Microsoft is Enabling BitLocker Device Encryption By Default on Windows 11

microsoft-is-enabling-bitlocker-device-encryption-by-default-on-windows-11
Microsoft is Enabling BitLocker Device Encryption By Default on Windows 11

Posted by msmash from the up-next dept.

Microsoft is making BitLocker device encryption a default feature in its next major update to Windows 11. From a report: If you clean install the 24H2 version that’s rolling out in the coming months, device encryption will be enabled by default when you first sign in or set up a device with a Microsoft account or work / school account.

Device encryption is designed to improve the security of Windows machines by automatically enabling BitLocker encryption on the Windows install drive and backing up the recovery key to a Microsoft account or Entra ID. In Windows 11 version 24H2, Microsoft is reducing the hardware requirements for automatic device encryption, opening it up to many more devices — including ones running the Home version of Windows 11. Device encryption no longer requires Hardware Security Test Interface (HSTI) or Modern Standby, and encryption will also be enabled even if untrusted direct memory access (DMA) buses / interfaces are detected.

“We want to create puppets that pull their own strings.” — Ann Marion “Would this make them Marionettes?” — Jeff Daiell

Working…