Microsoft 365 - Getting Started with BitLocker

BitLocker is a Windows security feature that protects your data by encrypting your drives. This encryption ensures that if someone tries to access a disk offline, they won’t be able to read any of its content.

BitLocker is a built-in encryption feature in Windows that helps protect your data by encrypting your entire drive. When you access your data, Windows normally has protections associated with your sign-in information. However, if someone tries to bypass these protections by physically removing the hard drive and connecting it to a second device, they could potentially access your data without needing your credentials.

With BitLocker encryption, when they try to use that method to access the drive, they’ll need to provide a decryption key (which they shouldn’t have) to access anything on the drive. Without the decryption key, the data on the drive appears as gibberish, making it unreadable and secure from unauthorized access.

BitLocker is particularly valuable if your device is lost or stolen, as it keeps your sensitive information secure. It’s designed to be user-friendly and integrates seamlessly with the Windows operating system, making it easy to set up and manage.

BitLocker offers two functionalities

  • Device Encryption, which is designed for simplicity of use, and it's usually enabled automatically
  • BitLocker Drive Encryption, which is designed for advanced scenarios, and it allows you to manually encrypt drives

How was BitLocker activated on my device?

Here are some scenarios that describe how BitLocker might have been activated on your device:

  • Your device automatically enabled Device Encryption: in this case, your BitLocker recovery key is automatically saved to your Microsoft account or work or school account, before protection is activated
  • An administrator on your device manually activated Device Encryption: in this case, the recovery key is automatically saved to their Microsoft account  or work or school account, before protection is activated
  • An administrator on your device manually activated BitLocker Drive Encryption: in this case, the user activating BitLocker selected where to save the recovery key
  • An organization that is managing your device activated BitLocker protection through policy settings: in this case, the organization might have your BitLocker recovery key

What if I can't find the recovery key?

  • If your device is managed by an organization, check with your IT department to retrieve the recovery key.
  • If you can’t find the BitLocker recovery key and are unable to undo any changes that caused it to be needed, you’ll have to reset your device using one of the Windows recovery options.
  • Resetting your device will remove all of your files.

Additional resources



Keywords:
microsoft ms office365 o365 m365 recovery key encryption stolen device drives 
Doc ID:
162836
Owned by:
Ara M. in Microsoft 365
Created:
2026-07-23
Updated:
2026-07-23
Sites:
DoIT Help Desk, Microsoft 365