• September 30, 2026
  • 7 mins
How to Remove BitLocker: A Step-by-Step Guide to Disabling Encryption Safely

Have you ever needed to move a drive to another PC, only to hit a wall of encryption prompts? Knowing how to remove BitLocker can save you time and frustration. Just as important, it helps you avoid a security mistake that leaves your data exposed.

BitLocker is the built-in Windows tool that encrypts your drives so a lost or stolen device cannot easily give up its data. Sometimes you need to turn it off, for example when you are repairing a PC, selling hardware, or fixing performance issues. This guide shows you how to remove BitLocker step by step, and how to keep your data safe afterward.

What Is BitLocker and Why Would You Remove It?

BitLocker is a full-disk encryption feature available in Windows Pro, Enterprise, and Education editions. It scrambles the contents of a drive so only someone with the right password, PIN, TPM chip, or recovery key can read it.

People usually remove BitLocker for reasons like these:

  • Upgrading hardware or reinstalling Windows
  • Moving a drive to another computer
  • Troubleshooting boot problems or recovery-key prompts
  • Retiring or reassigning a company device
  • Resolving compatibility issues with older tools

Removing BitLocker means the drive will be decrypted, so anyone with physical access can read it. Only do this when it is truly necessary.

Before You Remove BitLocker: Preparation Checklist

Complete these steps first to avoid data loss or lockouts:

  1. Back up your important files. Decryption is normally safe, but a power failure mid-process can cause problems.
  2. Locate your BitLocker recovery key. Check your Microsoft account, a printed copy, a USB drive, or your organization’s Active Directory or Entra ID.
  3. Sign in as an administrator. Standard accounts cannot change encryption settings.
  4. Plug in your laptop. Decryption can take a long time on large drives.
  5. Check your company policy. On managed devices, Group Policy or your IT team may require BitLocker to stay on.

How to Remove BitLocker Using Windows Settings

This is the simplest option in Windows 10 and Windows 11.

  1. Open Start and go to Settings > Privacy & security > Device encryption (on some editions, search for Manage BitLocker).
  2. Select the drive you want to change.
  3. Click Turn off BitLocker.
  4. Confirm by clicking Turn off BitLocker again.

Windows starts decrypting the drive in the background. You can keep working, though your PC may run slower until it finishes.

How to Remove BitLocker from Control Panel

  1. Open Control Panel > System and Security > BitLocker Drive Encryption.
  2. Find the encrypted drive and click Turn off BitLocker.
  3. If the drive is locked, click Unlock drive and enter your password or recovery key first.
  4. Confirm the prompt and wait for decryption to complete.

How to Remove BitLocker Using Command Prompt (manage-bde)

Admins often prefer the command line for speed and scripting.

  1. Search for cmd, right-click Command Prompt, and choose Run as administrator.
  2. Check the current status:
 
manage-bde -status
  1. If the drive is locked, unlock it with your recovery password:
 
manage-bde -unlock D: -RecoveryPassword YOUR-48-DIGIT-KEY
  1. Turn off BitLocker and start decryption:
 
manage-bde -off D:

Replace D: with your drive letter. Run manage-bde -status again to see the decryption percentage.

How to Remove BitLocker with PowerShell

PowerShell offers a clean one-line option:

 
Disable-BitLocker -MountPoint "C:"

To check progress, run:

 
Get-BitLockerVolume

The Conversion Status shows Fully Decrypted when the process is done.

Quick Comparison of Methods

Method Best For Skill Level
Windows Settings Everyday users Beginner
Control Panel Older Windows 10 setups Beginner
Command Prompt Admins and scripts Intermediate
PowerShell Automation and reporting Intermediate

Common Problems When You Try to Remove BitLocker

  • “Turn off BitLocker” is greyed out. Your organization’s Group Policy may enforce encryption, or you may lack admin rights.
  • You cannot find the recovery key. Check your Microsoft account, your workplace account, or ask your IT administrator. Without it, a locked drive is generally unrecoverable.
  • Decryption seems stuck. Large drives can take hours. Keep the PC powered on and avoid heavy tasks.
  • The drive is locked and will not unlock. Enter the recovery key through manage-bde or the unlock prompt.
  • Option missing on Windows Home. Home editions offer “Device encryption,” which is managed under Settings instead.

Why Removing BitLocker Matters for Cybersecurity

Disk encryption is a key defense against data theft. If a laptop is lost or stolen and its drive is not encrypted, an attacker can read files by connecting the drive to another machine. That can lead to a costly data breach, regulatory penalties, and lost customer trust.

Attackers also misuse encryption. Ransomware groups have been known to abuse legitimate tools, including BitLocker, to lock victims out of their own systems. That is why unexpected encryption activity, or a sudden recovery-key prompt you did not trigger, deserves attention.

Watch for these warning signs:

  • BitLocker turning on or off without your approval
  • A ransom note or unfamiliar recovery key on a machine you manage
  • Unknown scripts running manage-bde or Disable-BitLocker
  • Encryption changes on many devices at once

Security Best Practices After You Remove BitLocker

Do not leave a drive unprotected longer than necessary. Follow these tips:

  • Re-encrypt when the task is done. Turn BitLocker back on or use another trusted encryption tool.
  • Store recovery keys safely. Keep them in a secure vault or your identity platform, never in a plain text file on the same device.
  • Limit who can change encryption settings. Use least-privilege access and Group Policy.
  • Wipe drives properly before disposal. Decryption alone does not erase data.
  • Monitor endpoint activity. Use endpoint detection and response (EDR) to flag unusual encryption or command-line behavior.
  • Adopt a zero-trust approach. Treat unknown files and processes as untrusted until verified, so threats are contained before they reach your data.

Frequently Asked Questions (FAQ)

1. How do I remove BitLocker from a drive?

Open Settings > Privacy & security > Device encryption (or Manage BitLocker), select the drive, and click Turn off BitLocker. You can also run manage-bde -off D: in an administrator Command Prompt.

2. Can I remove BitLocker without the password or recovery key?

No. Without the password, PIN, or recovery key, you cannot unlock an encrypted drive. If you have lost them, check your Microsoft account or contact your IT administrator. Formatting the drive is the only alternative, and it erases all data.

3. Will I lose data if I remove BitLocker?

Normally no. Decryption keeps your files intact. Still, back up first, keep your device powered on, and do not interrupt the process.

4. How long does it take to remove BitLocker?

It depends on drive size, speed, and system load. A small SSD may finish in under an hour, while a large hard drive can take several hours.

5. Is it safe to remove BitLocker?

It is safe if you do it for a good reason and take precautions. However, a decrypted drive is readable by anyone who gets physical access, so re-enable encryption or use another protection method as soon as you can.

Conclusion: Decrypt With Care, Then Protect Your Data

Now you know how to remove BitLocker with Settings, Control Panel, CMD, and PowerShell. Whichever method you choose, back up your data, keep your recovery key handy, and re-secure the drive when you finish. Encryption is only one layer, and it will not stop unknown malware already running on your endpoint.

Xcitium’s zero-trust endpoint protection contains unknown threats before they can damage your system or steal your data, whether your drives are encrypted or not.

👉 Request a Demo and see how Xcitium can protect your endpoints, users, and data.

Like what you see? Share with a friend.

Please give us a star rating based on your experience.

15 votes, average: 2.07 out of 515 votes, average: 2.07 out of 515 votes, average: 2.07 out of 515 votes, average: 2.07 out of 515 votes, average: 2.07 out of 5 (15 votes, average: 2.07 out of 5, rated)
Patented Threat Prevention
Built For Today

Zero-day malware can't be stopped from entering,
but Xcitium prevents damage entirely. Zero infection.

By clicking “Accept All" button, you agree to the storing of cookies on your device to enhance site navigation, analyze site usage, and assist in our marketing efforts. Cookie Disclosure

Manage Consent Preferences

When you visit any website, it may store or retrieve information on your browser, mostly in the form of cookies. This information might be about you, your preferences or your device and is mostly used to make the site work as you expect it to. The information does not usually directly identify you, but it can give you a more personalized web experience. Because we respect your right to privacy, you can choose not to allow some types of cookies. Click on the different category headings to find out more and change our default settings. However, blocking some types of cookies may impact your experience of the site and the services we are able to offer.

These cookies are necessary for the website to function and cannot be switched off in our systems. They are usually only set in response to actions made by you which amount to a request for services, such as setting your privacy preferences, logging in or filling in forms. You can set your browser to block or alert you about these cookies, but some parts of the site will not then work. These cookies do not store any personally identifiable information.
These cookies allow us to count visits and traffic sources so we can measure and improve the performance of our site. They help us to know which pages are the most and least popular and see how visitors move around the site. All information these cookies collect is aggregated and therefore anonymous. If you do not allow these cookies we will not know when you have visited our site, and will not be able to monitor its performance.
These cookies enable the website to provide enhanced functionality and personalisation. They may be set by us or by third party providers whose services we have added to our pages. If you do not allow these cookies then some or all of these services may not function properly.
These cookies may be set through our site by our advertising partners. They may be used by those companies to build a profile of your interests and show you relevant adverts on other sites. They do not store directly personal information, but are based on uniquely identifying your browser and internet device. If you do not allow these cookies, you will experience less targeted advertising.