How to enable full-disk encryption on windows 10

How to enable full-disk encryption on windows 10

Windows 10 sometimes uses encryption by default, and sometimes doesn’t—it’s complicated. Here’s how to check if your Windows 10 PC’s storage is encrypted and how to encrypt it if it isn’t. Encryption isn’t just about stopping the NSA—it’s about protecting your sensitive data in case you ever lose your PC, which is something everyone needs.

Unlike all other modern consumer operating systems—macOS, Chrome OS, iOS, and Android—Windows 10 still doesn’t offer integrated encryption tools to everyone. You may have to pay for the Professional edition of Windows 10 or use a third-party encryption solution.

If Your Computer Supports It: Windows Device Encryption

Many new PCs that ship with Windows 10 will automatically have “Device Encryption” enabled. This feature was first introduced in Windows 8.1, and there are specific hardware requirements for this. Not every PC will have this feature, but some will.

There’s another limitation, too—it only actually encrypts your drive if you sign into Windows with a Microsoft account. Your recovery key is then uploaded to Microsoft’s servers. This will help you recover your files if you ever can’t log into your PC. (This is also why the FBI likely isn’t too worried about this feature, but we’re just recommending encryption as a means to protect your data from laptop thieves here. If you’re worried about the NSA, you may want to use a different encryption solution.)

Device Encryption will also be enabled if you sign into an organization’s domain. For example, you might sign into a domain owned by your employer or school. Your recovery key would then be uploaded to your organization’s domain servers. However, this doesn’t apply to the average person’s PC—only PCs joined to domains.

To check if Device Encryption is enabled, open the Settings app, navigate to System > About, and look for a “Device encryption” setting at the bottom of the About pane. If you don’t see anything about Device Encryption here, your PC doesn’t support Device Encryption and it’s not enabled. If Device Encryption is enabled—or if you can enable it by signing in with a Microsoft account—you’ll see a message saying so here.

How to enable full-disk encryption on windows 10

For Windows Pro Users: BitLocker

If Device Encryption isn’t enabled—or if you want a more powerful encryption solution that can also encrypt removable USB drives, for example—you’ll want to use BitLocker. Microsoft’s BitLocker encryption tool has been part of Windows for several versions now, and it’s generally well regarded. However, Microsoft still restricts BitLocker to Professional, Enterprise, and Education editions of Windows 10.

BitLocker is most secure on a computer that contains Trusted Platform Module (TPM) hardware, which most modern PCs do. You can quickly check whether your PC has TPM hardware from within Windows, or check with your computer’s manufacturer if you’re not sure. If you built your own PC, you may able to add a TPM chip to it. Search for a TPM chip that’s sold as an add-on module. You’ll need one that supports the exact motherboard inside your PC.

Windows normally says BitLocker requires a TPM, but there’s a hidden option that allows you to enable BitLocker without a TPM. You’ll have to use a USB flash drive as a “startup key” that must be present every boot if you enable this option.

If you already have a Professional edition of Windows 10 installed on your PC, you can search for “BitLocker” in the Start menu and use the BitLocker control panel to enable it. If you upgraded for free from Windows 7 Professional or Windows 8.1 Professional, you should have Windows 10 Professional.

How to enable full-disk encryption on windows 10

If you don’t have a Professional edition of Windows 10, you can pay $99 to upgrade your Windows 10 Home to Windows 10 Professional. Just open the Settings app, navigate to Update & security > Activation, and click the “Go to Store” button. You’ll gain access to BitLocker and the other features that Windows 10 Professional includes.

Security expert Bruce Schneier also likes a proprietary full-disk encryption tool for Windows named BestCrypt. It’s fully functional on Windows 10 with modern hardware. However, this tool costs $99—the same price as an upgrade to Windows 10 Professional—so upgrading Windows to take advantage of BitLocker may be a better choice.

For Everyone Else: VeraCrypt

Spending another $99 just to encrypt your hard drive for some additional security can be a tough sell when modern Windows PCs often only cost a few hundred bucks in the first place. You don’t have to pay the extra money for encryption, because BitLocker isn’t the only option. BitLocker is the most integrated, well-supported option—but there are other encryption tools you can use.

The venerable TrueCrypt, an open-source full-disk encryption tool that is no longer being developed, has some issues with Windows 10 PCs. It can’t encrypt GPT system partitions and boot them using UEFI, a configuration most Windows 10 PCs use. However, VeraCrypt—an open-source full-disk encryption tool based on the TrueCrypt source code—does support EFI system partition encryption as of versions 1.18a and 1.19.

In other words, VeraCrypt should allow you to encrypt your Windows 10 PC’s system partition for free.

How to enable full-disk encryption on windows 10

TrueCrypt’s developers did famously shut down development and declare TrueCrypt vulnerable and unsafe to use, but the jury is still out on whether this is true. Much of the discussion around this centers on whether the NSA and other security agencies have a way to crack this open-source encryption. If you’re just encrypting your hard drive so thieves can’t access your personal files if they steal your laptop, you don’t have to worry about this. TrueCrypt should be more than secure enough. The VeraCrypt project has also made security improvements, and should potentially be more secure than TrueCrypt. Whether you’re encrypting just a few files or your entire system partition, it’s what we recommend.

We’d like to see Microsoft give more Windows 10 users access to BitLocker—or at least extend Device Encryption so it can be enabled on more PCs. Modern Windows computers should have built-in encryption tools, just like all other modern consumer operating systems do. Windows 10 users shouldn’t have to pay extra or hunt down third-party software to protect their important data if their laptops are ever misplaced or stolen.

One of the key elements of data protection is encryption. Users who regularly back up their files are familiar with the concept since Acronis always recommends to store data in an encrypted form. Doing so protects your data in transit to a local server or to the cloud, and it protects data when it is being stored on different media. If someone gains access to your file – either accidentally or maliciously – that person won’t be able to read it or easily decrypt it if strong encryption algorithms like AES-256 are used.

The same applies to a work machine. Full disk encryption can be enabled by default in your organization, but often it is not since it’s not as critical in a protected office environment. If you’re working remotely, either at a home office or on the road, full disk encryption definitely should be enabled, because the likelihood is much higher that someone can get access to your machine.

Given the number of machines suddenly being used to work from home, we’ve prepared this short post on how to enable full disk encryption on Windows and macOS machines.

How to use Microsoft Bitlocker

BitLocker is a full-volume encryption feature that’s been built into different versions of Microsoft Windows beginning with Windows Vista. It is designed to protect data by providing encryption for entire volumes. By default, it uses the AES encryption algorithm in cipher block chaining (CBC) or XTS mode with a 128-bit or 256-bit key. CBC is not used over the whole disk; it is applied to each individual sector.

To turn on Device Encryption in Windows 10, you need to be logged in to your Microsoft Windows account. The easiest way to launch a BitLocker is just type it in a search window.

How to enable full-disk encryption on windows 10

As every encryption uses an encryption key, full disk encryption on Windows uses some machine or user data as a key for encryption. That key could be your Microsoft account, your Microsoft account password, your computer’s name, or any combination of these in a further encrypted way.

How to enable full-disk encryption on windows 10

Once you got into the main screen for Bitlocker, you need to turn it on. You’ll be asked if you want to back up your security key, which you should do, but on another drive (preferably a USB stick). You can choose whether to encrypt only used space or the whole disk during the next step.

After that, you are basically good to go, although the disk encryption that will take some time.

Full disk encryption for macOS

macOS has its own full disk encryption tool called FileVault. FileVault 2 uses XTS-AES-128 encryption with a 256-bit key, which is pretty similar to its Windows counterpart. FileVault 2 is available in OS X Lion or later.

When FileVault is turned on, your Mac always requires that you log in with your account password.

  1. Choose Apple menu () > System Preferences, then click Security & Privacy.
  2. Click the FileVault tab.
  3. Click , then enter an administrator name and password.
  4. Click Turn On FileVault.

How to enable full-disk encryption on windows 10

You have to choose how you’ll want to unlock your disk or reset your password (if you ever forget your password). Apple recommends the following:

If you’re using OS X Yosemite or later, you can choose to use your iCloud account to unlock your disk and reset your password.

If you’re using OS X Mavericks, you can choose to store a FileVault recovery key with Apple by providing the answers to three security questions. Choose answers that you’ll be sure to remember*.

If you don’t want to use iCloud FileVault for recovery, you can create a local recovery key. Keep the letters and numbers of the key somewhere safe—other than on your encrypted startup disk.

Once initiated, the encryption occurs in the background so you can continue using your Mac. It only runs while your Mac is awake and plugged into AC power. Any new files that you create are automatically encrypted as they are saved to your startup disk.

When the FileVault setup is complete and you restart your Mac, you will use your account password to unlock your disk, allowing your Mac to finish starting up.

How to enable full-disk encryption on windows 10

Most of the Modern operating system like Mac OS X, Android, iOS, and Chrome provide an integrated encryption tool. But windows don’t provide any encryption tool on its operating system. Although, the third party disk encryption is inbuilt feature in windows 10 and updated version of windows 10.

Method 1:

Follow these simple steps to proceed.

Step 1: Go to search and enter “BitLocker.”

Step 2: After search the “BitLocker”, you will see “Manage BitLocker” option. Just click on that.

How to enable full-disk encryption on windows 10

Step 3: It will show “Encrypt Your All Disk.” But, firstly start with “Drive C” where your OS is installed. Encrypt the disk or drive with, click on “Turn On BitLocker.”

How to enable full-disk encryption on windows 10

Step 4: Now, you can also select any other drive to encrypt first as that’s your wish.

Method 2:

Step 1: Search “About” in your search box and you will see “About Your PC.” Just click on that.

How to enable full-disk encryption on windows 10

Step 2: After clicking on “About Your PC,” you will see the about page of computer. At the bottom, you can see “BitLocker Settings.” Just click on “BitLocker Settings” and follow the same steps explained above.

Note: if the “BitLocker settings” is not shown on the “About Your PC” page, then Understand that your PC doesn’t support disk encryption.

Did you find this post helpful? Leave a comment below if you have any related queries with this.

Although Windows 10 doesn’t offer any integrated solution for data encryption hers in this article we tell you the simple steps to enable full disk encryption on your Windows 10 operating system.Full disk encryption in windows 10 helps you to protect your data in case you ever lose your computer.

Most of the modern operating system like Mac OS X, Android, iOS and Chrome provides integrated encryption tool, but windows do not provide such kind of integrated tool on its os for that we have to use some third party tool or pay Microsoft for a professional windows 10 edition.

How to Check Windows 10 Support Device Encryption or Not

Before we go for full disk encryption it is important to check device encryption is enabled or not for our Windows 10 operating system follow the steps.

  • Open start menu in your Windows 10 computer and search About in that menu next click on the About Your PC showing in the search results.
  • After clicking on About your PC, it will take you the about page of your Windows computer and look for BitLocker settings.How to enable full-disk encryption on windows 10

If BitLocker settings option is not available there, this means your Windows 10 computer does not support disk encryption and if this option is available there then follow the next tutorial which tell you about full disk encryption on Windows 10 OS.

How to Enable Full Disk Encryption in Windows 10 Computer Step by Step

First of all, you need to already log in to your Microsoft Windows account to enable the device encryption in Windows 10 machine.

  • Go to Start menu of your Windows 10 computer and enter BitLocker.
  • After that, you will see Manage BitLocker option showing on the search results just click on Manage BitLocker option.
  • Next it will show an option to Encrypt your full disk.Start with the C drive as most of your Operating system data found in this drive and click to encrypt your full disk option on windows 10 computer.How to enable full-disk encryption on windows 10

A lot of SSDs now implement OPAL-compliant AES hardware encryption, which seems to be the only option to get full-disk encryption on modern PCs without buying the (very expensive) Windows 10 Pro edition.

I enabled this encryption with a HDD password in the UEFI, but from what I’ve read, BIOS- or UEFI-based HDD password can be unreliable (and you have no way to know whether your model implements it correctly until you get hacked).

I searched on how to enable OPAL encryption, but this information seems to be inexistent. Every webpage talking about OPAL says that it’s activated by a software, but no one seems to know which software.

I tried the vendor’s SSD managing software (Samsung Magician), but it only says that I need “specialized software”. It seems that Microsoft BitLocker can use this, but as I said, this is only in Windows Pro and the price is incredibly high.

Is there any Windows software capable of activating OPAL hardware encryption ?

1 Answer 1

You ought to be able to find something useful here (binaries and source included by r0m30 on github also).

Up until recently, configuring these TCG Opal drives was only possible under Windows, or under Linux with a commercial solution that was not available to mere end-users. Fortunately, a programmer named r0m30 stepped up to the challenge and has developed an open source utility called msed and an accompanying pre-boot authorization (PBA) image with which the super fast encryption function on these drives can be fully configured and used also in pure Linux systems.

The “pure Linux” system shouldn’t be a problem – the PBA is OS agnostic, it should simply boot whatever is in the active partition once it is unlocked. The OS and the drive will “see” an unencrypted drive without even be aware that the hardware is actually doing decryption on the fly, unless they issue the appropriate API status calls.

Keep in mind that very likely you’ll need to reformat the SSD altogether, since this solution is for booting off an encrypted device and requiring it to boot from a small non-encrypted shadow “partition” for password acquisition purposes.

So you probably will need to:

  • backup your data
  • disable OPAL in the UEFI
  • format disk and install the shadow MBR with OPAL encryption
  • enable OPAL from shadow MBR and insert a new password
  • restore your data (the disk might be slightly smaller).

We all want to keep our data encrypted and secure. But unlike Mac OS X, iOS, android or any other OS, Microsoft doesn’t provide free encryption. Rather, it wants you to pay to get a business grade encryption tool called Windows BitLocker. Microsoft Bitlocker is a encryption software that come pre bundled with Windows 10 pro and higher versions. It offers security features like encrypting your disks, or any other removable drives.

Today we will see how to use it to fully encrypt your disk.

For Encryption key, It uses either your pieces of your personal data from your Microsoft Account or your Microsoft Account password or it could be odd combination of all these data in a further encrypted way.

Before you start any of the steps, you need to be damn sure that you are running Windows 10 Pro or higher version. To verify this right click on the ‘This PC ‘ icon on your desktop and click properties, and see the version mentioned.

Here are the steps on how to enable full encryption in Windows 10:

Step 1:

Go to start and type ‘Bitlocker’ and click on the ‘Manage BitLocker’

How to enable full-disk encryption on windows 10 Starting Bitlocker

Step 2:

Once you click on it, it will show the BitLocker Drive Encryption Window. Based on the number of drives your computer has e.g C,D,E,F, you need to turn it on for those drives.

Or else there is yet another way to do the same.

Step 1: Go to Start > Settings and search for ‘About’ and you will get a result called ‘About your PC’. Click on that

How to enable full-disk encryption on windows 10 Search in settings

Step 2: After Clicking on it, it will take you to to the about page of your computer. At the bottom you will see ‘Bitlocker settings’.

How to enable full-disk encryption on windows 10 About Page

Then it will take you to the main settings window and the rest process is same as earlier

If this option is missing there, then it probably means your PC doesn’t support full Encryption.

TIP: If you don’t have a Windows 10 pro but still you want to try bitlocker for encrypting REMOVABLE drives, then there is method you can follow without pirating windows 10 pro. You need to install VirtualBox or any other virtual machine software. Download Windows 10 Pro using Microsoft recommended link https://www.microsoft.com/en-in/software-download/windows10 and install it on your virtual machine. Then connect your removable drive to the guest OS, and you can encrypt it now using the above method.

Thank you guys for reading, stay tuned for more!

A Engineering grad, who is in love with windows, and loves to write about it!

How to enable full-disk encryption on windows 10

Full-disk encryption in Windows 10 protects your data from prying eyes. It’s easy to implement and invaluable for just about any user, especially those that travel with important data.

What Is Full-Disk Encryption in Windows 10, and Should I Use It?

Full-disk encryption means that without your user password, the data on your hard drive is completely inaccessible. If a disk is not encrypted, it’s possible to remove the disk from your computer, mount it to the attacker’s computer, and access all your files with no restrictions. Encrypted disks don’t suffer from this security hole. Because their data is hopelessly scrambled without the key, it’s totally unintelligible to a key-less attacker.

Should I Use Full-Disk Encryption in Windows 10?

Yes, especially so if you have a laptop or have files you want to keep secure. Desktop computers are less of a security risk since they don’t travel. However, the downsides of full-disk encryption are so few that there isn’t much reason not to. Modern computers are fast enough to handle the computational overhead of encryption without even pausing. The major downside is that if you forget your password and lose your recovery key, your files are toast. It might also limit your ability to use third-party backup solutions, but we haven’t been able to test that ourselves.

Full-Disk Encryption in Windows 10 Using BitLocker

BitLocker is Microsoft’s proprietary disk encryption software for Windows 10. Because it’s designed by a large, for-profit company, and because the U.S. government approached Microsoft about adding a “back door” to its encryption scheme, BitLocker hasn’t enjoyed the greatest reputation. However, well-respected security researcher Bruce Schneier still recommends it, and it’s perfectly adequate for average Windows users. If using software produced by a giant corporation with ambiguous intent and potential backroom dealings with the U.S. government, that’s reasonable. VeraCrypt is a good, open-source option.

1. Locate the hard drive you want to encrypt under “This PC” in Windows Explorer. We’ll be encrypting my boot disk for this tutorial.

How to enable full-disk encryption on windows 10

2. Right-click the target drive and choose “Turn on BitLocker.”

How to enable full-disk encryption on windows 10

3. If you see an error message about needing a “Trusted Platform Module” or TPM, you’ll need to add a Group Policy Exception to allow BitLocker to run anyway. If you don’t see this error message, proceed to step 10.

How to enable full-disk encryption on windows 10

Running BitLocker without a TPM

4. Type gpedit.msc into the Run menu (accessible by the “Win +R” shortcut) and press “Enter” to open the Local Group Policy Editor.

How to enable full-disk encryption on windows 10

How to enable full-disk encryption on windows 10

5. Navigate to “Computer Configuration -> Administrative Templates -> Windows Components -> BitLocker Drive Encryption -> Operating System Drives” in the side bar.

How to enable full-disk encryption on windows 10

6. Double-click on “Require additional authentication at startup” in the main window.

How to enable full-disk encryption on windows 10

7. Click the radio button next to “Enabled.”

How to enable full-disk encryption on windows 10

8. Also make sure that “Allow BitLocker without a compatible TPM” is checked, then click “OK.”

How to enable full-disk encryption on windows 10

9. Finally, we can turn on BitLocker. Right-click the target drive again and choose “Turn on BitLocker.”

How to enable full-disk encryption on windows 10

Finishing the BitLocker Setup

10. Choose “Enter a password.”

How to enable full-disk encryption on windows 10

11. Enter a secure password.

How to enable full-disk encryption on windows 10

12. Choose how to enable your recovery key which you’ll use to access your drive if you lose your password. I like to print mine, but it’s your choice. If you don’t have a printer, you can also save a file to your hard drive, save a file to a USB drive, or save the key to your Microsoft account.

How to enable full-disk encryption on windows 10

13. Choose “Encrypt entire drive,” which is the more-secure option that encrypts files that have been marked for deletion but haven’t yet been overwritten.

How to enable full-disk encryption on windows 10

14. Unless you need your drive to be compatible with older Windows machines, choose “New encryption mode.”

How to enable full-disk encryption on windows 10

15. Click “Start Encrypting” to begin the encryption process. Note that this will require a computer restart if you’re encrypting your boot drive. The encryption will take some time, but it will run in the background, and you’ll still be able to use your computer while it runs.

How to enable full-disk encryption on windows 10

Conclusion

BitLocker is powerful and easy to enable. Turning it on should be a no-brainer for anyone with a portable computer or secure data to protect.

Alexander Fox is a tech and science writer based in Philadelphia, PA with one cat, three Macs and more USB cables than he could ever use.

One of the key elements of data protection is encryption. Users who regularly back up their files are familiar with the concept since Acronis always recommends to store data in an encrypted form. Doing so protects your data in transit to a local server or to the cloud, and it protects data when it is being stored on different media. If someone gains access to your file – either accidentally or maliciously – that person won’t be able to read it or easily decrypt it if strong encryption algorithms like AES-256 are used.

The same applies to a work machine. Full disk encryption can be enabled by default in your organization, but often it is not since it’s not as critical in a protected office environment. If you’re working remotely, either at a home office or on the road, full disk encryption definitely should be enabled, because the likelihood is much higher that someone can get access to your machine.

Given the number of machines suddenly being used to work from home, we’ve prepared this short post on how to enable full disk encryption on Windows and macOS machines.

How to use Microsoft Bitlocker

BitLocker is a full-volume encryption feature that’s been built into different versions of Microsoft Windows beginning with Windows Vista. It is designed to protect data by providing encryption for entire volumes. By default, it uses the AES encryption algorithm in cipher block chaining (CBC) or XTS mode with a 128-bit or 256-bit key. CBC is not used over the whole disk; it is applied to each individual sector.

To turn on Device Encryption in Windows 10, you need to be logged in to your Microsoft Windows account. The easiest way to launch a BitLocker is just type it in a search window.

How to enable full-disk encryption on windows 10

As every encryption uses an encryption key, full disk encryption on Windows uses some machine or user data as a key for encryption. That key could be your Microsoft account, your Microsoft account password, your computer’s name, or any combination of these in a further encrypted way.

How to enable full-disk encryption on windows 10

Once you got into the main screen for Bitlocker, you need to turn it on. You’ll be asked if you want to back up your security key, which you should do, but on another drive (preferably a USB stick). You can choose whether to encrypt only used space or the whole disk during the next step.

After that, you are basically good to go, although the disk encryption that will take some time.

Full disk encryption for macOS

macOS has its own full disk encryption tool called FileVault. FileVault 2 uses XTS-AES-128 encryption with a 256-bit key, which is pretty similar to its Windows counterpart. FileVault 2 is available in OS X Lion or later.

When FileVault is turned on, your Mac always requires that you log in with your account password.

  1. Choose Apple menu () > System Preferences, then click Security & Privacy.
  2. Click the FileVault tab.
  3. Click , then enter an administrator name and password.
  4. Click Turn On FileVault.

How to enable full-disk encryption on windows 10

You have to choose how you’ll want to unlock your disk or reset your password (if you ever forget your password). Apple recommends the following:

If you’re using OS X Yosemite or later, you can choose to use your iCloud account to unlock your disk and reset your password.

If you’re using OS X Mavericks, you can choose to store a FileVault recovery key with Apple by providing the answers to three security questions. Choose answers that you’ll be sure to remember*.

If you don’t want to use iCloud FileVault for recovery, you can create a local recovery key. Keep the letters and numbers of the key somewhere safe—other than on your encrypted startup disk.

Once initiated, the encryption occurs in the background so you can continue using your Mac. It only runs while your Mac is awake and plugged into AC power. Any new files that you create are automatically encrypted as they are saved to your startup disk.

When the FileVault setup is complete and you restart your Mac, you will use your account password to unlock your disk, allowing your Mac to finish starting up.

The Samsung range of SSD drives boast about their hardware level encryption – but what surprises me is that there is so little detail about this feature.

In fact, the more I looked into it I noticed that it’s not even enabled by default and there’s no clear instruction on how to enable it.

Here I hope to clear up some of that mystery and show how to enable the hardware level encryption.

What is the hardware level encryption?

Encryption is the processing of taking data from its standard state and processing it so it is no longer readable without a ‘key’ to unlock it.

Hardware level encryption is where the hardware manages the encryption/decryption process of all data on the drive – this has a significant performance advantages and reduces read/write cycles that ultimately shorten the life of the drive. Without hardware level encryption you can still encrypt the data but performance is typically reduced.

What’s important to note here is that the drive alone does not encrypt the data – it needs to be done along with a software level encryption tool like BitLocker or TrueCrypt.

How can I tell if hardware level encryption is enabled?

  1. Download and install the Samsung Magician software on the computer with the SSD drive.
  2. Open Samsung Magician and select ‘Data Security’ from the left hand menu
  3. Make sure the correct drive is selected under ‘Target Drive’
  4. Under ‘Encrypted Drive’ you will see ‘Disabled’ if it is not already enabled.
  5. How to enable full-disk encryption on windows 10

How to enable hardware level encryption?

Note: this process requires you to erase all existing content on the SSD drive – backup and be prepared to reinstall everything.

To enable hardware level encryption on your Samsung drive you will need to

  1. use the Samsung Magician software to enable it,
  2. create a bootable usb drive
  3. boot the drive with the SSD connected and follow the on screen prompts
  4. re-install Windows
  5. enable BitLocker (required the Professional edition of Windows) or TrueCrypt (or similar third party paid software)

Step 1: Enable encrypted drive

  1. Download and install the Samsung Magician software on the computer with the SSD drive.
  2. Open Samsung Magician and select ‘Data Security’ from the left hand menu
  3. Make sure the correct drive is selected under ‘Target Drive’
  4. Under ‘Encrypted Drive’ click ‘How to enable’
  5. In the pop-up click ‘Ready to enable’
  6. How to enable full-disk encryption on windows 10
  7. The state will change from ‘Disabled’ to ‘Ready to enable’

Step 2: Create bootable media

  1. Now in the left hand menu select ‘Secure Erase’ – you will now need to create a bootable drive, you can do this using a CD/DVD or USB (note that this will erase all existing content from the USB drive).
  2. Using the USB option, insert the USB drive into the computer.
  3. Click ‘Browse’ and select the drive from the list
  4. Click ‘Start’ to start the process
  5. How to enable full-disk encryption on windows 10
  6. When finished it will prompt you to restart the computer.
  7. Restart the computer and boot from the USB drive.

Step 3: SSD Secure Erase

When booted from the USB drive you’ll see the following screen

How to enable full-disk encryption on windows 10

  1. Click ‘Y’ on the keyboard to continue
  2. The software will list the compatible SSD drive connected to the computer
  3. Click ‘Y’ on the keyboard to continue
  4. How to enable full-disk encryption on windows 10
  5. If you see a message which says “the selected drive is in a Frozen state” – you will need to follow the on instructions provided on screen (I’ve had this happen on desktop and laptop computers – it is much more awkward for laptop computers and should be done with extreme caution … you are after all prodding your hands inside a powered computer!)
  6. How to enable full-disk encryption on windows 10
  7. Once completed you will see “Secure Erase is Successful” – the software will exit to DOS – you can now turn off the computer and begin the Windows re-install process.
  8. How to enable full-disk encryption on windows 10

Step 4: Re-install Windows and enable BitLocker

I won’t detail how to re-install Windows, but once this is done this guide will help explain how to enable BitLocker on Windows 10 – Windows 10 – How to encrypt a drive using BitLocker