account, someone else signed in with their account during setup, or the hardware didn't meet the requirements.
Here's where the whole arrangement falls apart, though. The key is on a website, and the PC you'd use to open it is the one refusing to boot.
On Pro, fixing that takes two minutes. Open Control Panel, go to BitLocker Drive Encryption, and click Back up your recovery key, then save it to a USB flash drive, a text file on a separate drive, or a printout.

Home doesn't get that panel, and the BitLocker link on the Settings page mostly tries to sell you a Pro upgrade. Search Control Panel for Device encryption instead, which opens the same Back up your recovery key wizard. Failing that, run manage-bde -protectors -get C: in PowerShell as administrator and copy the numerical password it prints.
If you lose a key, it's gone for good because Microsoft support can't regenerate it. Anyone holding a copy can also decrypt the drive, so keep yours away from the PC it belongs to and treat it like a spare house key.
Firmware updates lock people out more often than thieves do
What worries me here isn't theft. It's a routine BIOS update. Device Encryption ties the key to your boot state through the TPM, so anything that alters that state looks like tampering. Flashing firmware, switching Secure Boot off for a Linux install, clearing the TPM, swapping a motherboard, or moving the drive to another PC will all trigger it.
That last one is personal. I clone SSDs between PCs rather than reinstalling, and an encrypted drive dropped into new hardware immediately asks for the key.
The answer is to suspend protection instead of decrypting. Run manage-bde -protectors -disable C: -RebootCount 1 before you flash anything. The drive stays encrypted, Windows parks the key so the next boot passes without a prompt, and protection resumes afterward. If you're using Pro, you get the same result by clicking Suspend protection in that control panel.


Back the key up first, suspend second, flash third. Microsoft's own updates in October 2025 and April 2026 pushed some PCs into the recovery screen with no hardware change, so the copy matters either way.
The next PC worth checking probably isn't yours
Five minutes per PC scales badly across a household, and that's the part I'd act on. Every PC you've set up for a parent or a partner has a key sitting in someone's account, or in nobody's. Work through those next, then watch the drive itself, because your SSD might be telling you it's about to die long before the recovery screen ever appears.





