34,333
edits
Changes
→Performing the Encryption and Generating Keys
With all the appropriate features and settings configured it is now time to perform the encryption. Open the BitLocker control panel as outlined above and click on the ''Turn on BitLocker'' link beneath the drive to be encrypted. The resulting dialog will warn you that BitLocker Encryption decreases performance and provide the option to cancel the operation. To proceed select ''Continue with BitLocker Drive Encryption''.
The next screen to appear is the ''Set BitLocker startup preferences'' screen. The options provided on this screen will be governed by whether ths the host system has a TPM or not. The following figure shows the screen on a system without a TPM, and as such only provides the option to use BitLocker with a USB flash drive containing a startup key:
Do not save the recovery password on the same USB device as the startup key, but instead insert a different device. It is also recommended that multiple copies of the password be kept so it also recommended adviced that the password be printed out and kept safely on file. Once the recovery password has been saved click ''Next'' to proceed. On the final screen , make sure the ''Run BitLocker system check'' toggle is set and click ''Continue'' to begin the encryption process. The system will restart and begin the encryption process, indicated by a dialog with a progress bar.
Once the encryption process is complete the startup key or PIN (depending on the configuration settings) will be required next time the system is started.