Skip to content
OS-related partition diagram

Encryption

BitLocker turns every move into a crypto project

Updated May 2026 · 9 min read

Encrypted volumes still occupy physical sectors. Tools may refuse to slide them, or Windows may auto-unlock only when policies allow—plan protectors before you rearrange disks.

Understand protectors and recovery keys

TPM-only setups behave differently from TPM+PIN or USB-key protectors. Losing the recovery password is worse than losing free space.

Export recovery keys to a secure location before maintenance windows, not after something fails.

Resize and move cautions

Suspending BitLocker for one reboot is sometimes enough for in-Windows resizes; offline moves may still require full decryption depending on edition and policy.

Domain-joined machines may re-enable protection automatically—coordinate with IT before scripting changes.

Cloning encrypted disks

Cloning a mounted, unlocked volume is not the same as cloning at rest. Follow the guidance that ships with the edition you run.

Expect to re-enable or resume protection on the clone after it successfully boots as the system disk.

Related guides

← Back to all articles

Download