Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

manage-bde is Microsoft’s built-in command-line tool for checking and managing BitLocker. Use manage-bde -status to inspect a volume, -on to start encryption, protector commands to manage recovery and unlock credentials, -unlock to access a locked drive, and -off to decrypt it. Run Command Prompt as an administrator, check the target drive letter carefully, and choose the command for the task: syntax and effects differ by subcommand.

What manage-bde supports

Microsoft describes manage-bde as a command-line alternative to the BitLocker Drive Encryption Control Panel. Microsoft Learn lists Windows 10 and Windows 11, Windows Server 2016 through 2025, and Azure Local 2311.2 and later among applicable systems. See Microsoft’s manage-bde overview for scope and command details.

BitLocker protectors are the mechanisms that protect the encryption key. Depending on the volume and configuration, they can include TPM-based protection, a startup key, a PIN, a recovery password, an external recovery key, or supported password and certificate options. An operating-system volume and a data volume do not necessarily use the same setup or unlock flow.

Check BitLocker status

To see every volume, run:

manage-bde -status

To check one volume, specify its drive letter:

manage-bde -status C:

The status output is more informative than a simple on/off label. It reports volume size and BitLocker version, conversion status, percentage encrypted, encryption method, protection status, lock status, identification field, and key protectors. Use it to distinguish a volume still encrypting from one fully encrypted, and an encrypted volume with protection suspended from one with protection enabled. Microsoft documents the fields and a batch-check option in its status command reference.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
#1 Best Overall
Yubico - Security Key C NFC - Basic Compatibility - Multi-Factor authentication (MFA) Security Key and passkey, Connect via USB-C or NFC, FIDO Certified
  • POWERFUL SECURITY KEY: The Security Key C NFC is the essential physical passkey for protecting your digital life from phishing attacks. It ensures only you can access your accounts.
  • WORKS WITH 1000+ ACCOUNTS: Compatible with Google, Microsoft, and Apple. A single Security Key C NFC secures 100 of your favorite accounts, including email, password managers, and more.
  • FAST & CONVENIENT LOGIN: Plug in your Security Key C NFC via USB-C and tap it, or tap it against your phone (NFC) to authenticate. No batteries, no internet connection, and no extra fees required.
  • TRUSTED PASSKEY TECHNOLOGY: Uses the latest passkey standards (FIDO2/WebAuthn & FIDO U2F) but does not support One-Time Passwords. For complex needs, check out the YubiKey 5 Series.
  • BUILT TO LAST: Made from tough, waterproof, and crush-resistant materials. Manufactured in Sweden and programmed in the USA with the highest security standards.

For batch checks, -protectionaserrorlevel sets the command’s error level to 0 when the volume is protected and 1 when it is unprotected. This is useful in scripts that need to branch on protection state rather than parse the full status output.

Turn on BitLocker

The basic command is manage-bde -on <drive>. For example, Microsoft documents starting encryption on the operating-system volume with a recovery-password protector:

manage-bde -on C: -recoverypassword

For a startup-key workflow, its example is:

manage-bde -on C: -startupkey E:

That configuration uses an external startup key stored on the specified removable drive; the key must be available at startup. Microsoft’s documentation describes this external startup-key method for computers without a TPM. A USB drive is therefore relevant to this specific configuration, not a universal BitLocker requirement.

Rank #2
Yubico - YubiKey 5 NFC - Multi-Factor authentication (MFA) Security Key and passkey, Connect via USB-A or NFC, FIDO Certified - Protect Your Online Accounts
  • POWERFUL SECURITY KEY: The YubiKey 5 NFC is the most versatile physical passkey, protecting your digital life from phishing attacks. It ensures only you can access your accounts
  • WORKS WITH 1000+ ACCOUNTS: Compatible with popular accounts like Google, Microsoft, and Apple. A single YubiKey 5 NFC secures 100+ of your favorite accounts, including email, password managers, and more
  • FAST & CONVENIENT LOGIN: Plug in your YubiKey 5 NFC via USB and tap it, or tap it against your phone (NFC), to authenticate. No batteries, no internet connection, and no extra fees required
  • MOST SECURE PASSKEY: Supports FIDO2/WebAuthn, FIDO U2F, Yubico OTP, OATH-TOTP/HOTP, Smart card (PIV), and OpenPGP. That means it’s versatile, working almost anywhere you need it
  • PRIMARY & SPARE KEYS: Just like having a spare house key, we recommend buying two YubiKeys - one for daily use and one as a spare. That way you’ll never get locked out of your accounts

Other documented options include -recoverykey, -tpmandpin, and password protection for a data drive. Encryption choices include -usedspaceonly and AES method options. The command and applicable choices depend on whether the target is an operating-system or data volume. Consult Microsoft’s -on syntax reference before selecting options. Some configurations require a reboot to finish setup; Microsoft’s BitLocker operations guide describes that possibility, including inserting a startup key before the operating system can start. Not every setup requires a reboot or removable drive.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

List, add, back up, suspend, or enable protectors

List protector types and IDs

Use this command to inspect protectors on a volume:

manage-bde -protectors -get C:

It lists the protector types and their IDs. Record the relevant ID when a later operation, such as backing up a recovery protector, requires it. The protector command reference covers the available operations.

Rank #3
USB A Port Blockers 10 Pack, Security Locks with Removal Key, Black
  • USB A PORT BLOCKERS WITH KEY: Designed for standard USB A ports on laptops, desktop PCs, notebooks, and docking stations. Includes 10 USB blockers and a removal key for simple physical port control on compatible devices.
  • PREVENT DATA THEFT AND UNWANTED ACCESS: Use these USB port locks to restrict unauthorized data transfer on unattended devices. They provide total peace of mind for offices, schools, front desks, computer labs, and libraries.
  • FOR WORK, TRAVEL, AND SHARED DEVICES: Useful when devices are left unattended or used by multiple people. Ideal for business travel, classrooms, hotel workstations, field setups, and family computers in shared spaces.
  • DUST AND MOISTURE PROTECTION: In addition to controlling port access, these USB A blockers keep out dust, debris, and moisture that collect in open ports over time. A smart choice for everyday protection and cleaner ports.
  • DESIGNED FOR IT ADMINS AND HOME USERS: Made from durable, heat resistant PE material. A simple solution for IT teams, schools, parents, and security minded users who want better control over open USB A ports.

Add and back up a recovery protector

To add a recovery-password protector, Microsoft’s operations guidance gives this example:

manage-bde -protectors -add C: -RecoveryPassword

A recovery password or external recovery key must be available when recovery is needed. In a managed environment, administrators can back up recovery information to Microsoft Entra ID or Active Directory. To back up a specific protector, use its ID, including the braces:

Free tools Windows power users keep installed

One-click scans. No signup required.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
  • manage-bde -protectors -aadbackup C: -id {ID} backs up to Microsoft Entra ID.
  • manage-bde -protectors -adbackup C: -id {ID} backs up to Active Directory.

Replace {ID} with the protector ID shown by the get command. These backup operations are described in Microsoft’s BitLocker operations guide.

Rank #4
Yubico - Security Key NFC - Basic Compatibility - Multi-Factor Authentication (MFA) Key, Connect via USB-A or NFC, FIDO Certified
  • POWERFUL SECURITY KEY: The Security Key NFC is the essential physical passkey for protecting your digital life from phishing attacks. It ensures only you can access your accounts.
  • WORKS WITH 1000+ ACCOUNTS: Compatible with Google, Microsoft, and Apple. A single Security Key NFC secures 100 of your favorite accounts, including email, password managers, and more.
  • FAST & CONVENIENT LOGIN: Plug in your Security Key NFC via USB-A and tap it, or tap it against your phone (NFC) to authenticate. No batteries, no internet connection, and no extra fees required.
  • TRUSTED PASSKEY TECHNOLOGY: Uses the latest passkey standards (FIDO2/WebAuthn & FIDO U2F) but does not support One-Time Passwords. For complex needs, check out the YubiKey 5 Series.
  • BUILT TO LAST: Made from tough, waterproof, and crush-resistant materials. Manufactured in Sweden and programmed in the USA with the highest security standards.

Suspend or re-enable protection

Suspending protection is not the same as decrypting a volume. The volume remains encrypted, but the key is made available unsecured while protection is suspended. For a planned maintenance window, the following example suspends protection for three reboots:

manage-bde -protectors -disable C: -rc 3

Without a reboot count, Microsoft documents protection resuming on restart. To re-enable protection explicitly, run:

manage-bde -protectors -enable C:

Delete protectors carefully

Deleting a protector changes how the volume is protected. Microsoft warns that deleting the last protector disables BitLocker protection, to avoid accidentally losing access to data. Before deleting one, confirm another appropriate protector remains and that needed recovery material is available. The protector reference documents the delete operation and its implications.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Best Value
FIDO2 U2F Security Key Passkey Two-Factor Authentication (2FA) USB Key PIN+Touch (Non-Biometric) USB-A Type TrustKey T110
  • Security Key : Protect your online accounts against unauthorized access by using FIDO2 and U2F authentication with T110. It's the world's most protective security key that works with windows, Mac OS, Linux as well as Chrome, Firefox, Edge and many other major browsers.
  • Certified with the new FIDO2 standard, T110 provides the benefit of fast login and strong protection against phishing, account takeover as well as many other online attactks.
  • Works with : Bank of America, Github, Google, Microsoft, DUO, Twitter, Facebook, Dropbox, Apple, ebay, BINANCE, mor and more.
  • Fits USB-A port : Insert the T110 security key into the USB-A port of each service and log in conveniently with one touch
  • For the driver download and user guide, please visit TrustKey Solutions Home support page.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

Unlock a BitLocker-encrypted drive

To unlock a secondary data drive with its recovery password, use the 48-digit password for that volume:

manage-bde -unlock D: -recoverypassword <48-digit-recovery-password>

If you have an external recovery key file, specify its path instead:

manage-bde -unlock D: -recoverykey <path-to-.bek-file>

The command also supports certificate-based unlocking and password prompting for data-drive scenarios. Choose a credential that is already configured or available for that volume. -unlock does not discover or recreate a lost recovery key. See Microsoft’s -unlock reference and operations guide.

Turn off BitLocker and decrypt a volume

To start decrypting a volume, run:

manage-bde -off C:

This starts decryption without the confirmation step used by the Control Panel workflow. Verify the drive letter before running it: once decryption completes, Microsoft says the volume’s key protectors are removed. Use -off when you intend to decrypt, not merely to suspend protection temporarily. Microsoft documents the command in its -off reference and operations guide.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Choose the right BitLocker workflow

Decision Options and practical distinction
Volume role Operating-system and data volumes can have different setup and protector options; check the applicable syntax before enabling or unlocking.
Unlock mechanism Depending on configuration, protection can use TPM, TPM plus PIN, a startup key, a recovery password, an external recovery key, or supported certificate/password options.
Recovery administration Keep recovery material available, or back up recovery information to Active Directory or Microsoft Entra ID in a managed environment.
Encryption scope and method Documented choices include used-space-only or full-volume encryption and AES method variants; select them through the applicable -on options.
Temporary change or decryption Disabling protectors suspends protection while the volume remains encrypted; -off starts decryption and removes protectors when it finishes.

Useful Microsoft command references

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.