MH IT SOLUTION — Production Tech Knowledge Base & IT Troubleshooting Guides ▶ YouTube Channel

Enable BitLocker with TPM and Back Up Recovery Keys to Microsoft Entra ID

MH IT SOLUTION Editorial Team · Updated August 02, 2026 · 7 min readIntermediate

Encrypt Windows 11 drives with BitLocker using the TPM, add a recovery password and back it up to Entra ID so a lost laptop never means lost data.

Common Symptoms and Quick Fixes

Symptom Likely Cause Quick Fix
Cannot start BitLocker TPM missing or not ready Check Get-Tpm; enable TPM in firmware
Recovery key prompt after update No recovery key stored Back up the key to Entra ID or AD
Encryption slow Full-disk encryption of used and free space Use -UsedSpaceOnly on new drives

Method 1: Check TPM and Current Status

Run in an elevated PowerShell window.

Get-Tpm
Get-BitLockerVolume

Method 2: Enable BitLocker and Add a Recovery Password

XTS-AES 256 is a strong default. Add the recovery password right after.

Enable-BitLocker -MountPoint "C:" -EncryptionMethod XtsAes256 -UsedSpaceOnly -TpmProtector
Add-BitLockerKeyProtector -MountPoint "C:" -RecoveryPasswordProtector

Method 3: Back Up the Recovery Key to Entra ID

This stores the key on the device object so IT can retrieve it later.

$id = (Get-BitLockerVolume -MountPoint C:).KeyProtector | Where-Object KeyProtectorType -eq 'RecoveryPassword' | Select-Object -ExpandProperty KeyProtectorId
BackupToAAD-BitLockerKeyProtector -MountPoint "C:" -KeyProtectorId $id
Pro Tip for AdministratorsOn domain-joined PCs that use Active Directory instead, use Backup-BitLockerKeyProtector. Confirm the key is visible in the admin portal before the device is deployed.

Frequently Asked Questions (FAQ)

Q: Does BitLocker slow the PC?

On modern hardware the impact is small thanks to hardware AES.

Q: Can I use BitLocker without a TPM?

Yes, with a policy that allows a password or USB key, but a TPM is recommended.

Leave a Reply

Your email address will not be published. Required fields are marked *