The quickest way to check BitLocker status
Open the Control Panel, go to System and Security, then select BitLocker Drive Encryption. You'll see a list of your drives with a status next to each one — either "BitLocker on" or "BitLocker off". This takes about 30 seconds and works on Windows 10 and Windows 11.
If you don't see BitLocker in System and Security, your Windows version may not include it. BitLocker is available on Windows Pro, Enterprise, and Education editions — not on Windows Home. You can check your Windows edition by right-clicking This PC and selecting Properties; your edition appears under "Windows specifications".
BitLocker encrypts your entire drive so that if your computer is lost or stolen, someone cannot read the files on it without your password or recovery key. Knowing whether it's on matters because if your drive fails or you forget your password, you'll need that recovery key to access your data again.
Key Takeaways
- The Control Panel method (System and Security > BitLocker Drive Encryption) is the fastest way to see whether BitLocker is on or off for each drive.
- BitLocker only comes with Windows Pro, Enterprise, and Education — if you have Windows Home, you won't see the option at all.
- If BitLocker is on, Windows stores a recovery key that you should save somewhere safe, because you'll need it if you forget your password or your drive has problems.
- The Command Prompt method using manage-bde -status shows the same information and works if the Control Panel route is blocked on your computer.
Using the Control Panel method
Start by opening the Control Panel. On Windows 10 and 11, the fastest way is to right-click the Start button and select Run, type control, and press Enter. This opens Control Panel directly.
Once Control Panel is open, click System and Security. Look for the heading BitLocker Drive Encryption — it's usually near the top of the page. Click on it, and you'll see a table showing each drive on your computer with its encryption status next to it.
The status column will show one of three things: "BitLocker on" (your drive is encrypted), "BitLocker off" (your drive is not encrypted), or "BitLocker suspended" (encryption is temporarily paused, usually because Windows Update is running or you've chosen to pause it temporarily). If a drive shows "BitLocker on", you can click the arrow next to it to see more details, including when it was turned on.
Checking BitLocker status from Command Prompt
If you prefer using the command line or the Control Panel method doesn't work on your computer, you can use Command Prompt. Press the Windows key, type cmd, right-click Command Prompt, and select Run as administrator. You'll need administrator permission for this to work.
Type the command manage-bde -status and press Enter. The output shows each drive on your computer and its encryption status. Look for the line that says "Conversion Status" — it will show "Fully Encrypted", "Fully Decrypted", "Encryption in Progress", or "Decryption in Progress".
This method shows the same information as the Control Panel but in text form. It's useful if you're troubleshooting or if you need to check BitLocker status on multiple computers quickly.
What to do if BitLocker is on and you don't have the recovery key
If you see that BitLocker is on but you don't have a copy of your recovery key, you should save it now. In the BitLocker Drive Encryption window in Control Panel, click the drive that has BitLocker on, then look for an option that says Back up your recovery key or Save your recovery key. You can save it to a file, print it, or save it to your Microsoft account.
The recovery key is a 48-character code that looks like this: 123456-789012-345678-901234-567890-123456. If you ever forget your BitLocker password or your drive won't start normally, you'll need this key to unlock your drive. Store it somewhere separate from your computer — a USB drive, a printed copy in a safe place, or your Microsoft account are all reasonable options.
If you've lost the recovery key and can't find it, you have limited options. Microsoft can help you recover it if you signed in with a Microsoft account when BitLocker was turned on, but the process requires proof of identity and can take time. If you used a local Windows account instead, recovery becomes much harder.
Understanding BitLocker suspension and what it means
Sometimes BitLocker shows a status of "suspended" rather than "on" or "off". This means encryption is temporarily paused. Windows automatically suspends BitLocker during major updates, and you can manually suspend it yourself if you need to do maintenance on your computer.
When BitLocker is suspended, your drive is still encrypted, but Windows isn't actively protecting it until you resume encryption. Suspension usually lasts until you restart your computer or until Windows finishes what it was doing. You don't need to do anything — just restart your computer, and BitLocker will resume automatically.
If BitLocker has been suspended for a long time and you want to resume it manually, go back to the BitLocker Drive Encryption window in Control Panel, click the suspended drive, and select Resume protection.
BitLocker on external drives and USB devices
BitLocker can encrypt external drives and USB devices too. When you plug in an external drive, it appears in the BitLocker Drive Encryption window just like your main drive does. The status shows whether that external drive has BitLocker encryption turned on.
If you turn BitLocker on for an external drive, you'll need to enter a password every time you plug it in on a different computer. This is useful if you carry sensitive files on a USB drive or external hard drive. The same recovery key rules apply — save your recovery key somewhere safe if you turn on BitLocker for an external drive.
Frequently Asked Questions
Can I turn BitLocker on or off from the same Control Panel window?
Yes. In the BitLocker Drive Encryption window, click the drive you want to change, then select either Turn off BitLocker or Turn on BitLocker. Turning it on takes time — Windows will encrypt your drive in the background, which can take hours on a large drive. Turning it off also takes time and requires your recovery key or password.
What happens if I turn off BitLocker?
Your drive will be decrypted, meaning the files on it will no longer be protected by BitLocker. If your computer is stolen after that, someone could read the files on your drive. Decryption happens in the background and doesn't delete your files — it just removes the encryption protection.
Do I need BitLocker if I already use a Windows password?
A Windows password protects your files while Windows is running, but BitLocker protects them even if someone removes your hard drive and connects it to a different computer. If your laptop is stolen, a Windows password alone won't stop someone from reading your files by booting from a USB drive or connecting the drive to another machine. BitLocker prevents that.
Why does BitLocker say "Conversion Status: Fully Decrypted" when I thought it was on?
This usually means BitLocker is in the process of being turned off, or it was recently turned off. Check the Control Panel window for a status that says "Decryption in Progress" — if so, let it finish. If it says "Fully Decrypted", BitLocker is off and your drive is no longer encrypted.
Can I check BitLocker status on someone else's computer?
You need administrator access to see BitLocker status. If you don't have administrator permission on the computer, you won't be able to open the BitLocker window or run the manage-bde command. Ask the computer's owner or administrator to check for you.