How to encrypt USB drive
Summary
This guide helps you troubleshoot and resolve: How to encrypt USB drive. Follow the steps below to fix the issue.
Common Causes
Problem
You need to encrypt a USB flash drive to protect sensitive company data in case the drive is lost or stolen.
Why encrypt?
- Protects confidential data if the USB is lost or stolen
- Required by many company security policies
- Prevents unauthorised access to business files
- Do not encrypt USB drives with tools that aren't approved by the company – IT may be unable to recover data if you use unsupported software.
- Use company‑approved encryption tools when available.
- Keep your password safe – if you lose it, data cannot be recovered.
Solutions
Method 1: Use BitLocker (recommended for Windows 11)
BitLocker To Go requires Windows Pro, Education or Enterprise and administrative rights. BitLocker encrypts the entire volume on any supported file system (NTFS, FAT32, exFAT). Formatting to NTFS can improve compatibility with older Windows versions, but it is not a technical requirement for full‑drive encryption.
Before using BitLocker, make sure Windows is up to date. See How to update Windows.
Check if BitLocker is available
- Insert the USB drive.
- Right‑click the drive in File Explorer.
- If you see
Turn on BitLocker, the feature is available. - If not, your edition of Windows may not support BitLocker To Go, or a Group Policy may be blocking it.
Encrypt the USB with BitLocker
- Right‑click the drive and select Turn on BitLocker.
- Choose Use a password to protect the drive and enter a strong password (refer to the company password policy for requirements).
- Save the recovery key – print it or store it in Azure AD, your Microsoft account, or another secure location separate from the USB.
- Select Encrypt entire drive (more secure, slower).
- Choose Compatible mode if the drive will be used on older Windows versions.
- Click Start encrypting and wait for the process to finish.
Using the encrypted USB
- Insert the USB into any company computer.
- Enter the password when prompted.
- Access your files normally.
Troubleshooting BitLocker
- Option not visible: Verify that you are running a Windows edition that includes BitLocker To Go (Pro, Education, Enterprise). Check
gpedit.mscforTurn on BitLocker To Gopolicy settings. - TPM requirements: BitLocker on removable drives does not require a TPM, but some corporate policies may enforce TPM‑based checks. Contact IT if you encounter TPM‑related errors.
- Write‑protected drive: Ensure the USB switch (if present) is set to write‑enable, and that the drive is not marked read‑only in Disk Management.
- Recovery key retrieval: In Azure AD‑joined devices, the recovery key is automatically backed up to Azure AD. Retrieve it via the My Devices portal. For personal Microsoft accounts, visit the Microsoft account devices page.
- Group Policy restrictions: Some organisations disable BitLocker for removable media. If you suspect a policy is blocking the feature, open a ticket with IT.
Method 2: Use Windows built‑in encryption (EFS) – not recommended for removable drives
EFS only works on NTFS‑formatted volumes and the encrypted files are tied to the user account that performed the encryption. Removable drives formatted as FAT32 or exFAT cannot be encrypted with EFS, and the data will not be accessible on other computers.
For USB encryption, use BitLocker or an approved third‑party solution instead.
Method 3: Use company‑approved encryption software
- Open the Company Portal (Software Center) and look for approved tools such as “ESET Endpoint Encryption” or “McAfee Complete Data Protection”.
- If no tool is listed, Open a Ticket to request the appropriate software.
- Follow the vendor’s documentation to encrypt the USB drive.
Method 4: Use 7‑Zip (third‑party option)
7‑Zip encrypts individual archive files, not the whole USB drive. This method does not provide full‑drive encryption and may not satisfy company security policies. Use only for low‑risk data or when approved by IT.
- Download 7‑Zip from the official website.
- Right‑click the files or folders on the USB, choose 7‑Zip → Add to archive.
- Set “Archive format” to “zip”.
- Enter a password (minimum 12 characters recommended).
- Check “Encrypt file names” for additional security.
- Click OK to create the encrypted archive.
- To access the files, extract the archive and provide the password.
If you require a solution that does not rely on software, consider using a hardware‑encrypted USB drive that meets the company’s approved device list.
Best practices for USB encryption
- Use strong passwords (12+ characters, mixed case, numbers, symbols) in line with the company password policy.
- Never store the password on the same USB drive.
- Keep the recovery key in a secure location separate from the device (Azure AD, Microsoft account, or a physical safe).
- Only use USB drives approved by IT for sensitive data.
- When travelling, keep encrypted USBs with you – not in checked luggage.
- Consider formatting to NTFS only if you need compatibility with very old Windows versions; otherwise, FAT32 or exFAT are acceptable for BitLocker.
For broader guidance on Windows security features, see How to protect your PC with built‑in Windows security features.
There is no built‑in recovery method for encrypted USB drives without the password. If the password is lost:
- All data on the encrypted drive will be inaccessible.
- The USB must be wiped and reformatted.
- Contact IT via Open a Ticket if the data belongs to the company.
Need more help?
If you need a company‑approved encryption tool, are unsure which method to use, or require assistance with the encryption process, please Open a Ticket.
Still Having Issues?
đź’» Open a Ticket