tech

How to encrypt your PC's disk without giving the keys to Microsoft

Storing recovery keys with Microsoft allows the company to unlock your disk.

How to encrypt your PC's disk without giving the keys to Microsoft

TL;DR

  • Microsoft provided BitLocker encryption recovery keys to the FBI for an investigation in Guam.
  • BitLocker automatically encrypts drives and stores recovery keys on Microsoft servers for Windows 11 Home users signed in with a Microsoft account.
  • Users concerned about privacy can upgrade to Windows 11 Pro to manually manage BitLocker and store recovery keys elsewhere.
  • The process of taking manual control involves decrypting the drive, then re-encrypting it while saving the recovery key to a non-Microsoft location (e.g., printout, text file on external drive).
  • This manual control adds a layer of privacy but requires the user to manage the recovery key's location.