Enable BitLocker AES-XTX 256 encryption algorithm

 
 
  • Gérald Barré

Windows 10 version 1511 introduced a new encryption algorithm, AES-XTX, designed specifically for encrypting drives. By default, Windows 10 1511 uses AES-XTX 128. If you want stronger protection for sensitive data, you can switch to AES-XTX 256. Here is how to enable it.

  1. Open the Local Group Policy Editor
  2. Select Computer Configuration / Administrative Templates / Windows Components / BitLocker Drive Encryption
  3. Double-click on Choose drive encryption method and cipher strength (Windows 10 [Version 1511] and later)
  4. Select Enabled and choose the encryption algorithm you want
  5. Open Windows Explorer, right-click on a drive, and select Turn On BitLocker

You can check the encryption algorithm using the following command (as administrator):

Shell
manage-bde -status

Do you have a question or a suggestion about this post? Contact me!

Follow me:
Enjoy this blog?