Clear, practical technology insights BSOD Code Lookup · Windows Error Code Lookup · Wi-Fi Troubleshooting · PC Troubleshooting Checklist

How to Encrypt a USB Drive with BitLocker To Go

Encrypt a removable USB drive, choose a secure password, back up the BitLocker recovery key, test access, and decrypt it safely.

Table of Contents

BitLocker To Go encrypts a removable USB drive so its files cannot be opened without an unlock password, recovery key, or organization-approved method. It protects data if the drive is lost, but it does not replace backups or malware scanning. Before starting, copy important files elsewhere and prepare a safe location for the 48-digit recovery key.

Encrypt your USB drive using BitLocker on Windows. Picture 1

Requirements and compatibility

  • Turning on BitLocker manually requires Windows Pro, Enterprise, or Education. Windows Home can generally unlock an existing BitLocker To Go drive but does not provide the full management interface.
  • A work or school PC may enforce organization-specific encryption and recovery policies. Contact IT before encrypting removable media.
  • Devices that do not support BitLocker may not be able to read the encrypted drive.
  • Keep the USB connected and the computer powered during encryption.

Microsoft's current steps are documented in BitLocker Drive Encryption.

Encrypt a USB drive with BitLocker To Go

1. Open Manage BitLocker

Connect the USB drive. Open Start, type BitLocker, and select Manage BitLocker. You can also open Control Panel > System and Security > BitLocker Drive Encryption.

Encrypt your USB drive using BitLocker on Windows. Picture 2

2. Turn on BitLocker for the correct drive

Under Removable data drives – BitLocker To Go, locate the USB by its drive letter and label. Verify both before clicking Turn on BitLocker.

Encrypt your USB drive using BitLocker on Windows. Picture 3

3. Choose an unlock method

Select Use a password to unlock the drive unless your organization provides a smart card or another required method. Create a long, unique password that you can store in a password manager.

Encrypt your USB drive using BitLocker on Windows. Picture 4

Do not reuse your Windows sign-in password, and do not write the password on the USB drive.

4. Back up the recovery key

Save the 48-digit recovery key to your Microsoft account, a separate file location, or a printout as offered by the wizard. Do not store the only copy on the USB being encrypted or in the same bag as the drive.

Encrypt your USB drive using BitLocker on Windows. Picture 5

Microsoft cannot recreate a lost BitLocker recovery key. Its recovery-key backup guide recommends keeping more than one secure copy.

5. Choose how much of the drive to encrypt

  • Encrypt used disk space only: faster for a new or empty USB drive.
  • Encrypt entire drive: better for a drive that has previously stored files, because deleted space may still contain recoverable data.

Choose the compatibility mode presented for removable drives if you need to use the USB with older supported Windows systems. The exact wizard wording depends on your Windows version and organization policy.

6. Start encryption

Review the choices and click Start encrypting. Wait until Windows reports completion before ejecting the USB.

Encrypt your USB drive using BitLocker on Windows. Picture 6

Test the encrypted drive

  1. Use Safely Remove Hardware to eject the USB.
  2. Reconnect it.
  3. Confirm that Windows asks for the password.
  4. Open a noncritical file and verify that it is intact.
  5. From another device, confirm that you can retrieve the recovery key without relying on the encrypted USB.

Unlock and lock the USB

When you connect the drive, open File Explorer, select it, and enter the password. The drive remains unlocked for the current Windows session. Ejecting it locks it again.

Use Automatically unlock on this PC only on a trusted personal computer. Anyone with access to that Windows account may then be able to open the drive without re-entering its password.

Change the password or back up the key again

Open Manage BitLocker, expand the removable drive, and select the appropriate action to change the password or back up the recovery key. Make a new recovery-key backup after any management change and label it with the key ID, not just the USB name.

Decrypt the drive

To remove encryption, back up the files, open Manage BitLocker, select Turn off BitLocker for the USB, and confirm decryption. Keep the drive connected until it finishes.

What BitLocker does not protect against

  • Malware running while the drive is unlocked
  • Accidental deletion or drive failure
  • Someone who knows the password or obtains the recovery key
  • Files copied elsewhere before encryption

Keep a separate backup and scan removable media. TipsMake also explains how to find a BitLocker recovery key, unlocking a BitLocker drive from Command Prompt, and recovering access to a removable drive. For a different control, see how to block writing to USB drives.

Use conservative language about security

No encryption makes data “absolutely secure.” BitLocker significantly reduces the risk of offline access when the password and recovery key are protected, Windows is maintained, and the drive is locked before it leaves your control.

Discussion

Reader Comments 0

Sign in with email or Google to join the discussion.