Windows 11 Encryption Guide — EFS, BitLocker & Device Encryption Explained

Windows 11 has three native encryption paths that look similar in Settings but protect different things. This guide explains which one your edition supports, how to use it safely, and when a dedicated file encryption tool makes more sense.

Windows Encryption Desk Editorial TeamUpdated July 18, 202622 minute read
Quick answer

Device Encryption is the simplest whole-device option and can appear on supported Windows 11 Home PCs. BitLocker Drive Encryption adds full volume controls on Pro, Enterprise, and Education. EFS encrypts selected NTFS files for a Windows user account and is not available on Home. Back up the recovery key or EFS certificate before making firmware, account, drive, or Windows changes.

Windows 11 encryption guide covering EFS BitLocker and Device Encryption
Direct answers

Enable, disable, or suspend BitLocker without guessing

To enable BitLocker: on Windows 11 Pro, Enterprise, or Education, search for Manage BitLocker, choose Turn on BitLocker, select an unlock method, back up the recovery key, choose used-space-only or full-drive encryption, and start.

To disable BitLocker: open Manage BitLocker, choose Turn off BitLocker, and confirm decryption. Leave the PC connected to power and do not interrupt the process.

To suspend BitLocker: choose Suspend protection before an expected BIOS, UEFI, TPM, or firmware change. Suspension keeps data encrypted but temporarily allows the expected boot change without repeated recovery prompts.

Recovery-first rule: verify the 48-digit recovery key before disabling protectors, clearing a TPM, updating firmware, reinstalling Windows, formatting a drive, or changing boot settings.
Definition

How Windows 11 Encryption — EFS, BitLocker & Device Encryption Protects Your Data

Encryption converts readable data into ciphertext using a cryptographic key. In Windows 11, the key can be released at boot by the Trusted Platform Module, after a password or PIN, or after the correct Windows user signs in with access to an EFS certificate.

Data at rest
Files stored on an internal drive, external disk, USB drive, or local encrypted locker. BitLocker, Device Encryption, and EFS mainly address this state.
Data in transit
Information moving over a network. Windows disk encryption does not replace HTTPS, TLS, VPN encryption, encrypted email, or secure file-sharing controls.
Authentication is not encryption
A Windows password, hidden folder, or permission can block casual access while the data remains readable outside that environment. Encryption adds a cryptographic barrier.
Illustration explaining how encryption protects readable files with cryptographic keys
My situation is

Choose the protection that matches the risk

I may lose the laptop

Use Device Encryption or BitLocker so the internal drive is unreadable when removed or booted offline. This is the main full-disk encryption scenario.

Check edition support →

I share a Windows PC

EFS can separate selected files between Windows accounts on supported editions. A dedicated encrypted locker is easier when you want a separate password or portable vault.

Compare file-level options →

I carry files on USB

Use BitLocker To Go on supported editions or a portable encrypted locker. Test the drive on every computer where authorized users must open it.

Protect a removable drive →
Disk encryption software protecting a Windows laptop and stored data
Edition compatibility

Windows 11 Home vs Pro encryption differences

The feature name matters less than the edition, hardware support, account type, and management controls available on the PC.

FeatureWindows 11 HomeProEnterprise / EducationBest use
Device EncryptionAvailable on supported devicesAvailable on supported devicesAvailableSimple automatic protection for the OS and fixed drives
Manage BitLockerNot includedIncludedIncluded with policy controlsFull volume management, removable drives, recovery options
EFS file encryptionNot availableAvailableAvailable with enterprise recovery policySelected NTFS files tied to a Windows user certificate
BitLocker To GoCannot enable nativelyCan enableCan enable and manageUSB and removable-drive encryption
Dedicated encryption softwareAvailableAvailableCheck organizational policyFolder-level password protection, portable lockers, cloud workflows
Windows compatibility illustration for encryption features across supported devices

TPM 2.0 and Secure Boot

Windows 11 normally requires TPM 2.0, and modern Device Encryption relies on compatible hardware and firmware. Full BitLocker can also use TPM protectors, startup PINs, or a startup key under the right policy.

EFS certificate backup

EFS does not use the BitLocker recovery key. Export the EFS certificate and private key to a protected backup. Reinstalling Windows or losing the profile can make files unreadable.

Complete methods guide

Windows 11 BitLocker

01

Windows 11 Device Encryption vs BitLocker

Easy5 minutesWhole device

Device Encryption is a simplified BitLocker experience that can automatically protect the operating system drive and fixed drives on compatible Windows 11 hardware. It is designed for people who want encryption without managing every BitLocker policy.

  1. Open Settings and select Privacy & security.
  2. Select Device encryption. If it is missing, run System Information as administrator and check Device Encryption Support.
  3. Turn Device Encryption on and sign in with a Microsoft, work, or school account so the recovery key can be attached to the account.
  4. Verify the recovery key from a second device.
Best for
Everyday laptops, especially supported Home devices.
Limitations
Fewer controls than full BitLocker and dependent on hardware support.
02

How to Enable BitLocker Encryption in Windows 11

Moderate10 minutes setupPro or higher

BitLocker protects an entire volume against offline access. It is the native choice for system drives, fixed data drives, virtual hard disks, and removable drives when you need recovery-key and policy controls.

  1. Search for Manage BitLocker and open it.
  2. Choose Turn on BitLocker beside the drive.
  3. Select a protector such as TPM, PIN, password for data drives, or startup key where supported.
  4. Back up the recovery key before continuing.
  5. Choose used-space-only for a new drive or full encryption for a drive that has held sensitive data.
  6. Start encryption and verify the status after completion.
Windows File Explorer view used when managing encrypted drives and folders
Best for
Lost-device protection, managed PCs, internal and removable volumes.
Limitations
It does not create a separate password-protected folder inside an already unlocked Windows session.
03

Windows 11 EFS

Windows 11 EFS encrypt folder step by step

ModeratePro or higherFile level

EFS encrypts selected NTFS files using a certificate linked to the Windows account. It is useful for separating files between users on the same PC, but it is not a simple folder password and it is easy to lose access after profile or system changes.

  1. Right-click the file or folder and select Properties.
  2. Select Advanced.
  3. Check Encrypt contents to secure data, then apply the change.
  4. Choose whether to encrypt the folder only or its contents.
  5. Immediately export the EFS certificate and private key when Windows prompts you.
  6. Store the exported certificate and password away from the encrypted drive.
Windows folder encryption interface for securing selected files and folders
Windows 11 Home: the Encrypt contents to secure data option is not available. Do not use registry edits or service changes as a substitute for an unsupported edition.
04

BitLocker To Go for USB drives

ModeratePortable drivePro or higher to enable

BitLocker To Go encrypts removable drives. Choose a strong password, save the recovery key somewhere separate, and test the drive on the exact Windows editions used by recipients.

  1. Connect the USB drive and open Manage BitLocker.
  2. Select Turn on BitLocker beside the removable drive.
  3. Choose a password or smart card and back up the recovery key.
  4. Select the encryption scope and compatible mode based on where the drive will be used.
  5. Wait for completion before ejecting.
05

Windows 11 encrypt folder with password: EFS, BitLocker, 7-Zip, or an encrypted locker?

VariesFolder levelAll editions

Windows does not provide a native “set a separate password on this folder” command. EFS ties access to a Windows certificate, BitLocker protects a drive, and 7-Zip creates encrypted archives. Dedicated encryption software can create a password-protected locker that behaves more like a working folder.

Use 7-Zip for files you archive and send occasionally. Use a dedicated locker for files you open and update often, or when Windows Home lacks EFS and full BitLocker controls.

Best for
Separate passwords, working folders, portable encrypted containers, cloud-sync workflows.
Limitations
Requires software installation, careful password backup, and compatibility testing.
Interactive tools

Windows 11 Encryption Lab

Use these tools to narrow the right method, check compatibility, estimate performance, and build a recovery-safe setup.

Encryption type selector

Search-intent selector

Choose what you are trying to do.

Home vs Pro at a glance

Capability
Home
Pro
Enterprise
Education
Device Encryption on supported hardware
Yes
Yes
Yes
Yes
Full Manage BitLocker
No
Yes
Yes
Yes
EFS
No
Yes
Yes
Yes
BitLocker To Go enablement
No
Yes
Yes
Yes

TPM 2.0 checker

Device and platform compatibility

Verify encryption status with Windows commands

These commands show status. They do not unlock, bypass, or remove protection.

manage-bde -status
manage-bde -protectors -get C:
cipher /c "C:\path\to\file.ext"

Encryption algorithm selector

Encryption strength visualizer

Strong algorithm, but recovery and password practices still need work.

AES-256 explainer

AES transforms blocks of plaintext through repeated key-dependent rounds. This simplified animation shows the concept, not the actual cipher math.

Quarterly payroll.xlsx
7F A2 1C 90 4B...

Algorithm and tool comparison matrix

Method
Scope
Typical cipher
Separate password
Best fit
BitLocker
Volume
XTS-AES 128/256
Optional by drive type
Windows device theft
EFS
Files
Windows-managed file encryption
No, user certificate
Multi-user separation
7-Zip
Archive
AES-256
Yes
Send or store snapshots
Encrypted locker
Working folders
AES-256 varies by product
Yes
Frequent access and cloud sync

Performance impact calculator

AES-128 vs AES-256 performance

Modern CPUs often accelerate both, so storage speed and initial encryption volume dominate. XTS-AES 256 can have a small throughput cost, but the difference is workload and hardware dependent.

  • New SSD: used-space-only is the quickest setup.
  • Old HDD: full-drive encryption can take hours.
  • Heavy databases and virtual machines: benchmark the real workload.
  • Battery-powered laptops: connect power for initial encryption.

Encrypted vs unencrypted storage benchmark guide

Measure sequential and random reads and writes before and after enabling encryption, with the same power plan, thermal state, free space, and background workload. A synthetic benchmark is useful, but application launch time, file copy, virtual machine startup, and database latency are more meaningful.

Troubleshooting flowchart: cannot access encrypted data

Do you own or administer the device and data?

Recovery source checklist

  • Microsoft account recovery-key page
  • Work or school account / IT escrow
  • Printed BitLocker key
  • Saved text file or USB copy
  • EFS .pfx certificate export
  • Password manager or license email
  • Known-good unencrypted backup

Actions to avoid

  • Do not clear the TPM before verifying the key.
  • Do not format a drive that contains needed data.
  • Do not reinstall Windows before recovering EFS certificates.
  • Do not use “bypass” tools on devices you do not own.
  • Do not store the only recovery copy on the encrypted drive.

Encryption risk score quiz

Encryption concepts test

1. Which protects an entire volume?
2. Which backup is essential for EFS?
3. Does encryption replace backups?

Windows 11 encryption checklist

0 of 8 completed

At a glance

Windows 11 Encrypt Folder EFS Vs BitLocker Vs 7-zip

MethodDifficultySecurity scopeCostBest forLimitations
Device EncryptionEasyOS and fixed drivesIncluded on supported devicesSimple lost-device protectionHardware dependent, fewer controls
BitLockerModerateFull volumeIncluded with Pro or higherInternal, data, VHD, and removable drivesNot a separate folder password
EFSModerateSelected NTFS filesIncluded with Pro or higherWindows user separationCertificate loss can be permanent
7-Zip AES-256 archiveModerateArchive contentsFreeSending or storing file snapshotsAwkward for files edited frequently; metadata settings matter
VeraCrypt containerAdvancedVolume or containerFree and open sourcePortable containers and advanced usersManual mounting, recovery and update discipline
Folder Lock 10Easy to moderateEncrypted lockers and protected foldersFree tier; paid ProSeparate password, frequent use, cloud-sync lockersThird-party software and subscription for full features
Editorial verdictUse BitLocker or Device Encryption for the whole PC. Add EFS only when you understand certificate recovery. Use an archive for occasional transfer, or a dedicated locker for an actively used password-protected folder.
Comparison illustration for Windows encryption software and data protection methods
Technical explainer

How Modern Encryption Algorithms Work

Symmetric vs Asymmetric Encryption — What You Need to Know

Symmetric encryption uses one secret key for encryption and decryption. It is efficient for disks and large files, which is why AES is common. Asymmetric encryption uses a public and private key pair and is useful for exchanging keys, digital signatures, or sharing access with specific people.

AES-256 and Windows 11 Encryption — What You Need to Know

BitLocker supports XTS-AES 128 and 256, plus compatible CBC modes. Automatic encryption commonly defaults to XTS-AES 128. AES-256 expands the key size, but a well-managed 128-bit key is already extremely resistant to brute force. Recovery, password quality, endpoint security, and backups remain decisive.

BitLocker AES-128 vs AES-256 performance difference

On modern hardware the difference is often small, but it is not universal. XTS-AES 256 can reduce maximum throughput on some systems. Measure your own storage workload before setting an organization-wide policy.

Hardware vs Software Encryption — Performance Tradeoffs

Hardware encryption can offload work to a self-encrypting drive, but security depends on the drive implementation and management chain. Software encryption is easier to standardize and audit across mixed hardware. Modern CPUs with AES acceleration usually make software encryption practical.

How encryption handles file names and metadata

Full-volume encryption protects names and metadata while the volume is locked. EFS encrypts file contents, but names, paths, sizes, timestamps, and access patterns may remain visible. Archive tools vary, so enable filename encryption where available.

Plausible deniability and hidden volumes

Some container tools support hidden volumes designed to make a second encrypted area difficult to prove. This is an advanced feature with complex operational risks. Overwriting free space, using the wrong volume, backups, thumbnails, and recent-file records can undermine the intended privacy.

Encryption software explainer showing protected files and secure access
Business requirements

Encryption Compliance Requirements for Businesses

Encryption can support HIPAA, GDPR, PCI DSS, and SOC 2 controls, but no encryption product makes an organization compliant by itself. The control must match the data, risk assessment, access model, incident process, retention policy, backups, and key-management evidence.

HIPAA

For electronic protected health information, document the risk analysis and why the selected encryption and access controls are reasonable for the environment. Protect keys separately from the encrypted data and preserve availability through tested backups.

GDPR

Article 32 identifies encryption as an appropriate measure depending on risk. Organizations still need access control, resilience, restoration, testing, breach response, and processor governance.

PCI DSS

Strong cryptography can render stored cardholder data unreadable, but encryption alone does not automatically remove systems from PCI scope. Key access, rotation, separation of duties, logging, and the surrounding environment matter.

SOC 2

Auditors look for controls that are designed, implemented, and operating. Record who owns keys, where recovery copies are stored, how access is approved and removed, and how restoration is tested.

Compliance note: use legal, security, and audit professionals for requirements that apply to your organization. This guide is technical education, not legal advice.
Best practices

Key management and backup strategies

Separate keys from encrypted data

Do not keep the only recovery key on the same PC or encrypted volume. Use a Microsoft account, authorized organizational escrow, password manager, protected USB, secure print copy, or another controlled repository.

Use more than one recovery path

Maintain at least two controlled copies in different failure domains. A cloud account and a printed copy, or IT escrow and a protected offline copy, are more resilient than two files on the same drive.

Back up before BIOS or TPM changes

Verify the recovery key and suspend BitLocker protection before expected firmware work. Re-enable protection afterward and confirm that protectors are active.

Test, do not assume

Record the key ID, locate the matching recovery key from another device, test certificate import on a safe copy, and perform a documented file restore. An untested backup is only a hope.

Backup encryption platforms protecting recovery copies across devices and cloud storage
The tool we recommend for most folder-level needs

A separate encrypted workspace without upgrading Windows editions

Folder Lock 10 is most useful when the protection boundary is smaller than the computer itself. It creates an encrypted workspace for selected records while Device Encryption or BitLocker continues to secure the Windows volume underneath it.

On Windows 11, you can keep a local locker on the PC, place encrypted data inside supported Dropbox, Google Drive, or OneDrive locations, or prepare a portable locker for removable storage. The local workspace expands as content is added, so there is less need to predict a fixed container size at the start.

Its sharing workflow is more controlled than sending an encrypted attachment with the password beside it. Authorized recipients use compatible Folder Lock software and their own permitted access. That can suit ongoing collaboration, but it also makes the process dependent on every participant having the required application and account access.

It is not a substitute for full-disk encryption, centralized endpoint management, or a tested backup plan. Only data placed inside the protected workspace receives locker encryption, cloud availability still depends on the chosen provider, and a lost encryption secret can leave the data unavailable. Keep Windows drive encryption enabled, retain an independent copy of important files, and confirm which capabilities require Pro before deployment.

Local and cloud lockersSeparate access boundaryPortable workflowsCross-device clients
LockersSafeguardSecretsCloud

My encrypted lockers

Business Records
Desktop lockerLocked
OneDrive Archive
Cloud lockerSynced
Portable Project
USB lockerReady
Folder Lock 10 main Windows application dashboard
Reference feature map

What a dedicated encrypted locker adds

1

Expandable local workspace

A Desktop Locker grows with the protected content instead of asking you to reserve a large fixed volume in advance.

2

Encrypted cloud locations

Dedicated locker choices place ciphertext inside supported Dropbox, Google Drive, or OneDrive folders.

3

Controlled collaboration

Approved users can receive access without everyone sharing the owner's master secret, provided they use compatible software.

4

Portable locker workflow

Selected data can travel in an encrypted container on removable media rather than exposing the whole drive.

5

Optional access restriction

The Windows Safeguard tools can hide or block selected items when encryption is unnecessary for that particular folder.

6

Cross-device continuity

Compatible desktop and mobile clients can open synchronized encrypted data, although available features vary by platform.

7

Private information vaults

Separate areas can organize confidential notes, account details, and other small records away from ordinary documents.

8

Deletion and privacy tools

File shredding, free-space cleanup, and Windows history cleanup address traces that encryption alone does not remove.

9

Free-to-Pro path

The no-cost edition supports a limited trial workflow, while larger lockers, broader syncing, sharing, and portable options require Pro.

10

Recovery stays with you

The software does not remove the need for password records, offline backups, restore tests, and a plan for account loss.

Folder Lock 10 Desktop Locker screen for local encrypted file storage
Step by step

How to encrypt files on Windows 11 using Folder Lock 10

  1. Install the official Windows build

    Download from NewSoftwares.net, scan the installer, and confirm that Windows displays the expected publisher before allowing changes to the PC.

  2. Create the account and master secret carefully

    Use a unique passphrase, verify the recovery email, and save the credential record somewhere that is not inside the locker you are about to create.

  3. Choose where encrypted data should live

    Select a Desktop Locker for local records or the matching cloud locker when encrypted files must synchronize through Dropbox, Google Drive, or OneDrive.

  4. Begin with a small test set

    Add copies of several representative files, open and edit them from the mounted workspace, then close the locker and confirm that the stored form is not directly usable outside it.

  5. Configure collaboration only when required

    For shared projects, authorize the intended recipient and confirm that the other person can use a compatible Folder Lock client. Do not send your master password as the access method.

  6. Close the workspace when work ends

    Lock the locker before stepping away and lock the Windows session as well. Device Encryption or BitLocker should remain active for protection while the computer is powered down.

  7. Test recovery on a safe copy

    Maintain an independent backup of irreplaceable files, record the installer and account details, and verify that you can reopen synchronized or portable data from another authorized device.

Technical details

Choosing the Right Encryption Software for Your Needs

A locker protects content that has been moved or created inside its managed workspace. Unencrypted originals, exports, email attachments, application caches, and temporary copies outside that boundary need separate handling.

Use a local locker when data should remain on the Windows PC. Choose a provider-specific cloud locker when encrypted data must travel through Dropbox, Google Drive, or OneDrive. The cloud provider still controls account availability, sync timing, version history, and storage quotas.

Product-managed sharing can grant an approved user access without disclosing the owner's main password. The recipient still needs a compatible client and working account access, so test the complete workflow before using it for a deadline-sensitive transfer.

Folder Lock clients exist for Windows, macOS, Android, and iPhone or iPad, but the feature set is not identical everywhere. Windows includes the broadest desktop protection tools, while mobile editions focus more on private media, documents, notes, wallets, app-level privacy, and secure transfer features. Treat cross-device access as continuity, not perfect feature parity.

The free edition is useful for confirming compatibility and learning the workflow, but its storage and device limits make it unsuitable for many production collections. Pro adds the capacity, sharing, folder-protection, and portable options that active users are more likely to need. Confirm the current matrix before purchase.

Check whether previews, thumbnails, recent-file lists, search indexing, autosave folders, print spools, and exported copies can leave readable traces outside the protected location. Encryption software cannot protect a duplicate that another application saved elsewhere.

Smart App Control helps block untrusted or malicious applications on eligible Windows 11 installations. It does not encrypt folders. Use it alongside encryption, Microsoft Defender, updates, and least-privilege accounts.

Check recent releases, signed downloads, audit reports, maintainer responsiveness, issue history, documentation, and whether the format can be recovered without a proprietary service.

Software comparison

Alternative to BitLocker for Windows 11 Home

OptionWindows 11 HomeWorking folderFull diskPortableBest for
Device EncryptionSupported hardware onlyNo separate folderOS and fixed drivesNoSimple whole-device protection
7-ZipYesArchive workflowNoYesOccasional transfer and storage
VeraCryptYesMounted containerSystem support depends on configurationYesAdvanced users seeking open-source containers
Folder Lock 10YesEncrypted lockerNot a BitLocker replacementPro includes portable lockersFrequently used data that needs a separate password or cloud-sync workflow
Bottom lineOn Home, keep Device Encryption enabled when supported. Add an encrypted archive for occasional use or a dedicated locker for files you work with frequently.
Folder Protect Windows interface for controlling folder access and modification

Folder Lock 10, Folder Protect, and Folder Lock Lite compared

These names describe different protection models. Choosing the wrong one can leave a gap between what the user expects and what the software actually secures.

ProductPrimary controlEncryptionUseful Windows 11 scenarioMain limitation
Folder Lock 10Encrypted lockers plus optional folder access controlsAES-256 for locker dataActive documents that need a password separate from Windows, cloud synchronization, or a portable containerDoes not encrypt the Windows system volume; recipients need compatible software for managed sharing
Folder ProtectRules that can hide an item or restrict opening, editing, and deletionNo cryptographic file encryptionShared PCs where the goal is to control how local users interact with selected files, folders, drives, programs, or file typesAccess restriction is not protection against offline disk access or physical drive theft
Folder Lock LiteBasic lock-and-hide workflowNo encryption capabilityLegacy users who only need simple visibility and access restrictionsShould not be selected when the requirement is confidential data at rest
Pricing reference

Folder Lock 10 Pricing: What You Get

Free version

$0

The free edition is best treated as a compatibility and workflow test rather than a complete long-term deployment.

  • Up to 1 GB of locker capacity
  • Synchronization on up to two devices
  • Mobile clients and private-information tools included
  • File shredding and Windows history cleanup available
  • No managed sharing, portable lockers, or Protect Folders capability
Download free version →
Folder Lock 10 Pro software boxshot for Windows file encryption

Free and Pro capability summary

CapabilityFreeProPlanning note
Locker capacity1 GBUnlimited in the product matrixCloud-provider and local-disk quotas still apply
Synced devices25Test every authorized device before depending on it
Shared usersNot includedListed as unlimitedRecipients require compatible Folder Lock access
Portable lockersNot includedIncludedUse a separate backup because removable media can fail
Folder access controlsNot includedIncludedThese controls complement encryption; they do not replace drive protection
Shredding and history cleanupIncludedIncludedReview exclusions carefully before destructive deletion

The product material reviewed for this page listed Folder Lock 10 Pro at US$39.95. Confirm the current billing term, renewal conditions, taxes, regional pricing, and feature limits at checkout.

Common errors and fixes

Windows 11 encryption troubleshooting

ProblemLikely causeSafe fix
Device Encryption is missingUnsupported hardware, standard account, local-account setup, or support condition not metRun System Information as administrator and read Device Encryption Support. Confirm edition and administrator status.
“Encrypt contents to secure data” is unavailableWindows 11 Home, non-NTFS location, policy restriction, or unsupported file stateConfirm the edition and NTFS volume. On Home, use a supported alternative instead of registry workarounds.
A valid USB key was not detected by BitLockerStartup-key policy, USB port availability before boot, incompatible media, or firmware settingsTry another known-good USB drive and port, confirm preboot USB support, and review authorized policy. Do not clear TPM protectors.
BitLocker asks for recovery after BIOS updateMeasured boot values changedUse the matching 48-digit recovery key. After Windows starts, verify firmware, then resume or reset protectors only if you administer the device.
This drive is locked by BitLockerAuto-unlock unavailable, password forgotten, protector changed, or drive movedUse the password, smart card, or matching recovery key. Check the key ID before entering a key.
After entering the recovery key, the prompt returnsUnresolved firmware, Secure Boot, boot order, or protector issueStart Windows with the key, correct the verified boot issue, update firmware carefully, and recreate protectors only after backing up the key.
EFS files are unreadable after reinstallThe original certificate and private key are missingImport the exported .pfx certificate, restore the original profile backup, or contact authorized organizational recovery support. A BitLocker key does not replace the EFS certificate.
Need to format a BitLocker driveDrive is being repurposed or data is no longer requiredRecover needed files first. Then unlock and format. If the data is not needed and you own the drive, formatting erases the encrypted volume.
Cannot remove BitLocker before selling a PCDecryption incomplete or Windows is not bootableBack up files and recovery key. Use Reset this PC with drive cleaning or a verified secure erase process appropriate to the drive and ownership.
Illustrative reader cases

How the choices play out in real work

A consultant with a Windows 11 Home laptop

Device Encryption stays enabled for lost-device protection. A separate encrypted locker holds client contracts because Home lacks EFS and full BitLocker management.

Illustrative scenario, not a customer endorsement.

A small clinic using Windows 11 Pro

BitLocker protects every laptop, recovery keys are escrowed, and a restricted encrypted folder holds exported reports. Access, backups, and audit logs remain separate compliance controls.

Illustrative scenario, not legal advice.

A designer carrying projects on USB

BitLocker To Go works when all recipients use compatible Windows systems. A portable encrypted locker is chosen when a separate password and self-contained workflow are more practical.

Illustrative scenario, not a customer endorsement.

A developer using virtual machines

XTS-AES 128 is retained after benchmarking shows little practical gain from changing the policy. Recovery keys are verified before every firmware update.

Illustrative scenario, not a performance guarantee.
Decision guide

Which method or tool is right for you?

User or situationRecommended methodWhyHonest alternative
Windows 11 Home laptop ownerDevice Encryption when supportedNative and automatic whole-device protectionDedicated locker for separate folder passwords
Pro user protecting the system driveBitLockerNative recovery and volume controlsDevice Encryption for a simpler configuration
Two users sharing one Pro PCBitLocker plus EFS for selected filesOffline volume protection plus user separationSeparate encrypted locker with its own password
Occasional encrypted file transferAES-256 archivePortable and easy to sendBitLocker To Go for a whole USB drive
Frequently edited cloud filesEncrypted cloud lockerEncrypted form syncs while files remain workableManual archive snapshots for infrequent changes
Enterprise-managed fleetBitLocker with centralized policy and escrowConsistent deployment, recovery, and auditabilityApproved file-level controls for high-risk datasets
Common questions

Windows 11 encryption FAQ

What is Windows 11 encryption?

Windows 11 encryption is a group of protections for data at rest. Device Encryption and BitLocker protect whole volumes, while EFS protects selected files and folders for a Windows user account.

How do Windows 11 EFS, BitLocker, and Device Encryption work?

Device Encryption is the simplified automatic form of BitLocker available on supported hardware, including some Home devices. Full BitLocker management is available in Pro, Enterprise, and Education. EFS encrypts individual files with a certificate linked to the user account.

Is Windows 11 encryption safe?

Yes, when it is configured correctly and the recovery material is backed up. The most common failure is not weak encryption but losing a recovery key, EFS certificate, password, or access to the account that holds it.

Does Windows 11 Home have BitLocker encryption?

Windows 11 Home can include Device Encryption on compatible hardware, but it does not include the full Manage BitLocker experience. Full BitLocker Drive Encryption management is available in Pro, Enterprise, and Education.

Does Windows 11 Home support EFS?

No. Microsoft states that built-in file and folder encryption is not available in the Home edition. EFS requires Windows 11 Pro, Enterprise, or Education.

How do I enable BitLocker encryption in Windows 11?

On Windows 11 Pro, Enterprise, or Education, search for Manage BitLocker, choose Turn on BitLocker for the drive, select an unlock method, back up the recovery key, choose an encryption scope, and start encryption.

How do I disable BitLocker encryption in Windows 11?

Open Manage BitLocker, choose Turn off BitLocker for the drive, and confirm decryption. Keep the device powered and do not interrupt the process. For a temporary firmware change, suspend protection instead of decrypting the whole drive.

Can I pause BitLocker encryption and remove a drive?

You can pause an active encryption or decryption process, but do not disconnect a removable drive until Windows shows that it is safe. Suspending protection is different: it temporarily stops boot measurements from triggering recovery while data stays encrypted.

Can I format a BitLocker-encrypted drive?

Yes, if you own the drive and accept that formatting erases its data. Unlock it first when possible, copy anything needed, then format it through Disk Management or File Explorer. Formatting is not a recovery method for files you still need.

Can I reinstall Windows if BitLocker is enabled?

Yes, but a clean installation can erase encrypted data. Back up the recovery key and files before reinstalling. If you need data from the existing installation, recover or unlock it first.

What is AES-256 and why is it widely used?

AES-256 is the Advanced Encryption Standard with a 256-bit key. It is widely trusted because it has a large key space, broad hardware acceleration, and extensive security review. Correct key handling still matters more than selecting the largest key alone.

Does encryption slow down a Windows 11 PC significantly?

On a modern CPU and SSD with hardware acceleration, day-to-day impact is usually modest. Initial encryption, large file transfers, older CPUs, and slow hard drives show the biggest difference.

Can encrypted files be decrypted without the key?

Properly encrypted data is not realistically recoverable by guessing a strong key. Recovery usually depends on a saved BitLocker recovery key, an EFS certificate, a password backup, an authorized organizational escrow, or an unencrypted backup.

Is open-source encryption software trustworthy?

It can be, but open source is not a guarantee. Review the project's maintenance, audit history, update process, cryptographic design, download verification, and recovery model before relying on it.

How does full-disk encryption differ from file-level encryption?

Full-disk encryption protects an entire volume when the device is off or locked at boot. File-level encryption protects selected files and can separate access between users, but it usually reveals more metadata and needs separate key or certificate management.

How should I encrypt files for cloud storage?

Encrypt the files locally before they enter the sync folder, keep the password or key outside the cloud account, test restoration, and retain a second backup. A cloud-synced encrypted locker is easier to manage than manually encrypting every upload.

What happens if I forget the password or lose the recovery key?

You may permanently lose access. Check your Microsoft account, work or school account, printed copy, saved key file, USB backup, password manager, EFS certificate export, and authorized IT support before changing or formatting anything.

How do Folder Lock 10, Folder Protect, and Folder Lock Lite differ?

Folder Lock 10 creates encrypted lockers and also includes optional access-control tools. Folder Protect focuses on restricting visibility, access, modification, or deletion without encrypting the file contents. Folder Lock Lite is a basic lock-and-hide edition and should not be treated as encryption software.

More on this topic

In-depth answers and official references

How to encrypt a hard drive before selling a computer

Back up the files and recovery key, then use Windows Reset with the drive-cleaning option or a verified secure erase process appropriate for the SSD or HDD. Encryption helps because destroying the remaining key can make residual ciphertext unusable, but verify the reset and remove the device from organizational management.

Best encryption software for protecting sensitive business files

Start with BitLocker for every supported Windows 11 business device. Add file-level controls only for a defined need: EFS with certificate recovery, approved encrypted archives for transfer, or an audited locker for active shared workflows. Central policy, key escrow, updates, logs, and restore testing matter more than a feature count.

Best encryption software for cloud storage

Choose a tool that encrypts locally before upload, supports the actual sync provider, handles file conflicts safely, and has a documented recovery process. Keep keys outside the cloud account and test restoration after a sync conflict or deleted-file recovery.

Email encryption software for small business

Disk encryption does not secure a message after it leaves the PC. Use a business email platform with TLS, identity controls, phishing protection, and message-level encryption for sensitive exchanges. For attachments, encrypt the file locally and send the password through a separate channel.

Samsung Portable SSD T7 encryption software

Decide whether to use the drive vendor's security software, BitLocker To Go, or a portable encrypted container. Avoid stacking multiple full-drive encryption layers unless the vendor supports it. Keep the unlock software and recovery information available on a separate device.

Our verdict

Use layers, and protect the recovery path

For most Windows 11 PCs, the first priority is whole-device encryption. Keep Device Encryption enabled on supported Home hardware, or use full BitLocker on Pro, Enterprise, and Education. Add EFS only when you can manage certificates and recovery correctly.

When the requirement is an actively used folder with its own password, Folder Lock 10 offers a clearer workflow than trying to turn BitLocker or EFS into a folder-password tool. Its strongest fit is selected business or personal data that must remain workable locally, synchronize in encrypted form through a supported cloud provider, or travel in a portable locker.

That recommendation has boundaries. Folder Lock does not protect the Windows boot volume, Folder Protect and Folder Lock Lite are not encryption substitutes, shared recipients need compatible access, and the useful Pro capabilities go beyond the free edition. The safest design combines drive encryption, a protected workspace only where needed, independent backups, and tested recovery records.