Adding pre-boot authentication PIN with Device Encryption in Windows 11 Home


fracu77polt

New member
Local time
8:46 AM
Posts
5
OS
Windows 11
Hi,
I would like to know how I can enable pre-boot authentication in Device Encryption (so not real Bitlocker) in Windows 11 Home with a local account.
I found this tutorial on how to add a recovery key when using Device Encryption and a local account( since you do not have any settings for this when you are not logged in into an MS account and use Home), but I would like to know how to add a pre-boot authentication as well.

Thank you very much!
 

My Computer My Computer

At a glance

Windows 11
OS
Windows 11
If you can type manage-bde in a command prompt, powershell or terminal and the tool is available than yes you could add that pin. I only run Pro editions which definitely do have that utility for managing drive encryption.
 

My Computer My Computer

At a glance

Linux Mint
OS
Linux Mint
Computer type
Laptop
Manufacturer/Model
System76 Lemur Pro

My Computer My Computer

At a glance

Windows 11
OS
Windows 11
Computer type
Laptop
That is exactly why I was asking. Maybe others (@Brink maybe?) can chime in if it is possible in any way, since using it without any pre-boot-authentication doesn't really make that much sense.

Hello, :alien:

You'll need to upgrade to Windows 11 Pro to have BitLocker available for the OS drive to require a PIN or USB to unlock the OS drive at startup/boot.


For now in Windows 11 Home, you could require a PIN or password to sign in to Windows with. It's not the same as at startup/boot, but at least this way the drive doesn't get unlocked by Device Encryption until you sign in.
 

My Computers My Computers

  • At a glance

    Windows 11 Pro for WorkstationsIntel i7-8700K 5 GHz64 GB (4x16GB) G.SKILL TridentZ RGB DDR4 3600...ASUS ROG-STRIX-GTX1080TI-O11G-GAMING (11GB GD...
    OS
    Windows 11 Pro for Workstations
    Computer type
    PC/Desktop
    Manufacturer/Model
    Custom self build
    CPU
    Intel i7-8700K 5 GHz
    Motherboard
    ASUS ROG Maximus XI Formula Z390
    Memory
    64 GB (4x16GB) G.SKILL TridentZ RGB DDR4 3600 MHz (F4-3600C18D-32GTZR)
    Graphics Card(s)
    ASUS ROG-STRIX-GTX1080TI-O11G-GAMING (11GB GDDR5X)
    Sound Card
    Integrated Digital Audio (S/PDIF)
    Monitor(s) Displays
    2 x Samsung Odyssey G75 27"
    Screen Resolution
    2560x1440
    Hard Drives
    1TB Samsung 990 PRO M.2,
    4TB Samsung 990 PRO M.2,
    TerraMaster F8 SSD Plus NAS
    PSU
    Seasonic Prime Titanium 850W
    Case
    Thermaltake Core P3 wall mounted
    Cooling
    Corsair Hydro H115i
    Keyboard
    Amazon Basics Wired Full Keyboard MD005
    Mouse
    Logitech MX Master 4
    Internet Speed
    2 Gbps Download and 100 Mbps Upload
    Browser
    Chrome and Edge
    Antivirus
    Microsoft Defender
    Other Info
    Logitech Z625 speaker system,
    Logitech BRIO 4K Pro webcam,
    HP Color LaserJet Pro MFP M477fdn,
    CyberPower CP1500PFCLCD
    Galaxy S23 Plus phone
  • At a glance

    Windows 11 ProSnapdragon X Elite (12 core) 3.42 GHz16 GB LPDDR5x-7467 MHz
    Operating System
    Windows 11 Pro
    Computer type
    Laptop
    Manufacturer/Model
    Surface Laptop 7 Copilot+ PC
    CPU
    Snapdragon X Elite (12 core) 3.42 GHz
    Memory
    16 GB LPDDR5x-7467 MHz
    Monitor(s) Displays
    15" HDR
    Screen Resolution
    2496 x 1664
    Hard Drives
    1 TB SSD
    Internet Speed
    Wi-Fi 7 and Bluetooth 5.4
    Browser
    Chrome and Edge
    Antivirus
    Microsoft Defender
Oh what a shame. I was really hoping this was possible. Of course, setting a Windows sign-in password is mandatory regardless of Bitlocker IMHO, but I was hoping to be able to set an additional layer of protection....
 

My Computer My Computer

At a glance

Windows 11
OS
Windows 11
BitLocker without pre-boot authorization is really a mechanism to protect encrypted drives. If someone grabs your drive without the key stored in the TPM, they can't decrypt your drive. However, if someone (like governments or other organizations) has access to forensics tools, such as ways to extract the key from the TPM (like the "cheap" hardware "key" often mentioned for bypassing TPM), bypassing login screens, or performing a cold-boot attack to capture the contents in memory, they WILL be able to access your BitLocker-protected system drive.

BitLocker with pre-boot authorization is a mechanism to protect encrypted drives along with the TPM. Without a PIN, for example, you can't extract the encrypted materials to decrypt the drive at all. BitLocker with TPM+PIN is currently considered very secure with no widely-known practical attacks assuming proper implementation and no TPM hardware vulnerabilities.
 

My Computer My Computer

At a glance

Windows 11 Pro 25H2
OS
Windows 11 Pro 25H2
Computer type
PC/Desktop
How about setting a PIN or password in BIOS?
 

My Computers My Computers

  • At a glance

    Windows 11 Pro 25H2 26200.9278AMD Ryzen 7 5825U with Radeon Graphics16GB
    OS
    Windows 11 Pro 25H2 26200.9278
    Computer type
    Laptop
    Manufacturer/Model
    Acemagic LX15PRO
    CPU
    AMD Ryzen 7 5825U with Radeon Graphics
    Motherboard
    BIOS CT_BI_AMI_LX15PRO_AB8139_A-004
    Memory
    16GB
    Screen Resolution
    1920 x 1080
    Hard Drives
    SSD 2TB
    Internet Speed
    30 Mbps
    Browser
    Brave
    Antivirus
    Webroot SecureAnywhere Complete beta
  • At a glance

    Windows 11 Pro 23H2 22631.2506Atom N450 1.66GHz2GB
    Operating System
    Windows 11 Pro 23H2 22631.2506
    Computer type
    Laptop
    Manufacturer/Model
    HP Mini 210-1090NR PC (bought in late 2009!)
    CPU
    Atom N450 1.66GHz
    Memory
    2GB
    Browser
    Brave
    Antivirus
    Webroot
  • Acer Swift SF114-34 laptop
    OS Windows 11 Pro 26200.8894
    CPU Pentium Silver N6000
    RAM 4GB
    BIOS v1.17
    SSD Samsung 970 EVO Plus SSD 2TB (an upgrade)
@kelper but that wouldn't help with the data being accessible like @echo2446 mentioned?

Are there other ways to encrypt the system drive that work well with Windows?
 

My Computer My Computer

At a glance

Windows 11
OS
Windows 11
Are there other ways to encrypt the system drive that work well with Windows?
Some people, not trusting Microsoft, do use VeraCrypt (which doesn't use TPM) to protect their system drive. This requires another strong password to boot the system, which is secure but not very convenient. Also, in my own testing, VeraCrypt degraded FDE performance more significantly (by tens of percentage points) than BitLocker (which had single-digit percentage impact), despite the recommended tweaks I tested. You may also be more prone to encounter Windows/System updates more often, as the number of users relying on VeraCrypt may not influence how those updates are tested.

I personally suggest that if you really need to protect against some physical attacks on your system, you should consider using Windows Pro (if Windows is your preference).

Remember that from a Windows system integration standpoint, nobody is going to beat Microsoft.
 
Last edited:

My Computer My Computer

At a glance

Windows 11 Pro 25H2
OS
Windows 11 Pro 25H2
Computer type
PC/Desktop
VeraCrypt works well with Windows
its open source freeware but i strongly recommend you read the howto files.

it will require a password to unlock the drive at boot and it will encrypt C: drive
without any major work but please read the howto file first as you have to disable (A). fast boot
then once installed go into the BIOS and (B). change the boot order so VeraCrypt is first in the boot order.

also ensure in Windows services you stop and disable the bitlocker service
and don't forget the password as there is no get out of jail card with VeraCrypt
unless you make a boot USB with the backup files for the encryption.

best of luck Steve ..
 

My Computers My Computers

  • At a glance

    Windows 11 HomeRyzen 7 5825u64GB DDR4 3200Ryzen 7 5825u
    OS
    Windows 11 Home
    Computer type
    PC/Desktop
    Manufacturer/Model
    HP 24" AiO
    CPU
    Ryzen 7 5825u
    Motherboard
    HP
    Memory
    64GB DDR4 3200
    Graphics Card(s)
    Ryzen 7 5825u
    Sound Card
    Realtek External 5w speaker bar.
    Monitor(s) Displays
    24" HP AiO
    Screen Resolution
    1920 x 1080 @60 Hz
    Hard Drives
    1TB WD Blue SN580 M2 SSD Partitioned C:/D: drives.
    2x 1TB USB HDD External Backup/Storage.
    all VeraCrypt encrypted.
    PSU
    90W external power brick
    Case
    24" All in One
    Cooling
    Default Air Cooling
    Keyboard
    Dell WiFi UK extended
    Mouse
    Dell WiFi 3 Button
    Internet Speed
    1GB full fibre
    Browser
    Vivaldi Browser/Email/Calendar
    Antivirus
    AVG Internet Security/Windows Defender
    Other Info
    Mainly Open Source Software
  • At a glance

    Ubuntu 22.04.5 LTSi5 7200u16GB DDR4Intel
    Operating System
    Ubuntu 22.04.5 LTS
    Computer type
    Laptop
    Manufacturer/Model
    Dell 13" Latitude 2017
    CPU
    i5 7200u
    Motherboard
    Dell
    Memory
    16GB DDR4
    Graphics card(s)
    Intel
    Sound Card
    Intel
    Monitor(s) Displays
    13" Dell Laptop
    Hard Drives
    250GB Crucial 2.5" SSD
    Mouse
    Generic WiFi 3 button
    Internet Speed
    WiFi only
    Browser
    Firefox
    Antivirus
    ClamAV TK
    Other Info
    Mainly Open Source Software
On my first Win 11 machine, I paid $99 through the MS App Store


Well worth it.

My subsequent machine already came with Win 11 Pro on it, so no hassle, there.
 

My Computers My Computers

  • At a glance

    Windows 11 Pro 25H2 build: (26200.7623)32GB
    OS
    Windows 11 Pro 25H2 build: (26200.7623)
    Computer type
    Laptop
    Manufacturer/Model
    Microsoft Surface Pro
    Memory
    32GB
  • At a glance

    Microsoft 25H2 ProIntel Core Ultra 764GBIntel Integrated Graphics
    Operating System
    Microsoft 25H2 Pro
    Computer type
    Laptop
    Manufacturer/Model
    Dell Pro 14 - PC14250
    CPU
    Intel Core Ultra 7
    Memory
    64GB
    Graphics card(s)
    Intel Integrated Graphics
    Hard Drives
    Micron 1TB SSD
Windows does have a built-in Drive Encryption feature, which you probably already know about; and according to this guide Windows 11 Device Encryption With Local Account it can work with a Local Account.

The alternative would be to use some third-party software, most of which is commercial, but the Open-Source Veracrypt software does have a similar feature. Veracrypt: System Encryption

Obviously, the cost of any third-party commercial option would need to be weighed against the cost of upgrading to Windows Pro, but whatever option is chosen requires a secure bacik-up system for storing encryption/decryption keys.
 

My Computers My Computers

  • At a glance

    macOS 14.x (plus Windows 11, Debian, FreeBSD ...Apple M1 Max (T6001) - 8 performance 2 effici...32GB LPDDR5Apple M1 Max (32-core)
    OS
    macOS 14.x (plus Windows 11, Debian, FreeBSD for ARM64)
    Computer type
    Laptop
    Manufacturer/Model
    MacBook Pro M1 MAX
    CPU
    Apple M1 Max (T6001) - 8 performance 2 efficiency cores
    Memory
    32GB LPDDR5
    Graphics Card(s)
    Apple M1 Max (32-core)
    Hard Drives
    a) 1TB SSD + + 1TB SD Card + external SSD Drives
    Browser
    1. Safari 2. DuckDuckGo
    Antivirus
    -
  • At a glance

    Windows 11 Pro, plus VirtualBox VMs: various ...i732GB
    Operating System
    Windows 11 Pro, plus VirtualBox VMs: various Windows & Linux
    Computer type
    Laptop
    Manufacturer/Model
    Microsoft Surface Laptop Studio
    CPU
    i7
    Memory
    32GB
    Hard Drives
    1TB SSD, plus external SSDs for Virtual Machines etc.
    Browser
    1. MS Edge 2. DuckDuckGo
    Antivirus
    Defender
Thank you everyone.

@XxXxX Can you re-enable fast boot afterwards? And what about Secure Boot: I read that you need to disable that as well? That is not ideal...

@LeLibran yes, as mentioned in my first post I know how to enable the decryption with a local account. But it is unfortunately not possible to set a pre-boot authentication with this method.
 

My Computer My Computer

At a glance

Windows 11
OS
Windows 11
Thank you everyone.

@XxXxX Can you re-enable fast boot afterwards? And what about Secure Boot: I read that you need to disable that as well? That is not ideal...

@LeLibran yes, as mentioned in my first post I know how to enable the decryption with a local account. But it is unfortunately not possible to set a pre-boot authentication with this method.

no you will be able to enable fast boot, hence the reading of the VeraCrypt howto is highly recommended.
as fast boot will interfere with how VeraCrypt operates.

best of luck Steve ..
 

My Computers My Computers

  • At a glance

    Windows 11 HomeRyzen 7 5825u64GB DDR4 3200Ryzen 7 5825u
    OS
    Windows 11 Home
    Computer type
    PC/Desktop
    Manufacturer/Model
    HP 24" AiO
    CPU
    Ryzen 7 5825u
    Motherboard
    HP
    Memory
    64GB DDR4 3200
    Graphics Card(s)
    Ryzen 7 5825u
    Sound Card
    Realtek External 5w speaker bar.
    Monitor(s) Displays
    24" HP AiO
    Screen Resolution
    1920 x 1080 @60 Hz
    Hard Drives
    1TB WD Blue SN580 M2 SSD Partitioned C:/D: drives.
    2x 1TB USB HDD External Backup/Storage.
    all VeraCrypt encrypted.
    PSU
    90W external power brick
    Case
    24" All in One
    Cooling
    Default Air Cooling
    Keyboard
    Dell WiFi UK extended
    Mouse
    Dell WiFi 3 Button
    Internet Speed
    1GB full fibre
    Browser
    Vivaldi Browser/Email/Calendar
    Antivirus
    AVG Internet Security/Windows Defender
    Other Info
    Mainly Open Source Software
  • At a glance

    Ubuntu 22.04.5 LTSi5 7200u16GB DDR4Intel
    Operating System
    Ubuntu 22.04.5 LTS
    Computer type
    Laptop
    Manufacturer/Model
    Dell 13" Latitude 2017
    CPU
    i5 7200u
    Motherboard
    Dell
    Memory
    16GB DDR4
    Graphics card(s)
    Intel
    Sound Card
    Intel
    Monitor(s) Displays
    13" Dell Laptop
    Hard Drives
    250GB Crucial 2.5" SSD
    Mouse
    Generic WiFi 3 button
    Internet Speed
    WiFi only
    Browser
    Firefox
    Antivirus
    ClamAV TK
    Other Info
    Mainly Open Source Software
When I suggested a password in BIOS I meant two. One to prevent others changing any BIOS settings AND a user setting which prevents anyone from accessing the OS or changing the boot order or booting from a USB device.
 

My Computers My Computers

  • At a glance

    Windows 11 Pro 25H2 26200.9278AMD Ryzen 7 5825U with Radeon Graphics16GB
    OS
    Windows 11 Pro 25H2 26200.9278
    Computer type
    Laptop
    Manufacturer/Model
    Acemagic LX15PRO
    CPU
    AMD Ryzen 7 5825U with Radeon Graphics
    Motherboard
    BIOS CT_BI_AMI_LX15PRO_AB8139_A-004
    Memory
    16GB
    Screen Resolution
    1920 x 1080
    Hard Drives
    SSD 2TB
    Internet Speed
    30 Mbps
    Browser
    Brave
    Antivirus
    Webroot SecureAnywhere Complete beta
  • At a glance

    Windows 11 Pro 23H2 22631.2506Atom N450 1.66GHz2GB
    Operating System
    Windows 11 Pro 23H2 22631.2506
    Computer type
    Laptop
    Manufacturer/Model
    HP Mini 210-1090NR PC (bought in late 2009!)
    CPU
    Atom N450 1.66GHz
    Memory
    2GB
    Browser
    Brave
    Antivirus
    Webroot
  • Acer Swift SF114-34 laptop
    OS Windows 11 Pro 26200.8894
    CPU Pentium Silver N6000
    RAM 4GB
    BIOS v1.17
    SSD Samsung 970 EVO Plus SSD 2TB (an upgrade)

Latest Support Threads

Back
Top Bottom