Device encryption support requirements


MisterEd

Well-known member
Power User
VIP
Local time
2:53 AM
Posts
1,750
Location
Huntsville, AL
OS
Windows 11 Pro 25H2 (26200.6901)
Computer #1.webp

Computer #2.webp
Computer #3.webp
Compute Status.webp

Comments and questions

Computer #1:
I assume that Device Encryption Support is not supported because Secure Boot is not enabled.
Can I enable Secure Boot in the BIOS without having to reinstall Windows 11? Or should I just leave it as is?

Computer #2: I did a clean install of Windows 11 because of all the hardware and software changes since the computer was first built. Enabling UEFI and Secure Boot in the BIOS before this was done made the Windows 11 setup go very smoothly.
Is this why this is the only computer that fully supports drive encryption?

Computer #3: The original boot disk was moved to a different but identical laptop model.
Is that why Device Encryption is not supported? Would I have to reinstall Windows 11 to fix this?
 

My Computers My Computers

  • At a glance

    Windows 11 Pro 25H2 (26200.6901)AMD Ryzen 7 6800H with Radeon 680M GPU (486MB...Crucial DDR5-4800 (2400MHz) 32GB (2 x 16GB)NVIDIA RTX 3060 Laptop (6GB RAM)
    OS
    Windows 11 Pro 25H2 (26200.6901)
    Computer type
    Laptop
    Manufacturer/Model
    ASUS TUF Gaming A15 (2022)
    CPU
    AMD Ryzen 7 6800H with Radeon 680M GPU (486MB RAM)
    Memory
    Crucial DDR5-4800 (2400MHz) 32GB (2 x 16GB)
    Graphics Card(s)
    NVIDIA RTX 3060 Laptop (6GB RAM)
    Sound Card
    n/a
    Monitor(s) Displays
    15.6-inch
    Screen Resolution
    1920x1080 300Hz
    Hard Drives
    2 x Samsung 990 Evo Plus (2TB M.2 NVME SSD)
    PSU
    n/a
    Mouse
    Wireless Mouse M510
    Internet Speed
    2100Mbps/300Mbps
    Browser
    Firefox
    Antivirus
    Malwarebytes
  • At a glance

    Windows 11 Pro 25H2 (26200.8246)AMD Ryzen 7 5700X3DG.SKILL Flare X 32GB (2x16GB) DDR4ASUS ROG-STRIX-RTX3060TI-08G-V2-GAMING (RTX 3...
    Operating System
    Windows 11 Pro 25H2 (26200.8246)
    Computer type
    PC/Desktop
    Manufacturer/Model
    Custom build
    CPU
    AMD Ryzen 7 5700X3D
    Motherboard
    ASUS ROG Strix B550-F Gaming WiFi II
    Memory
    G.SKILL Flare X 32GB (2x16GB) DDR4
    Graphics card(s)
    ASUS ROG-STRIX-RTX3060TI-08G-V2-GAMING (RTX 3060-Ti, 8GB RAM)
    Monitor(s) Displays
    Samsung G50D IPS 27"
    Screen Resolution
    1440p/180Hz
    Hard Drives
    SAMSUNG 990 EVO Plus (2TB] M.2 NVME SSD
    SAMSUNG 990 EVO Plus (4TB) M.2 NVME SSD
    PSU
    Corsair RM750x (750 watts)
    Case
    Cooler Master MasterCase 5
    Cooling
    Scythe Mugen 6
    Keyboard
    Logitech K520 (MK540 keyboard/mouse combo)
    Mouse
    Logitech M310 (MK540 keyboard/mouse combo)
    Internet Speed
    2100 Mbps down / 300 Mbps up
    Browser
    Firefox, Edge, Chrome
    Antivirus
    Malwarebytes (Premium)
    Other Info
    ASUS Blu-ray Burner BW-16D1HT (SATA) || Western Digital Easystore 20TB USB 3.0 external hard drive used with Acronis True Image 2025 backup software || HP OfficeJet Pro 6975 Printer/Scanner
View attachment 152465

View attachment 152466
View attachment 152467
View attachment 152468

Comments and questions

Computer #1:
I assume that Device Encryption Support is not supported because Secure Boot is not enabled.
Can I enable Secure Boot in the BIOS without having to reinstall Windows 11? Or should I just leave it as is?

Computer #2: I did a clean install of Windows 11 because of all the hardware and software changes since the computer was first built. Enabling UEFI and Secure Boot in the BIOS before this was done made the Windows 11 setup go very smoothly.
Is this why this is the only computer that fully supports drive encryption?

Computer #3: The original boot disk was moved to a different but identical laptop model.
Is that why Device Encryption is not supported? Would I have to reinstall Windows 11 to fix this?

You are overthinking things. It really is quite simple.

All modern UEFI based PCs with TPM 2 support Device Encryption. Whether Device Encryption is actrive or not depends on situation.

Point 1: Device Encryption only activates automatically on clean installs with TPM enabled and secure boot on. Note: At one time device also needed to support Modern Standby as well, but that criterion has been removed.

Point 2: If you change pc from secure boot off to on AFTER installation, you have to manually turn device encryption on if you want it.

So:

Computer 1 - Enabling secure boot is a good plan as it reduces potential malware attacks.

Computer 2 - You met the above criteria of Point 1 on a clean install.

Computer 3 - As this was not a clean install, then device Encryption is not automatic (essentialy same as Point 2).

A lot of people worry about whether updates, hardware changes etc. invoke Device Encryption.
This does not happen (see Point 1). Once it is turned off, it remains off.
 

My Computer My Computer

At a glance

Windows 11 Pro + Win11 Canary VM.I9 13th gen i9-13900H 2.60 GHZ16 GB solderedIntegrated Intel Iris XE
OS
Windows 11 Pro + Win11 Canary VM.
Computer type
Laptop
Manufacturer/Model
ASUS Zenbook 14
CPU
I9 13th gen i9-13900H 2.60 GHZ
Motherboard
Yep, Laptop has one.
Memory
16 GB soldered
Graphics Card(s)
Integrated Intel Iris XE
Sound Card
Realtek built in
Monitor(s) Displays
laptop OLED screen
Screen Resolution
2880x1800 touchscreen
Hard Drives
1 TB NVME SSD (only weakness is only one slot)
PSU
Internal + 65W thunderbolt USB4 charger
Case
Yep, got one
Cooling
Stella Artois (UK pint cans - 568 ml) - extra cost.
Keyboard
Built in UK keybd
Mouse
Bluetooth , wireless dongled, wired
Internet Speed
900 mbs (ethernet), wifi 6 typical 350-450 mb/s both up and down
Browser
Edge
Antivirus
Defender
Other Info
TPM 2.0, 2xUSB4 thunderbolt, 1xUsb3 (usb a), 1xUsb-c, hdmi out, 3.5 mm audio out/in combo, ASUS backlit trackpad (inc. switchable number pad)

Macrium Reflect Home V8
Office 365 Family (6 users each 1TB onedrive space)
Hyper-V (a vm runs almost as fast as my older laptop)

Latest Support Threads

Back
Top Bottom