How to Lock Local Disk in Windows 10: A Step-by-Step Guide

If by “lock a disk” you mean protect its contents from someone who does not have the key, use BitLocker or Device Encryption where supported. Hiding a drive letter or changing permissions is not equivalent to encrypting the data.

Check whether BitLocker is available

Search Windows for Manage BitLocker. BitLocker management is available on supported Windows editions; some devices use Device Encryption instead.

Turn on encryption for the intended drive

Select the correct fixed or removable drive and choose the option to enable BitLocker. Choose an approved unlock method and follow the encryption wizard.

Save the recovery key safely

Store the recovery key somewhere separate from the encrypted disk, such as the appropriate Microsoft/work account or another secure location. Losing both the unlock credential and recovery key can make the data inaccessible.

Know what encryption protects

BitLocker protects data at rest, especially if a drive is removed or the computer is stolen. It does not prevent an already signed-in authorized user or malware running in that session from accessing unlocked files.

Do not use obscure “folder lock” utilities as a substitute for supported encryption. Windows 10 standard support ended in 2025, so migrate compatible systems while preserving encryption recovery information.

Locking an unlocked BitLocker drive

Removable/data drives can be locked again by disconnecting them safely or using supported BitLocker management commands. The Windows system drive normally remains unlocked while Windows is running because the operating system needs continuous access to it.

Back up before encrypting

Encryption is not a backup. A failing disk can still lose encrypted files, so keep an independent copy of important data before enabling encryption on an older drive.