BitLocker drive encryption
Answer: BitLocker enablement is supported on Windows Pro, Enterprise, Pro Education/SE, and Education. Windows Home can provide automatic Device Encryption on qualifying hardware, but it is not the same management boundary.
Administrator playbook
Decide, verify, and document
Use the curated answer as a starting point, then prove the outcome against the target tenant or device.
What it means
- BitLocker enablement and BitLocker management have different licensing requirements
- Enterprise management rights can depend on Enterprise or Education licensing
- TPM and startup-authentication design affect the deployment experience
What to check next
- Separate automatic Device Encryption from administrator-managed BitLocker
- Confirm TPM, firmware, partition, and recovery-key escrow readiness
- Verify the exact management entitlement before enforcing organizational policy
Verify success
- Confirm the feature is present or enabled on the target edition and build.
- Test the intended workflow with a pilot device and least-privileged user.
- Confirm policy reports success from the actual management authority.
Escalate when
- The documented edition and hardware requirements are met but the feature is absent.
- Policy reports success while the user or device state is incorrect.
- Licensing or OEM terms—not technical prerequisites—control the outcome.
Copyable admin briefAnswer, next checks, source, and review date
Capture edition and build
Get-ComputerInfo | Select-Object WindowsProductName,WindowsVersion,OsBuildNumber,OsArchitectureRead-only. Edition and exact build often control availability.
List optional feature state
Get-WindowsOptionalFeature -Online | Where-Object State -ne "Disabled" | Select-Object FeatureName,StateRead-only. Not every Windows capability is represented as an optional feature.
Evidence to preserve
- Windows edition, version, and build
- Hardware and firmware prerequisites
- Management authority and policy source
- Required user or device experience
