Windows OS Hub
  • Windows
    • Windows 11
    • Windows Server 2022
    • Windows 10
    • Windows Server 2019
    • Windows Server 2016
  • Microsoft
    • Active Directory (AD DS)
    • Group Policies (GPOs)
    • Exchange Server
    • Azure and Microsoft 365
    • Microsoft Office
  • Virtualization
    • VMware
    • Hyper-V
  • PowerShell
  • Linux
  • Home
  • About

Windows OS Hub

  • Windows
    • Windows 11
    • Windows Server 2022
    • Windows 10
    • Windows Server 2019
    • Windows Server 2016
  • Microsoft
    • Active Directory (AD DS)
    • Group Policies (GPOs)
    • Exchange Server
    • Azure and Microsoft 365
    • Microsoft Office
  • Virtualization
    • VMware
    • Hyper-V
  • PowerShell
  • Linux

 Windows OS Hub / Windows 11 / Disable BitLocker Automatic Drive Encryption in Windows 11

October 16, 2024

Disable BitLocker Automatic Drive Encryption in Windows 11

Starting with Windows 11 24H2, when you perform a clean install or reinstall the OS on a device with a TPM chip and Secure Boot enabled, all drive partitions are automatically encrypted. All drives connected to the computer (including the system drive) are encrypted with BitLocker. Automatic encryption is enabled regardless of your account type (local or Microsoft account) and Windows edition (Home, Pro, or Enterprise). In previous Windows 11 builds, automatic device encryption was only enabled if the TPM was present + Modern Standby support + the device passed the HSTI test.

Device encryption is performed during the final OOBE phase of the Windows installation. The data is encrypted but is not actually protected by the Bitlocker key protector until the user logs in for the first time and the volume encryption key can be easily extracted in clear text.

  • Signing in with a Microsoft account (MSA) activates the protection and sends the Bitlocket recovery key to the Microsoft cloud, Entra ID, or on-premises AD (if the Active Directory is configured to store the BitLocker recovery keys).
  • When a user logs into Windows 11 with a local account, the data is not protected until a user manually configures Key Protector.

Automatic device encryption can be turned off in Settings -> Privacy & Security. Slide the Device Encryption switch to Off.

Disable BitLocker drive encryption in Windows 11 24H2

You can check whether the specified volume is encrypted using the command:

manage-bde -status

To turn off encryption for a volume:

manage-bde –off C:

manage-bde - disable drive encryption

Disable BitLocker encryption for all drives:

Get-BitLockerVolume | Disable-BitLocker

To prevent local drives from being encrypted during installation, use Rufus to write the Windows 11 install ISO image to the USB flash drive. When you burn an ISO image with Rufus, make sure that the ‘Disable BitLocker automatic device encryption‘ option is checked.

Rufus option 'Disable BitLocker automatic device encryption'

Or, disable device encryption during Windows setup.

  1. Once the Windows 11 installation files have been copied, your computer will restart and you will be taken to the OOBE screen (with region and language selection).
  2. Press Shift+F10 to open the command prompt from this screen.
  3. To open the Registry Editor, run regedit.exe
  4. Navigate to the reg key HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\BitLocker and create a DWORD (32-bit) parameter named PreventDeviceEncryption
  5. Set the value to 1
    PreventDeviceEncryption - registry key
    Or create a registry parameter using the command:
    REG ADD HKLM\SYSTEM\CurrentControlSet\Control\BitLocker /v PreventDeviceEncryption /t REG_DWORD /d 1
  6. Close the command prompt and continue installing Windows 11. The BitLocker automatic drive encryption will not be enabled.
2 comments
10
Facebook Twitter Google + Pinterest
Windows 11
previous post
Check the Software Installation/Removal History in Windows
next post
Remove a Specific Device from the Safely Remove Hardware List on Windows

Related Reading

Create a Custom Windows Image with Pre-installed Apps

February 28, 2024

Upgrading to Windows 11 on Unsupported Hardware

March 6, 2024

Configuring RemoteApps Hosted on Windows 10/11 (without Windows...

January 25, 2025

How to Assign (Passthrough) a Physical GPU to...

June 11, 2024

Enable Hyper-V on Windows 10/11 Pro and Home...

August 12, 2024

Fix: Your IT Administrator Has Limited Access to...

March 22, 2024

Get Started with Docker on Windows (WSL2) without...

September 4, 2024

Disable and Completely Remove Widgets from Taskbar in...

September 26, 2024

2 comments

sajid November 2, 2024 - 4:58 pm

your work (all of your website) is of next level..

Reply
randomDude February 14, 2025 - 8:12 pm

Thx, this saved me lots of time.

Reply

Leave a Comment Cancel Reply

join us telegram channel https://t.me/woshub
Join WindowsHub Telegram channel to get the latest updates!

Recent Posts

  • Configuring Windows Protected Print Mode (WPP)

    May 19, 2025
  • Map a Network Drive over SSH (SSHFS) in Windows

    May 13, 2025
  • Configure NTP Time Source for Active Directory Domain

    May 6, 2025
  • Cannot Install Network Adapter Drivers on Windows Server

    April 29, 2025
  • Change BIOS from Legacy to UEFI without Reinstalling Windows

    April 21, 2025
  • How to Prefer IPv4 over IPv6 in Windows Networks

    April 9, 2025
  • Load Drivers from WinPE or Recovery CMD

    March 26, 2025
  • How to Block Common (Weak) Passwords in Active Directory

    March 25, 2025
  • Fix: The referenced assembly could not be found error (0x80073701) on Windows

    March 17, 2025
  • Exclude a Specific User or Computer from Group Policy

    March 12, 2025

Follow us

  • Facebook
  • Twitter
  • Telegram
Popular Posts
  • How to Allow Multiple RDP Sessions on Windows 10 and 11
  • How to Run Program without Admin Privileges and Bypass UAC Prompt
  • Fixing ‘The Network Path Was Not Found’ 0x80070035 Error Code on Windows
  • How to Delete Old User Profiles in Windows
  • How to Install Remote Server Administration Tools (RSAT) on Windows
  • How to Backup and Copy Local Group Policy Settings to Another Computer
  • How to Fix ‘An Operating System Wasn’t Found’ Error on Windows
Footer Logo

@2014 - 2024 - Windows OS Hub. All about operating systems for sysadmins


Back To Top