How to Tell if BitLocker Is Enabled on Windows 11

BitLocker encrypts your drive so your files can’t be read if your PC is lost or stolen. Many Windows 11 PCs turn on encryption automatically when you sign in with a Microsoft account, so it may already be on without you knowing. It’s important to know, because if BitLocker is on and something changes (like a BIOS update or a new motherboard), you may need your recovery key. This guide shows five quick ways to check whether BitLocker or device encryption is enabled.

Quick Answer

Open an administrator Terminal and run manage-bde -status. If Protection Status says Protection On and Conversion Status says Fully Encrypted, BitLocker is enabled. You can also look for a padlock on the drive icon in File Explorer, or check Settings > Privacy & security > Device encryption.

Administrator terminal running manage-bde -status with the C drive showing Fully Encrypted, Protection On, highlighted
manage-bde -status shows whether a drive is encrypted and protected.

Method 1: Command Line (Most Reliable)

  1. Right-click Start and choose Terminal (Admin), then click Yes.
  2. Type manage-bde -status and press Enter. Add a drive letter (manage-bde -status C:) to check one drive.
  3. Check each drive:
    • Fully Encrypted and Protection On: BitLocker is enabled and protecting the drive.
    • Fully Encrypted and Protection Off: encrypted but suspended (for example during an update), or waiting for activation.
    • Fully Decrypted: BitLocker is off.

In PowerShell, Get-BitLockerVolume shows the same information in a table.

Method 2: Settings (Windows 11 Home and Pro)

  • Home edition: go to Settings > Privacy & security > Device encryption. If the switch is On, your drive is encrypted. If you don’t see this page, your PC doesn’t support device encryption.
  • Pro, Enterprise, Education: the same page may show a link to BitLocker drive encryption; click it to see each drive’s status.

Method 3: Control Panel (Pro and Higher)

Open Control Panel > System and Security > BitLocker Drive Encryption. Each drive shows BitLocker on or BitLocker off, with options to suspend, back up the recovery key, or turn it off.

Method 4: File Explorer

Open File Explorer > This PC. An encrypted, unlocked drive shows a small padlock (open or closed) on its icon on many PCs. Right-click the drive; if you see Manage BitLocker, it’s available. The icon is a quick hint, but the command line is more reliable.

Method 5: System Information

Press Windows key + R, type msinfo32, and look at Device Encryption Support on the System Summary page to see whether your PC supports automatic device encryption.

If BitLocker Is On: Back Up Your Recovery Key

  • If you use a Microsoft account, the key is usually saved at your Microsoft account’s recovery key page. See how to find your BitLocker recovery key.
  • In Control Panel, click Back up your recovery key to save it to a file, USB drive or print it.
  • Suspend protection (Suspend protection in Control Panel, or manage-bde -protectors -disable C:) before BIOS updates or hardware changes to avoid being asked for the key.

Frequently Asked Questions

Does BitLocker slow down my PC?

On modern PCs with hardware encryption support, the impact is minimal for everyday use.

Why is my drive encrypted if I never turned BitLocker on?

Windows 11 turns on device encryption automatically on many PCs when you set them up with a Microsoft account.

How do I turn BitLocker off?

In Control Panel’s BitLocker page, click Turn off BitLocker, or on Home, turn off Device encryption in Settings. Decryption takes a while; keep the PC plugged in.

Summary

  1. Run manage-bde -status as administrator.
  2. Or check Settings > Privacy & security > Device encryption.
  3. Pro users can check Control Panel > BitLocker Drive Encryption.
  4. Back up your recovery key if encryption is on.