BitLocker vs Device encryption on Windows 11 Home: what's the difference?
Search for “BitLocker Windows 11 Home” and you'll find two names for what sounds like the same thing. BitLocker is the full drive-encryption tool in Windows 11 Pro. Device encryption is the cut-down version that many Windows 11 Home PCs get instead. They use the same encryption underneath, but what you can control — and what they protect — is different.
The short answer
- Windows 11 Home has Device encryption (on supported hardware), not BitLocker. It's a simple on/off switch for your PC's drive.
- Windows 11 Pro has full BitLocker: you choose which drives to encrypt, how they unlock, and you can encrypt USB sticks with BitLocker To Go.
- Both protect a PC that's switched off and stolen. Neither protects your files once you're signed in, or files you copy to a USB stick, an email or the cloud.
Side by side
| Device encryption | BitLocker | |
|---|---|---|
| Windows edition | Home and Pro, on supported hardware | Pro, Enterprise, Education |
| How you turn it on | One switch in Settings | Control Panel → Manage BitLocker, per drive |
| What it encrypts | The PC's internal drive | Any drive you choose, including USB sticks (BitLocker To Go) |
| Unlock options | Automatic with the PC's TPM chip | TPM, TPM + PIN, or a password for data drives |
| Recovery key | Saved to your Microsoft account | Microsoft account, a file, a printout or a USB stick |
| Needs a Microsoft account | Yes, to switch it on | No |
| Protects files while you're signed in | No | No |
How to check whether your PC has Device encryption
- Open Settings → Privacy & security.
- Look for Device encryption. If it's there, you can see whether it's on and switch it on or off.
- If it isn't listed, your hardware doesn't support it. To see why, search Start for System Information, right-click it → Run as administrator, and check the Automatic Device Encryption Support line.
Many new PCs arrive with Device encryption already switched on, especially if you signed in with a Microsoft account during setup. That's worth knowing, because of the next point.
Find your recovery key before you need it
With either BitLocker or Device encryption, a firmware update, a hardware change or a repair can make Windows ask for the recovery key at startup. Without it, the drive stays locked — including all your files. For Device encryption, the key is in your Microsoft account at aka.ms/myrecoverykey. Look it up now and write it down somewhere off the PC.
What drive encryption doesn't do
Device encryption and BitLocker are about the drive. Once Windows has started and you're signed in, every file is readable to anyone using your account — a family member, a repair shop with your password, or malware. And the moment you copy a file somewhere else, it's no longer encrypted: a USB stick, an email attachment or your OneDrive folder.
That's what file encryption is for. An app like Clavis encrypts individual files with AES-256-GCM, so they stay locked while you're signed in and wherever you copy them, and it works on Home without administrator rights. The best setup uses both: drive encryption for a stolen laptop, file encryption for your most private files.
See also: how to encrypt files on Windows 11 Home and how to encrypt a USB drive on Windows 11 Home.
Questions
Is Device encryption as secure as BitLocker?
The encryption itself is the same. Device encryption is BitLocker with fewer options: it covers the internal drive, unlocks automatically with the PC's TPM chip, and keeps its recovery key in your Microsoft account. BitLocker adds per-drive control, a startup PIN and encryption of USB sticks.
Why don't I have Device encryption on my PC?
Device encryption needs supported hardware, including a TPM chip, and you need to sign in with a Microsoft account to switch it on. If Settings doesn't show it, run System Information as administrator and read the Automatic Device Encryption Support line for the reason.
Should I upgrade to Windows 11 Pro just for BitLocker?
Only if you need its extra controls, such as a startup PIN or encrypting USB sticks with BitLocker To Go. For a stolen laptop, Device encryption already protects the drive. For protecting files while you're signed in or when you share them, you need file encryption on either edition.
Where is my Device encryption recovery key?
In your Microsoft account. Go to aka.ms/myrecoverykey, sign in with the account you use on the PC, and find the key for your device. Write it down somewhere other than the PC.