Share via


How to Disable Automatic BitLocker Encryption

Question

Saturday, September 14, 2019 5:16 PM

I purchased a new laptop and reinstalled Windows 10 by deleting ALL partitions and only installing on the Unallocated Partition and the drive is already encrypting as I booted right into Windows. So, I went to Disk Management and looked and the C Partition was BitLocker Encrypted. And then, I did the MANAGE-BDE -STATUS and was Encryption in Progress. Then I went to Manage Bitlocker and it says Waiting for Activation.

How can I disable BitLocker from Automatically encrypting after the OOBE?

From the URL link below, it explains on how this new Automatic BitLocker Encryption is implemented on modern computing devices.

https://docs.microsoft.com/en-us/windows/security/information-protection/bitlocker/bitlocker-device-encryption-overview-windows-10#bitlocker-device-encryption

BitLocker Device Encryption
Beginning in Windows 8.1, Windows automatically enables BitLocker Device Encryption on devices that support Modern Standby. With Windows 10, Microsoft offers BitLocker Device Encryption support on a much broader range of devices, including those that are Modern Standby, and devices that run Windows 10 Home edition.

Microsoft expects that most devices in the future will pass the testing requirements, which makes BitLocker Device Encryption pervasive across modern Windows devices. BitLocker Device Encryption further protects the system by transparently implementing device-wide data encryption.

Unlike a standard BitLocker implementation, BitLocker Device Encryption is enabled automatically so that the device is always protected. The following list outlines how this happens:

When a clean installation of Windows 10 is completed and the out-of-box experience is finished, the computer is prepared for first use. As part of this preparation, BitLocker Device Encryption is initialized on the operating system drive and fixed data drives on the computer with a clear key (this is the equivalent of standard BitLocker suspended state). In this state, the drive is shown with a warning icon in Windows Explorer. The yellow warning icon is removed after the TPM protector is created and the recovery key is backed up, as explained in the following bullet points.

  

All replies (1)

Monday, September 16, 2019 2:18 AM

For clean install Windows 10, device encryption is enabled by default, but it’s very easy to decrypt in Control Panel, don’t need to use manage-bde command.

You may check this similar case for some ideas.

Avoiding Bitlocker Device Encryption on W10 Home

https://www.tenforums.com/antivirus-firewalls-system-security/117478-avoiding-bitlocker-device-encryption-w10-home-2.html

Please Note: Since the website is not hosted by Microsoft, the link may change without notice. Microsoft does not guarantee the accuracy of this information.

Regards

Please remember to mark the replies as answers if they help.
If you have feedback for TechNet Subscriber Support, contact [email protected].