<div class="wpcnt">
			<div class="wpa">
				<span class="wpa-about">Advertisements</span>
				<div class="u top_amp">
							<amp-ad width="300" height="265"
		 type="pubmine"
		 data-siteid="173035871"
		 data-section="1">
		</amp-ad>
				</div>
			</div>
		</div><p dir="ltr">The right free method depends on your Windows edition. If you have Windows 11 Pro, Enterprise, or Education, you can turn on BitLocker for a whole drive or use the Encrypting File System for individual folders. If you have Windows 11 Home, BitLocker is not available, but your PC may already use Device Encryption, and you can protect individual files for free with 7-Zip or VeraCrypt. Whichever method you pick, keep a safe copy of your recovery key or password, because losing it can mean losing the data.</p>
<p dir="ltr">This guide covers each method with steps, explains the difference between encrypting a drive and encrypting a folder, and flags two 2026 issues worth knowing before you choose: where Microsoft stores recovery keys, and a signing dispute that affected VeraCrypt.</p>
<h2 dir="ltr">Drive Encryption vs. File Encryption</h2>
<p dir="ltr">Drive encryption protects everything on a disk. If someone steals your laptop and removes the drive, they cannot read it without the key. It does not protect files from someone who is signed in to your computer, because once Windows unlocks the drive, the files are readable.</p>
<p dir="ltr">File or folder encryption protects specific items. Some methods tie the protection to your Windows account, and others use a password you choose, so the files stay locked even when the drive is unlocked.</p>
<p dir="ltr">The two work well together. Drive encryption guards against loss and theft, and file encryption guards individual files you share or store in the cloud.</p>
<h2 dir="ltr">Which Method Fits Your Windows Edition</h2>
<p dir="ltr">According to Microsoft Learn, BitLocker is supported on Windows Pro, Enterprise, and Education editions, but not Home. Home and consumer devices that meet the hardware requirements get automatic Device Encryption instead. The Encrypting File System is also limited to Pro, Enterprise, and Education.</p>
<p dir="ltr">In practice:</p>
<ul dir="ltr">
<li>Windows 11 Home: Device Encryption, 7-Zip, or VeraCrypt containers.</li>
<li>Windows 11 Pro, Enterprise, or Education: BitLocker, EFS, 7-Zip, or VeraCrypt.</li>
</ul>
<p dir="ltr">To check your edition, open Settings, then System, then About.</p>
<h2 dir="ltr">Method 1: Device Encryption on Windows 11 Home</h2>
<p dir="ltr">Pureinfotech describes the path as Settings, then Privacy and security, then Device encryption. The page lets you turn it on or off if your hardware supports it. The requirements include a Microsoft account, TPM 2.0 with Modern Standby support, and UEFI firmware.</p>
<p dir="ltr">Microsoft Learn explains that on consumer devices, the recovery key is backed up to your Microsoft account automatically. Pureinfotech notes this backup cannot be prevented on Home, though you can download the key. If you sign in with only a local account, Microsoft Learn says the keys remain unprotected, so use a Microsoft account if you want the automatic protection and backup.</p>
<p dir="ltr">Check the key after you turn the feature on. Sign in to your Microsoft account and confirm that the recovery key is listed. Print or save a copy somewhere safe.</p>
<h2 dir="ltr">Method 2: BitLocker on Windows 11 Pro, Enterprise, or Education</h2>
<p dir="ltr">Windows Central gives the following path.</p>
<h3 dir="ltr"><strong>Step 1: Open Disk Settings</strong></h3>
<p dir="ltr">Go to Settings, then System, then Storage, then Advanced storage settings, then Disks and volumes. Select the drive and open Properties.</p>
<h3 dir="ltr"><strong>Step 2: Turn On BitLocker</strong></h3>
<p dir="ltr">Choose Turn on BitLocker. Windows walks you through the rest.</p>
<h3 dir="ltr"><strong>Step 3: Choose Where to Save the Recovery Key</strong></h3>
<p dir="ltr">You can back it up to your Microsoft account or save it to a file or USB drive, or print it. Pick a location you can reach when your computer will not start.</p>
<h3 dir="ltr"><strong>Step 4: Choose How Much to Encrypt</strong></h3>
<p dir="ltr">You can pick Encrypt used disk space only, which is faster and suited to new drives, or encrypt the entire drive. Windows also asks you to select an encryption mode.</p>
<h3 dir="ltr"><strong>Step 5: Start Encryption</strong></h3>
<p dir="ltr">Confirm and let Windows finish. You can keep using the computer, though it may run slower during the process.</p>
<h3 dir="ltr"><strong>BitLocker To Go for Removable Drives</strong></h3>
<p dir="ltr">Windows Central notes that BitLocker To Go protects USB drives and external disks. Right-click the drive and choose to turn on BitLocker, then set a password.</p>
<p dir="ltr">Microsoft Learn adds that a PIN or startup key is stronger than TPM alone, and that a password is discouraged. The 24H2 update relaxed some prerequisites, so more devices can use BitLocker than before.</p>
<h2 dir="ltr">Where Your Recovery Key Is Stored</h2>
<p dir="ltr">TechRepublic reported in January 2026 that Microsoft provided the FBI with BitLocker recovery keys for three laptops in a Guam COVID unemployment fraud case. Microsoft told the outlet it receives about 20 such requests a year, and that many cannot be fulfilled because the customer did not upload the key to Microsoft&#8217;s servers.</p>
<p dir="ltr">That detail leads to a real choice. Storing the key in your Microsoft account protects you from lockouts, but it means Microsoft holds a copy and can be legally compelled to provide it. Keeping the key only in a local file or on a USB drive avoids that cloud copy, according to the report, but then you alone are responsible for not losing it. Neither choice is wrong. Pick based on your risk. A typical user worried about lockouts may prefer the account backup, and a user worried about legal demands may keep the key offline.</p>
<h2 dir="ltr">Method 3: Encrypting File System for a Folder</h2>
<p dir="ltr">iTechGuides describes the steps. Right-click the file or folder, choose Properties, select the General tab, and click Advanced. Check Encrypt contents to secure data, then click OK and Apply. For a folder, choose whether to apply the change to the folder only or to subfolders and files.</p>
<p dir="ltr">EFS has limits. It requires Pro, Enterprise, or Education, and it works only on NTFS drives. Encryption is tied to your Windows user account, so the files open automatically when you are signed in and stay locked to other accounts. You cannot encrypt compressed files or system files.</p>
<p dir="ltr">Back up your certificate and key. iTechGuides recommends the command <code dir="ltr">cipher /x</code>, which exports them to a file. Without the key, you may lose access to the files after a Windows reinstall or an account problem.</p>
<h2 dir="ltr">Method 4: 7-Zip for Password-Protected Archives</h2>
<p dir="ltr">7-Zip is free and works on every Windows edition. Guidance from the Midwestern State University Texas help desk and the University of Edinburgh recommends these settings.</p>
<h3 dir="ltr"><strong>Create the Encrypted Archive</strong></h3>
<p dir="ltr">Right-click the files, choose 7-Zip, then Add to archive. Set the archive format to 7z. Under Encryption, enter a strong password and choose AES-256 as the method. Turn on Encrypt file names so that the list of files is also hidden.</p>
<h3 dir="ltr"><strong>Share the Password Separately</strong></h3>
<p dir="ltr">If you send the archive to someone, give them the password through a different channel, such as a phone call.</p>
<h3 dir="ltr"><strong>Avoid the Old ZIP Method</strong></h3>
<p dir="ltr">Both sources note that AES-256 is far stronger than the older ZipCrypto method used by default in standard ZIP files. Use the 7z format with AES-256.</p>
<p dir="ltr">The archive must be extracted to read the files, which leaves decrypted copies. Delete the copies when finished.</p>
<h2 dir="ltr">Method 5: VeraCrypt Containers</h2>
<p dir="ltr">VeraCrypt is free and creates an encrypted container file that you mount like a drive. It works on Windows Home. PCWorld&#8217;s 2021 coverage notes that a mounted volume stays open until you dismount it, so close it when you are done, and that a lost password means lost data, since there is no recovery.</p>
<h3 dir="ltr"><strong>The 2026 Signing Dispute</strong></h3>
<p dir="ltr">TechCrunch reported on April 8, 2026 that Microsoft terminated the signing account of VeraCrypt&#8217;s developer, Mounir Idrassi, which the developer announced on March 30. He warned that this could cause boot problems for system-drive encryption after a certificate revocation in July 2026. Microsoft vice president Scott Hanselman contacted him on April 9, and Cyberwarzone reported the accounts were reinstated around April 14, attributing the problem to a new account verification requirement for the Windows Hardware Program.</p>
<p dir="ltr">A project update on SourceForge, last updated June 12, 2026, lists version 1.26.24. It says existing drivers still work for non-system volumes, and that system encryption is uncertain because a 2011 Microsoft EFI certificate expires. The sources reviewed do not confirm that the certificate issue is resolved. For that reason, this guide recommends VeraCrypt for file containers only. If you want to encrypt your system drive, use BitLocker or Device Encryption and check VeraCrypt&#8217;s current notes before trying system encryption.</p>
<h2 dir="ltr">Choosing the Right Method</h2>
<h3 dir="ltr"><strong>Lost or Stolen Laptop</strong></h3>
<p dir="ltr">Use Device Encryption on Home or BitLocker on Pro. Both protect the drive at rest.</p>
<h3 dir="ltr"><strong>Sensitive Folder on Your Own PC</strong></h3>
<p dir="ltr">Use EFS on Pro. On Home, use a VeraCrypt container.</p>
<h3 dir="ltr"><strong>Files You Send or Store in the Cloud</strong></h3>
<p dir="ltr">Use a 7-Zip archive with AES-256 and a strong password shared separately.</p>
<h3 dir="ltr"><strong>USB Drive</strong></h3>
<p dir="ltr">Use BitLocker To Go on Pro, or a 7-Zip archive or VeraCrypt container on Home.</p>
<h2 dir="ltr">Good Habits</h2>
<p dir="ltr">Use a long, unique password. Store recovery keys somewhere separate from the computer. Test that you can open an encrypted archive or restore a backed-up key before you rely on it. Keep Windows updated. Back up your data, since encryption protects against theft and not against a failed drive.</p>
<h2 dir="ltr">Test Before You Trust</h2>
<p dir="ltr">Encryption protects data and also creates a way to lock yourself out. Before you rely on any method, run a short test. Encrypt a small folder of dummy files, then practice recovery. For BitLocker, confirm you can find the recovery key in your Microsoft account or the file you saved. For EFS, export the certificate with <code dir="ltr">cipher /x</code> and confirm the backup opens. For 7-Zip, extract the archive on a second computer using only the password. For VeraCrypt, dismount and remount the container.</p>
<p dir="ltr">Write down where each key or password lives. A recovery key kept on the same computer it protects does not help when the computer will not start.</p>
<h2 dir="ltr">Encryption Is Not a Backup</h2>
<p dir="ltr">Encrypted data can still be lost to a failed drive, ransomware, or an accidental delete. Keep a separate backup, and encrypt the backup too, using BitLocker To Go on Pro, or a 7-Zip archive or VeraCrypt container on Home. Store the backup somewhere other than the computer it copies, and test that you can restore from it. Encryption and backups protect against different problems, and a sound routine uses both.</p>
<h2 dir="ltr">Frequently Asked Questions</h2>
<h3 dir="ltr">Does Windows 11 Home have BitLocker?</h3>
<p dir="ltr">No. Microsoft Learn says BitLocker is supported on Pro, Enterprise, and Education. Home devices that meet hardware requirements get Device Encryption instead.</p>
<h3 dir="ltr">How do I encrypt a single folder in Windows 11?</h3>
<p dir="ltr">On Pro, Enterprise, or Education, right-click the folder, choose Properties, then Advanced, and check Encrypt contents to secure data. On Home, use a 7-Zip archive or a VeraCrypt container.</p>
<h3 dir="ltr">Can Microsoft access my BitLocker key?</h3>
<p dir="ltr">If your key is backed up to your Microsoft account, Microsoft stores a copy. TechRepublic reported that Microsoft gave the FBI recovery keys in a January 2026 case, and that it receives about 20 such requests a year.</p>
<h3 dir="ltr">Is 7-Zip encryption safe?</h3>
<p dir="ltr">With the 7z format, AES-256, and a strong password, yes, according to university guidance. The older ZipCrypto method is much weaker.</p>
<h3 dir="ltr">What happens if I lose my recovery key or password?</h3>
<p dir="ltr">You may lose access to the data. VeraCrypt has no recovery option, and BitLocker and EFS require the key or certificate.</p>
<h2 dir="ltr"><strong>References and Sources</strong></h2>
<p dir="ltr">Microsoft Learn, &#8220;BitLocker overview&#8221;: <a href="https://learn.microsoft.com/en-us/windows/security/operating-system-security/data-protection/bitlocker/">https://learn.microsoft.com/en-us/windows/security/operating-system-security/data-protection/bitlocker/</a></p>
<p dir="ltr">Pureinfotech, &#8220;How to enable Device Encryption on Windows 11 Home&#8221;: <a href="https://pureinfotech.com/enable-device-encryption-windows-11-home/">https://pureinfotech.com/enable-device-encryption-windows-11-home/</a></p>
<p dir="ltr">Windows Central, &#8220;How to enable BitLocker on Windows 11&#8221;: <a href="https://www.windowscentral.com/how-enable-bitlocker-windows-11">https://www.windowscentral.com/how-enable-bitlocker-windows-11</a></p>
<p dir="ltr">TechRepublic, &#8220;Microsoft gave the FBI BitLocker recovery keys&#8221;: <a href="https://www.techrepublic.com/article/microsoft-fbi-bitlocker-recovery-keys/">https://www.techrepublic.com/article/microsoft-fbi-bitlocker-recovery-keys/</a></p>
<p dir="ltr">iTechGuides, &#8220;How to Encrypt a Folder in Windows 11&#8221;: <a href="https://itechguides.com/how-to-encrypt-a-folder-in-windows-11/">https://itechguides.com/how-to-encrypt-a-folder-in-windows-11/</a></p>
<p dir="ltr">Midwestern State University Texas, &#8220;Encrypting files with 7-Zip&#8221;: <a href="https://msutexas.edu/it/help/7zip-encryption.php">https://msutexas.edu/it/help/7zip-encryption.php</a></p>
<p dir="ltr">University of Edinburgh, &#8220;Encrypt files with 7-Zip&#8221;: <a href="https://www.ed.ac.uk/information-services/help-consultancy/is-skills/encryption/7zip">https://www.ed.ac.uk/information-services/help-consultancy/is-skills/encryption/7zip</a></p>
<p dir="ltr">PCWorld, &#8220;How to encrypt files with VeraCrypt&#8221;: <a href="https://www.pcworld.com/article/veracrypt-encryption-guide.html">https://www.pcworld.com/article/veracrypt-encryption-guide.html</a></p>
<p dir="ltr">TechCrunch, &#8220;Microsoft terminated VeraCrypt developer&#8217;s account&#8221;: <a href="https://techcrunch.com/2026/04/08/microsoft-terminated-veracrypt-developer-account/">https://techcrunch.com/2026/04/08/microsoft-terminated-veracrypt-developer-account/</a></p>
<p dir="ltr">Cyberwarzone, &#8220;Microsoft reinstates VeraCrypt signing account&#8221;: <a href="https://cyberwarzone.com/microsoft-reinstates-veracrypt-account/">https://cyberwarzone.com/microsoft-reinstates-veracrypt-account/</a></p>
<p dir="ltr">SourceForge, &#8220;VeraCrypt project updates&#8221;: <a href="https://sourceforge.net/projects/veracrypt/">https://sourceforge.net/projects/veracrypt/</a></p>

How to Encrypt Files and Folders on Windows 11 for Free in 2026

How to Encrypt Files and Folders on Windows 11 for Free in 2026
