Jump to content
  • Microsoft is enabling BitLocker device encryption by default on Windows 11


    Karlston

    • 449 views
    • 3 minutes
     Share


    • 449 views
    • 3 minutes

    Clean installs of Windows 11 version 24H2 now have BitLocker device encryption enabled.

    Microsoft is making BitLocker device encryption a default feature in its next major update to Windows 11. If you clean install the 24H2 version that’s rolling out in the coming months, device encryption will be enabled by default when you first sign in or set up a device with a Microsoft account or work / school account.

     

    Device encryption is designed to improve the security of Windows machines by automatically enabling BitLocker encryption on the Windows install drive and backing up the recovery key to a Microsoft account or Entra ID.

     

    In Windows 11 version 24H2, Microsoft is reducing the hardware requirements for automatic device encryption, opening it up to many more devices — including ones running the Home version of Windows 11. Device encryption no longer requires Hardware Security Test Interface (HSTI) or Modern Standby, and encryption will also be enabled even if untrusted direct memory access (DMA) buses / interfaces are detected.

     

    b24f4c93_09b5_4efa_acd7_7c1a864db047.png

    The new device encryption setting in Windows 11, version 24H2.

    Image: Microsoft

     

    The latest Windows 11 version 24H2 update comes preinstalled on Microsoft’s range of Copilot Plus PCs and is expected to be available on existing machines in late September. That means if you clean install Windows 11 later this year or buy a new PC with 24H2 installed, BitLocker device encryption will be enabled by default. If you just upgrade to 24H2, Microsoft won’t enable device encryption automatically.

     

    The feature could impact SSD performance on some devices. Tom’s Hardware tested this software version of BitLocker last year and found it could slow drives by up to 45 percent. We’ve asked Microsoft repeatedly since early May to comment on BitLocker device encryption being enabled by default, but the company has only confirmed its plans through support documents where there is no mention of any potential performance impacts.

     

    deviceencryption.png

    You’ll need a Microsoft account to enable device encryption.

    Screenshot by Tom Warren / The Verge

     

    You can avoid automatic device encryption if you’re using a local account on a clean Windows 11 version 24H2 install. When you first set up a new machine and log in with a local account, you’ll be prompted to sign in with a Microsoft account to finish encrypting the device. BitLocker can still be manually enabled using the BitLocker Control Panel on local accounts, though. You can also disable device encryption through a toggle in the privacy and security section of Windows 11’s settings interface.

     

    Microsoft set out to improve security in Windows 11 in a meaningful way by requiring modern processors, Secure Boot, and TPM (Trusted Platform Module) chips. These requirements, while controversial, allowed Microsoft to also enable its virtualized Memory Integrity feature by default two years ago to better protect Windows 11 systems from malicious code.

     

    Source

     

    Hope you enjoyed this news post.

    Thank you for appreciating my time and effort posting news every single day for many years.

    2023: Over 5,800 news posts | 2024 (till end of July): 3,313 news posts

    • Thanks 1

    User Feedback

    Recommended Comments

    There are no comments to display.



    Join the conversation

    You can post now and register later. If you have an account, sign in now to post with your account.
    Note: Your post will require moderator approval before it will be visible.

    Guest
    Add a comment...

    ×   Pasted as rich text.   Paste as plain text instead

      Only 75 emoji are allowed.

    ×   Your link has been automatically embedded.   Display as a link instead

    ×   Your previous content has been restored.   Clear editor

    ×   You cannot paste images directly. Upload or insert images from URL.


  • Recently Browsing   0 members

    • No registered users viewing this page.
×
×
  • Create New...