A clear set up of Home windows 10 or Home windows 11 could allow Bitlocker drive encryption mechanically. The primary system partition and all mounted drives can be encrypted on this case after the out-of-box expertise.
Bitlocker protects information on the PC towards unauthorized entry by encrypting partitions and drives.
Microsoft calls this particular BitLocker function gadget encryption: “System encryption is a Home windows function that gives a easy method for some units to allow BitLocker encryption mechanically”.
Downside is, because the encryption course of occurs mechanically on this case, customers will not be conscious of it. This will result in points, for example when reinstalling the working system with out saving the Bitlocker restoration key or utilizing a Microsoft account. Entry to recordsdata is misplaced within the worst case.
Fortunately, there are methods to dam Home windows from enabling the automated encryption of drives throughout clear installs.
Choice 1: throughout set up
New PCs include a preinstallation of Home windows. This hurries up the setup course of, but it surely additionally provides customers much less management.
Step 1: It begins on the nation or area choice display.
Step 2: Open the Registry Editor
- Use the keyboard shortcut Shift-F10 to open a command immediate window.
- Sort regedit and press the Enter-key.
This opens the Registry Editor.
Step 3: Disable automated encryption utilizing BitLocker
- Use the construction on the left to go to HKEY_LOCAL_MACHINESYSTEMCurrentControlSetControlBitLocker
- Proper-click on BitLocker and choose New > Dword (32-bit) Worth.
- Title it PreventDeviceEncryption.
- Double-click on it and alter its worth to 1.
- Shut the Registry Editor.
- Shut the Command Immediate window.
Proceed with the set up.
Choice 2: Manipulating an ISO picture
It is usually attainable to change an ISO picture instantly. This requires a USB gadget with at the very least 16 GB of storage. The Home windows set up is copied to the USB gadget and the PC is booted from the USB gadget to put in Home windows.
Right here is how this works:
Step 1: Obtain Rufus
Rufus is a free program to create bootable USB drives. You possibly can obtain the most recent model for Home windows from the homepage.
Step 2: Run Rufus
Rufus doesn’t have to be put in. Simply double-click on the downloaded executable file to begin the app. Be sure you give your okay for on-line replace checks, should you do not need a Home windows ISO picture already. This lets you obtain the ISO utilizing Rufus.
Step 3a: obtain the ISO utilizing Rufus
Change from choose to obtain within the higher half of the interface. Activate Obtain once more to begin the method.
Choose the model of Home windows, version, language and structure. It could take some time for the obtain to finish.
Step 3b: choose an ISO that’s already in your gadget
Make certain choose, and never obtain, is chosen within the Rufus interface. Click on on the choose button and use the file browser that opens to pick the ISO picture.
Step 4: Making ready the ISO
Choose System on the prime to choose a tool that you simply need to copy the Home windows set up recordsdata to. Be aware that you simply can’t choose mounted laborious drives.
As soon as completed, activate the beginning button on the very backside. Rufus shows the Home windows Consumer Expertise window.
Make certain Disable BitLocker automated gadget encryption is checked. This prevents the automated encryption of drives utilizing BitLocker throughout set up of Home windows.
Choose OK to proceed. This system writes the recordsdata to the chosen USB gadget.
Bonus Tip: verify the BitLocker standing
A easy command reveals the standing of all drives and partitions with regard to BitLocker encryption. Right here is how that works:
- Open Begin.
- Sort CMD.
- Choose “run as administrator” whereas Command Immediate is chosen.
- Paste manage-bde -status and press the Enter-key.
Verify any of the next parameters: BitLocker model, Conversion standing, Share encrypted, Encryption technique, Lock standing, Identification discipline, or Key protectors.
Should you see “none, “absolutely decrypted”, “0.0%”, “None”, “Safety Off”, “Unlocked”, “None”, and “None Discovered”, then the drive shouldn’t be encrypted utilizing BitLocker.
You possibly can disable the safety by operating the command manage-bde –off DRIVELETTER, e.g., manage-bde –off C: from an elevated command immediate.
What about you? Do you employ encryption, perhaps even BitLocker? (inspiration from Deskmodder)
Abstract
Article Title
Tips on how to block Home windows 11 from encrypting drives throughout set up
Description
The information affords step-by-step directions to disable BitLocker automated drive encryption through the setup of Home windows 10 or 11.
Writer
Martin Brinkmann
Writer
Ghacks Expertise Information
Emblem
Commercial