BitLocker-Header

This is a step by step guide for those who want to enable bitlocker on their main Windows c drive and also want to enable the BitLocker screen when booting up their machine.

Prerequisites:
For this you’ll need to have a TPM version of 1.2 or later.

Applies to:

  • Windows 10
  • Windows Server 2016
  • Windows Server 2019

Implementation

  1. Open mmc.exe
  2. File > Add/Remove snap in
  3. Add into the selected snap-ins the “Local Computer Policy”
  4. Expand > Computer Configuration
  5. Administrative Templates
  6. Windows Components
  7. BitLocker Drive Encryption
  8. Operating System Drives

Double click on “Require additional authentication at startup” and enable it
Untick the “Allow BitLocker without a compatible TPM (requires a password or a startup key on a USB flash drive)

Double click on “Allow enhanced PINs for startup” and enable it.

mmc

You can now close the mmc console without having to save it.
Type in bitlocker on the Windows magnifier icon (bottom left hand side on tasbar).
Click on Manage BitLocker.
Tun BitLocker on.

turn-bitlocker-on

Enter a PIN (recommended)

enter-pin

Type in your BitLocker Password and select “Set PIN”

type-pin

Choose how you want to back up your recover key

backup

I would select the first option and one of the other two options or all. You can do all of them.

The recovery will come in handy in case you do a BIOS/UEFI update as it will detect a change and only once after the update, it will prompt for the recovery key.

how-much-to-encrypt

If this a fixed main drive that you use to load your Windows then select the first option. New encryption mode (best for fixed drives on this device)

encryption-mode

ready-to-encrypt

Restart your machine

restart

Now you will see the initial BitLocker screen prompting for the BitLocker password.

bitlocker-screen

After logging back in, BitLocker will still be in progress but won’t take long if you’re on an SSD drive.

Click on your hidden icons at the bottom left hand side of your taskbar. Double click on the BitLocker icon.

hidden-icons

encrypting1

References: