Windows 10 - Enable BitLocker Encryption without TPM
This guide describes how to enable the built-in BitLocker on Windows without TPM .
1.) Start - Run / Search - mmc.exe
- - - - - -
2.) File - Add / Remove Snap-ins - Add Group Policy Object Editor
- - - - - -
3.) Computer Configuration - Administrative Templates - Windows Components - Drive Encryption Using BitLocker - Operating System Drives
- - - - - -
4.) Require additional authentication at startup - Modify - Enabled and checked Enable BitLocker without a compatible chip
- - - - - -
5.) Control Panel - BitLocker Drive Encryption - Turn on BitLocker
PS: Windows 7 only allows encryption using a USB flash drive, newer versions of Windows allow it without it. The solution is to use eg WeraCrypt on W7.
Tip: You can only lock an unlocked D drive using
manage-bde -lock d:
Error - BitLocker cannot be turned on
When you try to encrypt drive C, the following error may occur after restart:
The specified data unit is not set to unlock automatically on this computer and cannot be unlocked automatically.
Drive C: not encrypted.
The solution is to set BitLocker encryption again and uncheck the system check (at restart) at the end.