How to Use Windows 10 Pro BitLocker to Encrypt a USB Drive

A USB flash drive is easy to lose, lend, or leave behind. If it contains tax records, work documents, passwords, photos, or backup files, anyone who finds it may be able to open them. Windows 10 Pro includes BitLocker To Go, a built-in feature that encrypts removable drives and protects their contents with a password or smart card.

BitLocker works differently from a normal folder password. It encrypts the entire supported USB volume, so files remain protected when the drive is removed from your computer. You can use the drive on another compatible Windows computer by entering the unlock password, while unauthorized users see encrypted data instead of readable files.

Before starting, copy important files to another location and make sure Windows 10 is activated and up to date. Encryption is usually straightforward, but choosing the correct settings and storing the recovery key safely will prevent many common access problems.

Why Encrypt a Removable Drive

USB drives are convenient because they move data between computers without an internet connection. That convenience also creates a security risk. A lost drive can expose its contents even when your Windows account is protected by a strong password, because the files can be accessed from another device.

BitLocker To Go uses encryption to make the data unreadable without the correct unlock method. The drive can still appear in File Explorer, but its files cannot be opened until Windows verifies the password, recovery key, or smart card. This is useful for personal documents, portable backups, school projects, and business files.

Encryption does not protect information after you unlock the drive and leave it connected. Anyone using your logged-in computer may be able to browse the files. It also does not remove malware or prevent accidental deletion, so continue using antivirus protection and maintain a separate backup.

Prepare the USB Drive and Recovery Key

Connect the USB flash drive and open File Explorer. Check its drive letter, available space, and existing contents before enabling BitLocker. The process normally keeps the files already on the drive, but a backup is still recommended because interruptions, drive errors, or incorrect formatting choices can cause data loss.

Use a drive with enough free space for the files you plan to store. BitLocker can encrypt standard removable storage such as USB flash drives and external hard drives formatted with a supported Windows file system. If Windows reports that the drive is corrupted or needs formatting, repair or back up the data first rather than proceeding immediately.

You will be asked to save a recovery key. This key is essential if you forget the password, the password becomes unreadable, or Windows detects a change that prevents automatic unlocking. Save it to a different USB drive, print it, or store it in a secure password manager. Do not save the only copy on the drive being encrypted.

For additional portable-storage guidance, review the offline maps guide, which also covers practical considerations when files need to remain available without an internet connection.

Turn On BitLocker in Windows 10 Pro

Open File Explorer, right-click the USB drive, and select Turn on BitLocker. If the option is missing, open Control Panel, choose System and Security, and select BitLocker Drive Encryption. Under Removable data drives, locate the connected USB device and click Turn on BitLocker.

Windows will ask how you want to unlock the drive. Select Use a password to unlock the drive, enter a strong password, and type it again. A useful password should be difficult to guess but practical enough to enter when you need the drive. Avoid using your Windows login password, a birthday, or a short word found in a dictionary.

Next, select a recovery-key location. Choose Save to a file, Print the recovery key, or another available method. Verify that the saved key belongs to the correct USB drive. If you encrypt several drives, label each recovery key clearly without placing the label and key on the same device.

BitLocker then asks how much of the drive to encrypt. Encrypt used disk space only is faster for a new or empty drive, while Encrypt entire drive is safer for a drive that has held files before. Deleted data may remain recoverable in unused areas, so choose the full-drive option when the USB has previously contained sensitive information.

Setting Best choice Why it matters
Unlock method Strong password Works on most compatible Windows computers
Recovery key Separate secure location Restores access if the password is forgotten
Encryption scope Used space for a new drive Finishes faster on an unused USB
Encryption scope Entire drive for an old drive Protects previously used storage areas
Compatibility mode Compatible mode for older Windows systems Improves access on older supported computers

Select Encryption and Compatibility Options

After choosing the encryption scope, Windows may ask which encryption mode to use. Select Compatible mode if you expect to open the USB drive on older versions of Windows. Choose New encryption mode when the drive will be used only with newer Windows systems and you prefer the current encryption format.

The compatible option is generally the safer choice for a portable flash drive that moves between computers. New encryption mode can provide a modern format, but an older computer may be unable to unlock it. If you need to share files with someone else, check their Windows version before selecting the mode.

Click Start encrypting to begin. The duration depends on the drive capacity, the amount of data, the USB connection, and whether you selected full-drive encryption. Do not remove the drive while encryption is active. Keep the computer connected to power, and avoid forcing a shutdown.

You can continue using Windows during the process, but performance may be slower. Wait for the BitLocker window to report that encryption is complete before ejecting the drive. Then use the Safely Remove Hardware icon in the notification area instead of pulling out the USB immediately.

Unlock, Lock, and Manage the Drive

When you reconnect the encrypted USB drive, Windows displays a BitLocker prompt. Enter the password and select Unlock. The drive then behaves like other removable storage until it is ejected or locked. If you enabled the option to automatically unlock the drive on that computer, Windows may open it without asking every time.

Automatic unlocking is convenient on a private desktop, but it is less suitable for a shared computer or laptop used in public places. To manage the setting, right-click the drive, choose Manage BitLocker, and review the available options. You can turn automatic unlocking off whenever the security situation changes.

To lock the drive without unplugging it, right-click its entry in File Explorer and choose Eject, or use the BitLocker management options where available. The exact menu can vary by Windows update and drive type. Once locked, the data cannot be browsed until the password or recovery key is entered again.

You can also change the password, back up the recovery key, remove the password, or turn off BitLocker through Manage BitLocker in Control Panel. Removing the password may require another unlock method, and disabling BitLocker starts a decryption process that can take time.

Fix Common BitLocker Problems

If Turn on BitLocker does not appear, confirm that you are signed in with an administrator account and that the computer is running Windows 10 Pro, Enterprise, or Education. Windows 10 Home does not provide the same full BitLocker management features. You can check the edition by opening Settings, selecting System, and choosing About.

A drive that cannot be encrypted may have file-system errors, insufficient free space, or an unsupported configuration. Copy the files elsewhere, format the drive with a compatible file system, and try again if the data is already backed up. Formatting permanently removes existing files, so do not use this step as an initial troubleshooting action.

If the password is rejected, check Caps Lock, Num Lock, keyboard layout, and spaces at the beginning or end of the entry. If the password is genuinely forgotten, select More options or the recovery-key option in the BitLocker prompt and enter the 48-digit recovery key. The key must match that particular drive.

When encryption appears frozen, allow extra time before interrupting it, especially with a large external drive. Check whether the drive activity light is still blinking. If Windows reports an I/O error, stop using the drive and copy any accessible data before attempting repairs. Repeated disconnects can damage the file system and interrupt encryption.

Security also depends on what you download and copy to removable media. For example, files associated with a blackjack VIP program should come from a trustworthy source and be scanned before storage; BitLocker protects data at rest but does not make unsafe software harmless.

Keep Your Encrypted USB Secure

BitLocker is strongest when combined with careful handling. A recovery key should be available when needed, but it should not be left beside the USB drive in an unlocked desk drawer. Store it separately and identify it using a private reference that does not reveal the password.

Use these practical habits:

Remember that encryption protects the storage device, not every copy of the data. A document emailed to another person, copied to an unencrypted laptop, or saved in an ordinary backup remains exposed according to that destination’s security.

BitLocker To Go gives Windows 10 Pro users a practical way to protect portable files without installing separate encryption software. Set it up from File Explorer or Control Panel, save the recovery key away from the USB drive, choose the encryption scope carefully, and wait for the process to finish before removing the device. Once configured correctly, the drive can travel with you while its contents remain private when it is lost or disconnected.