To protect sensitive and personal information, you may encrypt the file with data encryption software. BitLocker is a disk encryption software comes with the Pro and Enterprise editions of Windows 10/11. By default it uses the AES encryption algorithm in cipher block chaining (CBC) mode with a 256-bit key. 256-bit AES encryption is a strong encryption standard adopted by the US government.
Warning: It is important to note that once information is encrypted by any encryption software, it can only be opened with the CORRECT password. Losing the password means losing the information for good.
The followings are procedures in using BitLocker to protect sensitive data on an office PC or on a USB thumb drive:
Create a Virtual Hard Disk (VHD) file as a container
BitLocker is a disk-based encryption tool, you are recommended to create a Virtual Hard Disk as a container for data protection.
- Create a new Virtual Hard Disk (VHD) file . Right click on the Start menu button and select Computer Management Manage.
- Select Disk Management.
- Select Action -> Create VHD from the menu bar.
- Provide the file location and size for the VHDx file from the "Create and Attach Virtual Hard Disk" windows. And choose the option "Fixed size" and click "OK". (Note: The maximium size of a VHD file is 2,040 GB. If you are using Windows 10, 11, you can choose VHDX which supports up to 64 terabytes (TB) in size.)
- Initialize the new virtual drive. Click the new disk icon using the right mouse button and select Initialize Disk.
- Make sure "GPT" partition style is selected. Then press "OK". When done, the disk status will becomes "online",
- Then create a partition on the virtual drive. Right click the Unallocated space and select "New Simple Volume"
- Press Next for the welcome screen.
- Press Next for the Volume Size (It will use all available size by default).
- Give a volume label of the disk and use the default settings for the partition format and press Next.
- Press Finish to start format the virtual disk.
- Now we need to encrypt the new virtual drive using BitLocker. Right click the drive in Explorer and select "Turn on BitLocker...". (Warning: Please be careful to choose the Virtual Hard Disk for encryption rather than the physical disk.)
- Tick the option "Use a password to unlock the drive" and enter your password. Then press "Next".
- Choose a way to store the recovery key. Then press "Next".
(Warning: It is important to note that once information is encrypted, it can only be opened with the CORRECT password. Losing the password and the recovery key means losing the information for good.) - Check Encrypt used disk space only (faster and best for new PCs and drives).
- Check New encryption mode (best for fixed drives on this device).
- Press "Start Encrypting"
- Press "Close" when completed.
- Then you can store data to the new virtual drive encrypted by BitLocker.
How to dismount a Virtual Hard Disk
For Window 10/11:
- To dismount the drive, right click on the drive and choose "Eject".
How to mount a Virtual Hard Disk
For Window 10/11:
- To mount the drive again, right click your VHD file and choose "Mount" from the menu bar.
- Enter your password when prompt.
- Click Open folder to view files .
Note: Do NOT delete the VHD volume (i.e. the file "My Encrypted Disk" in this example). Otherwise, all the files stored in the container will also be deleted.
Protecting sensitive data on a USB thumb drive using "BitLocker To Go"
Basically, "BitLocker To Go" allows you to encrypt a USB drive and restrict access with a password. When you connect the USB drive to a Windows 7 computer, you are prompted for the password, and upon entering it you can read and write to the drive as you normally would.
Setting up a USB drive:
- Once you insert a USB drive, right-click on it and select the Turn on BitLocker
- "BitLocker To Go" will begin initializing your USB drive. (When BitLocker To Go initializes your USB drive, you don't have to worry about any data that is already on the drive.)
- Once the initialization process is complete, BitLocker To Go will prompt you to set up a password that you will use to unlock the drive.
- After you set up a password, BitLocker To Go will prompt you to store a recovery key. (You can use the recovery key to unlock your drive in the event that you forget the password.)
- To ensure that you don't lock yourself out of your drive, BitLocker To Go will create a recovery key.
- When the encryption is complete, you'll notice that the drive icon shows a lock on the drive.
To access the USB thumb drive using another PC:
Using a BitLocker To Go encrypted drive:- When you insert the BitLocker To Go encrypted drive in the Windows 10/11 system, you will be prompted to enter the password. (If you wish, you can click the "Eye" button, so that you can see the letters)
- Then press "Unlock".