Skip to main content

How do I Encrypt my Windows Laptop?

On this page, you will learn about how to encrypt your Windows laptop with BitLocker.  In addition, you will learn:

BitLocker Requirements (Windows only)

The following system requirements will allow Windows-based computers to be secured using BitLocker disk encryption.

  • Windows 11 Pro, Enterprise, or Education versions
  • All Windows-based computers should include these requirements.
  • Trusted Platform Module (TPM) 2.0 or higher. Note: TPM chip must be enabled in BIOS.

Turn on BitLocker in Windows

Click the Windows Search button (1) and type “Manage BitLocker” (2). Select Manage BitLocker (3).

Image shows the results found when searching for BitLocker.

Click Turn on BitLocker.

Image showing the Turn on Bitlocker link

Click Next to begin preparing the drive for BitLocker.

encryptWinLaptopImgc

Back up personal data before encrypting the drive to prevent data loss, click Next to continue.

Image showing BitLocker Drive Encryption Information

The preparation process should finish in a few minutes.

encryptWinLaptopImge

Click Restart now.

Image showing the Restart Now button

After the computer restarts, BitLocker Drive Encryption will pop up automatically. Click Next to continue.

Image showing BitLocker Pop up message Preparing your drive

You will be presented with options for storing your recovery key.  We recommend saving your recovery key to your Microsoft account (outlined in Red).**Important: Keep this key in a safe place and readily accessible if or when you need to use it.

Image showing where to save your recovery key

Make sure to select Encrypt the entire drive for full-disk encryption. UTHealth MSIT (Medical School Information Technology) policy requires all incoming student computers to be encrypted using full disk encryption. Click Next to continue.

Image showing options to chose how much of your drive to encrypt

Check Run BitLocker system check, and click Continue.

Image asking if you are ready to encrypt your drive

Click Restart now.

Image showing the Restart Now button

After the computer restarts, the encryption process will begin. Normally, the hard drive will take less than 2 hours to encrypt depending on its size. You can still use the computer during the process.

Image showing the drive encrypting progress

Click Manage BitLocker to make sure the encryption is successful.

Your computer is now encrypted with BitLocker.

Image showing the icon reflecting BitLocker is installed on the drive

To Enable TPM (Trusted Platform Module) chip on Dell BIOS

  1. Turn the computer on.
  2. As the computer performs POST, press the hotkey F2 to enter the BIOS.
  • Once in the BIOS, locate the section on the left panel that configures Security.
  • In the Security section, locate the TPM option. Then on the right panel, check TPM On and click Apply.
  • Click Exit to restart the computer.

Upgrade Windows 10 Pro to 11 Education Version

Windows 11 education version is available to upgrade at no cost from this link: http://uthealth.onthehub.com

Once you have your new Windows Activation key, you will need to change your computer’s product key to the new one.

  1. Select Start Settings Update & Security Activation.
  • Under Upgrade product key, select Change product key.
  • Enter a product key.
  • Select Next to start the upgrade 11 Education Version.

Verify if Full Disk Encryption is Enabled

Click the Windows Start button, type “cmd” to search for Command Prompt:

Image showing Command Prompt app

Right-click Command Prompt and select “Run as Administrator.”

In command prompt, type “manage-bde -status” and press Enter.

View the status of BitLocker on the drives in the computer:

Image showing Command Prompt Conversion Status

Medical School Information Technology

Administrative Offices
6431 Fannin St | MSB G.520 | Houston, TX 77030 USA | Fax: (713) 500-0708
IT Help Desk: (713) 486-4848