In today's article, you will learn how to encrypt a Windows 10 drive with BitLocker, whether it contains the operating system or is a simple USB flash drive.

If you are concerned about securing your data on a drive, you can encrypt it with BitLocker. BitLocker is a built-in feature of Windows 10 that can encrypt your drives, or USB flash drives. It is available in Windows 10 Pro / Education / Enterprise editions.
With BitLocker, you can choose to encrypt the entire disk, or you can choose to encrypt part of it (usually your data) and add additional files later.

BitLocker also gives you several options to unlock your encrypted drive. Encrypted data will be very difficult to decrypt, and if someone steals your system, such as a laptop or tablet or USB flash drive, they won't be able to access your data. Overall, the feature offers you better security for your data and system.
Therefore, if you are the administrator of a computer system, you can follow the steps below to encrypt a drive.
How to Bitlocker encrypt a drive in Windows 10
1. Press Win + E keys simultaneously to open File Explorer and click “PC”. Under Devices and drives, right-click the drive you want to encrypt, and click “Turn on BitLocker”.

NOTE: If the system is not equipped with a TPM (Trusted Platform Module aka TPM), you will receive the following notification: “This device cannot use a Trusted Platform Module. Your administrator must set the “Allow BitLocker without a compatible TPM” option in the “Require additional authentication at startup” policy for operating system volumes.”
In this case, refer to this article to troubleshoot this error.
2. Then, and especially if you have instructed the drive containing the Windows operating system to be encrypted, you will go through various warning and confirmation screens, without having to make any selections, except to press the “Next” button, until you reach the “Choose how to unlock the drive” section.

There choose the mode that suits you. There are two possibilities. Either use a PIN or a USB flash. In this example, we chose the PIN. Of course if you have instructed a flashUSB drive to be encrypted then the driver will not ask you if you want to unlock the flashUSB with a USB flsh !!!!
Click next and you will be taken to a screen where you will need to enter your PIN. This password unlocks your encrypted drive. Keep in mind that you will need to use this password every time you want to view your drive, so choose a strong password that you can remember. Click the Next button.

3. It will then ask you where you want to save the recovery key. This recovery key will be useful in case you forget or lose the above password. We recommend that you save the recovery key to your Microsoft account.

4. You will be notified, if you clicked Save to your Microsoft account in the previous step, that your recovery key has been saved.

But make sure you confirm this first at https://onedrive.live.com/recoverykey .

Don't expect to see the key as a file on Microsoft's OneDrive. Just click the link above and if you have multiple keys, make sure the most recent one is saved as well.
5. Then, on the next screen of the BitLocker Drive Encryption Wizard, select how much space you want to encrypt. We recommend that you select the Encrypt entire drive option here. Click Next. The encryption process will take some time. Be patient

6. Now, you need to select the encryption method. Here, selecting the new encryption mode will use the 128-bit XTS-AES encryption method. While selecting the compatible mode will use the 128-bit AES-CBC encryption method. After selecting, click on the Next button.

7. Then click “Start Encryption”.

If you have instructed the disk with the operating system to be encrypted, then you will be asked to restart your system. If you have selected another disk, then you will proceed to the next step.

8.After the end of encryption, every time you want to open the encrypted disk, you will have to type the password you set in step 2. If you have encrypted the disk with the operating system, this password will be requested when you start your system.

If you forgot your password, you can click the “More options” link and enter the recovery key you saved to your Microsoft account. Since you have saved your recovery key online, you can look it up from any of your devices to sign in to your Microsoft account.
This way, you have successfully encrypted a drive in Windows 10 with BitLocker. You can follow similar steps with any other drive on your computer.
If at some point you regret it and want to restore your disk to its original form, that is, without encryption, but without losing your data, all you have to do is go back to file explorer and next to the specific disk you will see a list of commands.

Use “Turn Off BitLocker” and everything will simply go back to how it was before. The process of removing the encryption takes as long as the encryption you did in the first place. So arm yourself with patience.
