Privacy and Security

How Can You Check Device Encryption Support in Windows 11?

You can check whether a Windows 11 PC supports Device Encryption in two built-in places. First, open Settings > Privacy & security > Device encryption. If that page and its toggle are present, Windows is exposing Device Encryption on the PC; the toggle then tells you whether it is currently On or Off. For the detailed eligibility result, open System Information and read Automatic Device Encryption Support or Device Encryption Support in System Summary.

I reproduced both checks on Windows 11 Home Single Language version 25H2, build 26220.7872. Settings displayed the Device encryption page with the toggle Off, so the tested PC supported the feature but was not currently using it. A standard-user System Information session exposed the correct row but reported Elevation Required to View. I did not elevate the automation, change the toggle, query a recovery key, inspect drive identifiers, or alter BitLocker, TPM, Secure Boot, firmware, registry, or recovery settings.

What is the difference between support and the current encryption state?

Support means the device and Windows configuration are eligible to offer Device Encryption. Current state means the feature is On or Off now. Those are different questions. The presence of the Device encryption page with an Off toggle is not an unsupported result; it means the setting is available but disabled. Likewise, a PC can meet the prerequisites while encryption is still preparing, suspended, or waiting for account and recovery-key protection.

Device Encryption is the simpler Windows interface built on BitLocker technology. Microsoft says it can automatically encrypt the operating-system drive and fixed data drives on eligible devices. It does not mean every removable USB drive is encrypted, and it does not prove that a recovery key is available merely because the Settings page exists.

Do not use the words “supported,” “enabled,” and “protected” interchangeably. Record the exact label and value you see. That prevents a common mistake in which an Off toggle is reported as a hardware failure or a visible page is reported as proof that every drive is protected.

Table of contents

How can you check Device Encryption support in Settings?

  1. Press Windows + I to open Settings.
  2. Select Privacy & security in the left pane.
  3. Select Device encryption. You can also search Settings for that exact phrase.
  4. Confirm that the page contains the Device encryption card and toggle.
  5. Read On or Off without changing it. Close Settings when you have recorded the result.
Windows 11 Device encryption Settings page with the Off toggle outlined in purple
The tested PC exposed the Device encryption page and reported Off. The focused derivative excludes the account name, email address, avatar, and recovery-key link.

Microsoft's Device Encryption guidance says the setting is under Privacy & security and notes that the page can be absent when the feature is unavailable or the signed-in account is a standard user. That caveat matters: a missing page alone does not identify the failing prerequisite.

The nearby BitLocker drive encryption link opens the fuller management experience on supported editions. It is not necessary for this availability check. The Find your BitLocker recovery key link leads to sensitive recovery material, so do not open or screenshot it merely to answer whether Device Encryption is supported.

How can you read the detailed support result in System Information?

  1. Open Start and search for System Information.
  2. For the complete encryption result, right-click the app and select Run as administrator, then approve the Windows prompt only if you intended to perform this read-only check.
  3. Select System Summary at the top of the left tree.
  4. Scroll to Automatic Device Encryption Support or Device Encryption Support.
  5. Read the value exactly. Close System Information without saving or exporting the full report.
System Information Automatic Device Encryption Support row showing Elevation Required to View outlined in purple
A standard session reached the exact Automatic Device Encryption Support row but honestly returned Elevation Required to View. Microsoft documents that some PCs require an elevated System Information session for the detailed value.

Microsoft's supported procedure uses an administrator session because some devices restrict this value. The tested non-elevated result above is therefore a limitation, not an eligibility verdict. If you see the same message, either use the documented administrator launch when you are comfortable approving it or rely on the visible Settings page for the simpler available/current-state distinction. The WinSides guides to opening System Information and running System Information as administrator explain those launches in more detail.

How should you interpret the System Information value?

Meets prerequisites is the direct support result: Windows considers the PC eligible for Device Encryption. Other values name a blocker or explain why automatic Device Encryption is unavailable. Microsoft lists examples including TPM is not usable, WinRE is not configured, and PCR7 binding is not supported.

Read the whole value because it can contain more than one reason. Do not reduce a detailed sentence to a generic “unsupported” label. A TPM-related result concerns the Trusted Platform Module; a WinRE result concerns Windows Recovery Environment; and a PCR7 or Secure Boot result concerns the measured startup chain. The separate WinSides guide to checking the TPM version in Windows 11 can verify that one component without claiming it is the only requirement.

Microsoft also changed the automatic-encryption prerequisites in Windows 11 version 24H2. HSTI or Modern Standby and the earlier untrusted-DMA eligibility tests are no longer required in the same way for ordinary Windows 11 devices. That is why an old checklist copied from a pre-24H2 article can disagree with current System Information. Prefer the live Windows result and current Microsoft documentation.

Is Device Encryption the same as BitLocker Drive Encryption?

They use the same underlying BitLocker technology, but the user experiences and edition rules are not identical. Device Encryption is the simplified setting offered on eligible devices across a wider range of Windows editions, including Windows Home. The fuller BitLocker Drive Encryption enablement and management experience is associated with Pro, Enterprise, and Education editions.

Device Encryption normally focuses on the operating-system and fixed internal drives and integrates recovery-key protection with a Microsoft account, work or school account, Microsoft Entra ID, or Active Directory, depending on how the PC is managed. A local-only account can change the automatic protection path. This article checks availability and current state only; it does not turn encryption on or verify where a recovery key is stored.

If you later decide to enable encryption, first understand the recovery-key and account consequences and use the normal Windows interface. Never publish a recovery key, key identifier, account address, volume identifier, or full manage-bde output in a screenshot. WinSides has a separate BitLocker recovery-key guide for that higher-stakes workflow.

What should you check if the Device encryption page is missing?

Start with the least invasive explanations. Confirm whether the current account is an administrator, then use the documented System Information value to identify the actual reason. If the message names TPM, Secure Boot, or Windows Recovery Environment, verify that component before making changes. A support result can also differ after a Windows feature update because Microsoft has revised eligibility rules.

Do not enable random firmware options, clear the TPM, edit BitLocker registry keys, repartition a drive, disable security features, or use a third-party “encryption fixer” merely to make the page appear. Clearing a TPM or changing boot configuration can create recovery problems. Back up important files and recovery information before any separate repair or enablement project.

On a work or school PC, policy can manage the page and encryption state. Contact the administrator rather than bypassing policy. On a personally owned PC, use the exact System Information reason as the next troubleshooting target instead of applying a broad list of changes.

What should you hide when sharing Device Encryption evidence?

A full Settings screenshot can expose the account name, email address, avatar, and a direct recovery-key link. A full System Information page can expose the computer name, user name, hardware identifiers, memory details, boot-device path, and other system inventory. None of that is needed for a support question.

Share only a focused crop of the Device encryption card or the Automatic Device Encryption Support row. Never share a recovery key or a page that displays one. The two published images here are article-specific derivatives from locally reproduced, read-only states; the account sidebar, user row, broad inventory, recovery link, desktop, and unrelated windows are excluded.

Frequently Asked Questions

Does an Off toggle mean Device Encryption is unsupported?

No. If the Device encryption page and toggle are present, Off means the feature is available but currently disabled. Support and current state are separate facts.

Why does System Information say Elevation Required to View?

Some PCs restrict the detailed support value to an administrator session. Microsoft documents opening System Information as administrator for this check; do not treat the elevation message itself as an unsupported result.

Can Windows 11 Home support Device Encryption?

Yes. Eligible Windows Home devices can offer the simplified Device Encryption setting. The fuller BitLocker Drive Encryption management experience has different edition requirements.

Do you need to view a recovery key to check support?

No. The Settings page and System Information support row answer the question. Opening or sharing recovery-key material adds risk and is unnecessary.

Use Settings for state and System Information for the reason

Open Privacy & security > Device encryption to see whether Windows exposes the feature and whether it is On or Off. Use the Automatic Device Encryption Support row for the detailed eligibility result, remembering that Microsoft may require System Information to run as administrator. Record the exact value, keep support separate from state, and do not change encryption or reveal recovery material just to perform the check.

For more interesting articles, stay tuned to WinSides.com!

Community

Comments (0)

Leave a helpful comment

Your email is never published. Replies are reviewed before appearing.