Enable BitLocker Without TPM in Windows 11

BitLocker Drive Encryption in Windows 11 standardly requires a Trusted Platform Module (TPM) chip to protect the operating system drive. However, systems lacking a compatible TPM can still utilize BitLocker by adjusting the Windows Local Group Policy. This guide provides step-by-step instructions on how to configure your policy settings to allow BitLocker encryption using an alternative startup key or password, followed by enabling the encryption on your system drive.

Step 1: Open the Local Group Policy Editor

  1. Press Windows Key + R on your keyboard to open the Run dialog box.
  2. Type gpedit.msc and press Enter or click OK. (Note: The Local Group Policy Editor is available in Windows 11 Pro, Enterprise, and Education editions).

Step 2: Navigate to the BitLocker Policy Settings

  1. In the left sidebar of the Group Policy Editor, navigate to: Computer Configuration > Administrative Templates > Windows Components > BitLocker Drive Encryption > Operating System Drives
  2. In the right pane, locate and double-click the policy named Require additional authentication at startup.

Step 3: Configure the Authentication Policy

  1. In the policy properties window, select the Enabled radio button at the top.
  2. Under the Options section in the lower pane, locate the checkbox labeled Allow BitLocker without a compatible TPM (requires a password or a startup key on a USB flash drive).
  3. Ensure this checkbox is checked.
  4. Leave the default settings for the remaining drop-down menus or customize them according to your preference.
  5. Click Apply, then click OK.
  6. Close the Local Group Policy Editor.

Step 4: Turn On BitLocker on the System Drive

  1. Open File Explorer and go to This PC.
  2. Right-click your Windows operating system drive (typically the C: drive) and select Turn on BitLocker.
  3. Choose your preferred startup unlock method:
    • Enter a password: You will be prompted to type this password every time the computer boots.
    • Insert a USB flash drive: The USB drive must be plugged in every time the computer boots to unlock the drive.
  4. Choose how to back up your recovery key (save to your Microsoft account, save to a file, or print it) and click Next.
  5. Choose how much of your drive to encrypt (used disk space only or the entire drive) and select your preferred encryption mode.
  6. Check the box for Run BitLocker system check to verify the configuration, then click Continue.
  7. Restart your computer when prompted to initiate the encryption process.