Configuration options

Setting

Description

Initial Encryption
  • Encrypt entire drive - Recommended for computers that are in production and already have user data, such as documents and emails.
  • Encrypt used disk space only - Encrypts only the data. Recommended for fresh Windows installations.
Drives to encrypt
  • All drives - Encrypt all drives and volumes.
  • OS drive only - Encrypt only the OS drive (usually, C:\). This is the default.
Encryption algorithm
  • Windows Default - This is recommended. On Windows 10 or later, unencrypted disks are encrypted with XTS-AES-128. On encrypted disks, the encryption algorithm is not changed.
  • XTS-AES-128
  • XTS-AES-256
Note:

To take control of a BitLocker-encrypted device, the target device must have a Trusted Platform Module (TPM) module installed.