Enable Windows Device Encryption
Employees should make a reasonable effort to secure and protect devices that have access to University data. When traveling abroad with mobile devices such as laptops, tablets, and smartphones, additional measures are required. A step we can take is encrypting our device, which makes it difficult for invaders to gain access to the contents.
Enable Device Encryption
If your device didn't automatically enable Device Encryption, here are the steps to enable it:
- Sign in to Windows with an administrator account
In the
Settings app on your Windows device, select Privacy security > Device encryption.Note:
If Device encryption doesn't appear, it's either unavailable on your device, or you might be signed in with a standard user account.Use the toggle button to turn Device Encryption On
Why isn't Device Encryption available?
Here are the steps to determine why Device Encryption might not be available:
- From Start
type System Information, right-click System Information in the list of results, then select Run as administrator - In the System Summary - Item's list, look for the value of Automatic Device Encryption Support or Device Encryption Support
The value describes the support status of Device Encryption:
- Meets prerequisites: Device Encryption is available on your device
- TPM is not usable: your device doesn't have a Trusted Platform Module (TPM), or the TPM isn't enabled in the BIOS or in the UEFI
- WinRE is not configured: your device doesn't have Windows Recovery Environment configured
- PCR7 binding is not supported: Secure Boot is disabled in the BIOS/UEFI, or you have peripherals connected to your device during boot (like specialized network interfaces, docking stations, or external graphic card)