Enable Windows Device Encryption

Employees should make a reasonable effort to secure and protect devices that have access to University data. When traveling abroad with mobile devices such as laptops, tablets, and smartphones, additional measures are required. A step we can take is encrypting our device, which makes it difficult for invaders to gain access to the contents. 

Enable Device Encryption

If your device didn't automatically enable Device Encryption, here are the steps to enable it:

  1. Sign in to Windows with an administrator account
  2. In the SettingsApp Settings app on your Windows device, select Privacy security > Device encryption.

    Note:
    If Device encryption doesn't appear, it's either unavailable on your device, or you might be signed in with a standard user account.

  3. Use the toggle button to turn Device Encryption On

     

Why isn't Device Encryption available?

Here are the steps to determine why Device Encryption might not be available:

  1. From Start  WindowsLogo  type System Information, right-click System Information in the list of results, then select Run as administrator
  2. In the System Summary - Item's list, look for the value of Automatic Device Encryption Support or Device Encryption Support
    The value describes the support status of Device Encryption:
  • Meets prerequisites: Device Encryption is available on your device
  • TPM is not usable: your device doesn't have a Trusted Platform Module (TPM), or the TPM isn't enabled in the BIOS or in the UEFI
  • WinRE is not configured: your device doesn't have Windows Recovery Environment configured
  • PCR7 binding is not supported: Secure Boot is disabled in the BIOS/UEFI, or you have peripherals connected to your device during boot (like specialized network interfaces, docking stations, or external graphic card)
This Content Last Updated:
08/21/2026

For Help Please Contact


Customer Engagement and Support
Estimated Read Time:
1 minutes
This Content Last Updated:
08/21/2026