Enable BitLocker with TPM and Back Up Recovery Keys to Microsoft Entra ID
Encrypt Windows 11 drives with BitLocker using the TPM, add a recovery password and back it up to Entra ID so a lost laptop never means lost data.
Common Symptoms and Quick Fixes
| Symptom | Likely Cause | Quick Fix |
|---|---|---|
| Cannot start BitLocker | TPM missing or not ready | Check Get-Tpm; enable TPM in firmware |
| Recovery key prompt after update | No recovery key stored | Back up the key to Entra ID or AD |
| Encryption slow | Full-disk encryption of used and free space | Use -UsedSpaceOnly on new drives |
Method 1: Check TPM and Current Status
Run in an elevated PowerShell window.
Get-Tpm
Get-BitLockerVolume
Method 2: Enable BitLocker and Add a Recovery Password
XTS-AES 256 is a strong default. Add the recovery password right after.
Enable-BitLocker -MountPoint "C:" -EncryptionMethod XtsAes256 -UsedSpaceOnly -TpmProtector
Add-BitLockerKeyProtector -MountPoint "C:" -RecoveryPasswordProtector
Method 3: Back Up the Recovery Key to Entra ID
This stores the key on the device object so IT can retrieve it later.
$id = (Get-BitLockerVolume -MountPoint C:).KeyProtector | Where-Object KeyProtectorType -eq 'RecoveryPassword' | Select-Object -ExpandProperty KeyProtectorId
BackupToAAD-BitLockerKeyProtector -MountPoint "C:" -KeyProtectorId $id
Pro Tip for AdministratorsOn domain-joined PCs that use Active Directory instead, use Backup-BitLockerKeyProtector. Confirm the key is visible in the admin portal before the device is deployed.
Frequently Asked Questions (FAQ)
Q: Does BitLocker slow the PC?
On modern hardware the impact is small thanks to hardware AES.
Q: Can I use BitLocker without a TPM?
Yes, with a policy that allows a password or USB key, but a TPM is recommended.