Security Guides
How to turn off BitLocker: decide whether suspending is enough, and save the recovery key first
How to turn off BitLocker or Device encryption on Windows 11 Pro and Home, step by step. Why a BIOS update only needs Suspend protection, how long decryption takes, and why you reset the PC instead of decrypting before selling it, based on Microsoft's official docs.
For: anyone who wants to turn off BitLocker (or Device encryption on Windows Home) on their own Windows PC, for example before swapping hardware or updating the BIOS, because recovery screens keep appearing, or because the PC is being sold or given away. The steps follow Microsoft's official documentation.
Before you start: save the recovery key outside the PC
You may be asked for the recovery key during decryption or when you restart after suspending. You can often find it in your Microsoft account (aka.ms/myrecoverykey), so write the number down or make sure you can open it on another device before you begin. Microsoft states that its support cannot retrieve, provide or recreate a lost recovery key. See how to find your BitLocker recovery key for where to look.
Turn off or suspend: decide first
There are two ways to "stop" BitLocker, and they do very different things.
Suspend protection (temporary pause)
- Data stays encrypted
- The key is temporarily left unprotected so the startup checks don't block changes
- Takes seconds; Resume protection puts it back
- Use for: BIOS, UEFI or TPM firmware updates, hardware swaps, boot setting changes
Turn off BitLocker (decrypt)
- Removes encryption from the whole drive
- Takes tens of minutes to hours
- Undoing it means encrypting the drive again
- Use for: when you have decided to stop encrypting
Microsoft explains that while suspended, the key sits on the drive in the clear, so you can change or update the PC without decrypting and re-encrypting. A suspended drive is effectively unprotected, so resume protection as soon as the job is done.
Update the BIOS or swap hardware
→ Suspend protection (resume afterwards)
Recovery screens keep appearing
→ Start with the recovery key, then fix the cause (boot order, attached devices)
Sell, give away or dispose of the PC
→ Don't decrypt; reset with Remove everything + Clean data
Stop encrypting altogether (your own PC)
→ Turn off BitLocker (steps below)
Before a BIOS or firmware update: suspend protection
Microsoft advises suspending protection before firmware updates from your PC maker, TPM firmware updates (the TPM is the chip that guards the encryption key), and other updates that change boot components. If you don't, you'll be asked for the recovery key on the next restart. Microsoft updates delivered through Windows Update need no action from you.
Choose Suspend protection in Control Panel
Open Control Panel > System and Security > BitLocker Drive Encryption, choose Suspend protection next to the operating system drive (usually C:), and select Yes. Typing "BitLocker" in Start and choosing Manage BitLocker opens the same screen.
Do the BIOS update or hardware swap
Follow your PC maker's instructions. To suspend from the command line instead, run Suspend-BitLocker -MountPoint "C:" -RebootCount 0 in PowerShell opened as administrator. -RebootCount sets how many restarts happen before protection resumes on its own; 0 keeps it suspended until you resume it manually.
Choose Resume protection when done
Choose Resume protection on the same screen, or run Resume-BitLocker -MountPoint "C:". On resume, BitLocker reseals the key to the updated state of the PC.
Windows Home's Device encryption has no BitLocker Drive Encryption screen in Control Panel. Microsoft says BitLocker is suspended automatically when a TPM firmware update clears the TPM through Windows APIs, but not every update works that way. On Home, the best preparation before a BIOS update from your PC maker is to have the recovery key saved.
How to turn it off, by edition
Both methods need you to be signed in with an administrator account. You can check your edition in Settings > System > About. For how BitLocker and Device encryption differ, see BitLocker vs Device encryption.
| Edition | Feature name | Where to turn it off |
|---|---|---|
| Windows 11 Pro / Enterprise / Education | BitLocker Drive Encryption | Turn off BitLocker in Control Panel, or manage-bde -off |
| Windows 11 Home | Device encryption | Settings > Privacy & security > Device encryption, toggle off |
| PC managed by your work or school | Managed by organization policy | Don't turn it off yourself (ask IT) |
Windows 11 Pro: from Control Panel
Open Manage BitLocker
Type "BitLocker" in Start and choose Manage BitLocker. The BitLocker Drive Encryption screen opens and shows the state of each drive.
Choose Turn off BitLocker for the drive
Choose Turn off BitLocker next to the drive you want to decrypt (usually the OS drive, C:), then confirm with Turn off BitLocker in the dialog. Decryption starts here.
Wait for it to finish
The screen shows decryption progress, and you can keep using the PC. When it finishes, the drive's status changes to Off.
Windows 11 Pro: from the command line (manage-bde -off)
To decrypt from the command line, open Terminal with Run as administrator and run:
manage-bde -off C:
Microsoft explains that this command disables the protectors while it decrypts and removes all key protectors once decryption completes. Check progress with manage-bde -status: when Percentage Encrypted reaches 0%, it's done.
Windows 11 Home: switch off Device encryption
Open the Device encryption setting
Go to Settings > Privacy & security > Device encryption. If you don't see it, Device encryption may not be available on that PC, or you may be signed in with a standard user account.
Switch the toggle off
Switch Device encryption off. If a confirmation appears, confirm that you want to turn it off. Decryption starts here.
Wait for it to finish
The same screen shows decryption progress. You can keep using the PC until it finishes.
How long it takes, and power
Decryption time depends on the drive type (SSD or HDD), its size and its speed; Microsoft names the same factors for encryption. As a rough guide, it can finish in tens of minutes, or take several hours on a large HDD.
- You can use the PC normally while it decrypts
- Microsoft says that if the PC loses power or hibernates midway, decryption resumes where it stopped the next time Windows starts
- Even so, keep a laptop plugged into its charger so a flat battery doesn't keep interrupting it
- Confirm it finished in Control Panel or with
manage-bde -status
What you give up by turning it off
BitLocker protects what's on the PC or drive while the power is off. Once you decrypt:
- If your laptop is stolen or left behind, anyone can remove the drive and read its contents
- PCs sent for repair and drives you throw away become readable too
- Protection while you're signed in and using the PC doesn't change either way
The more you carry the laptop around, the bigger this difference. For protecting a PC away from home, see laptop security when you travel. For how BitLocker itself works, see What is BitLocker?
Don't turn it off on a work or school PC
Microsoft notes that on organization-managed devices, BitLocker is typically managed by the IT department under the organization's policy. Decrypting a PC issued by your employer or school may break its rules, and depending on how it is managed, it may be encrypted again automatically. If you're stuck on a recovery screen, check the recovery key for your work or school account (aka.ms/aadrecoverykey) or contact your IT help desk.
Selling, giving away or disposing of a PC: reset, don't decrypt
Decrypting turns the data back into a readable state. It does not erase anything. Decrypting before you hand over a PC actually leaves its contents easier to read.
Microsoft advises that if you plan to donate, recycle or sell your PC, you turn on Clean data when you reset it. That option removes your files and cleans the drive, making it harder for others to recover what you deleted.
Back up what you want to keep
A reset removes all files, apps and settings. Move what you need to an external drive or cloud storage first.
Choose Reset PC, then Remove everything
Go to Settings > System > Recovery, choose Reset PC, then choose Remove everything.
Turn on Clean data under Change settings
On the Additional settings screen, choose Change settings, turn on Clean data, and follow the on-screen steps to reset. It takes longer, but it's the option to use for a PC you're letting go of.
This site's view: name the problem you're trying to solve with turning it off
Most people searching for how to turn off BitLocker don't object to encryption itself. They want to fix something in front of them: a recovery screen, a BIOS update, getting rid of the PC. Most of those can be fixed without decrypting. A BIOS update needs only a suspend, and disposal needs a reset.
If recovery screens keep appearing, look for the cause before decrypting. Microsoft lists changes to the boot order, adding or removing hardware, and removing or fully draining a laptop's battery among the causes. Remove the cause and keep the recovery key outside the PC, and you can keep encryption on without trouble.
Sources (official)
- Microsoft Learn, "BitLocker operations guide" (suspend and resume, turn off BitLocker) — learn.microsoft.com
- Microsoft Learn, "BitLocker FAQ" (suspend vs decrypt, suspending for updates, power loss, causes of recovery mode) — learn.microsoft.com
- Microsoft Learn, "Suspend BitLocker protection for non-Microsoft software updates" — learn.microsoft.com
- Microsoft Learn, "manage-bde off" — learn.microsoft.com
- Microsoft Support, "BitLocker Drive Encryption" — support.microsoft.com
- Microsoft Support, "Device encryption in Windows" — support.microsoft.com
- Microsoft Support, "Find your BitLocker recovery key" — support.microsoft.com
- Microsoft Support, "Reset your PC" — support.microsoft.com
Read next
- Recovery key: How to find your BitLocker recovery key
- Differences: BitLocker vs Device encryption
- Term: What is BitLocker? (disk encryption)
- On the go: Laptop security when you travel
FAQ
QWill turning off BitLocker delete my files?
No. Turning off BitLocker decrypts the drive back to its original state, and your files stay where they are. Still, back up important files and keep your recovery key handy before you start, in case something goes wrong.
QHow long does it take to turn off BitLocker?
It depends on the type, size and speed of the drive; Microsoft names the same factors for encryption time. As a rough guide, it can take anything from tens of minutes to several hours. You can keep using the PC meanwhile, and Microsoft says that if the power goes off, decryption picks up where it stopped the next time Windows starts.
QDo I need to turn off BitLocker before a BIOS update?
No. Microsoft advises using Suspend protection, a temporary pause, before firmware (BIOS/UEFI) updates from your PC maker. If you don't, you may be asked for the recovery key on the next restart. When the update is done, choose Resume protection.
QHow do I turn off BitLocker on Windows 11 Home?
Home has no Manage BitLocker screen; it is encrypted by a feature called Device encryption. Go to Settings > Privacy & security > Device encryption and switch the toggle off to start decryption. You must be signed in with an administrator account.
QShould I turn off BitLocker before selling my PC?
There's no need, because decrypting does not erase anything. Microsoft advises that if you plan to donate, recycle or sell your PC, you reset it with Remove everything and turn on the Clean data option.
QCan I turn off BitLocker on my work laptop?
Don't do it yourself. Microsoft notes that on organization-managed devices, BitLocker is typically managed by the IT department under the organization's policy. If you're stuck on a recovery screen, contact your IT help desk.