An external backup protects against failure of the PC's internal drive, but a lost portable disk can expose private files. BitLocker To Go encrypts removable data drives on supported Windows editions and can unlock them with a password or smart card. Encryption adds a new dependency: if you lose both unlock credential and recovery key, the backup becomes unusable. Set it up, store recovery separately, then perform a real unlock and restore test.
Before you start
Check that your Windows edition and organization policy permit BitLocker To Go. Back up the drive's existing contents before enabling encryption and confirm it is the correct drive. Choose a strong unique unlock passphrase and a safe key-storage location outside that disk. Keep a second copy of irreplaceable data; encryption does not prevent physical drive failure.Do it step by step
- Connect the external drive and open Control Panel > BitLocker Drive Encryption. Identify the removable drive by capacity and label before choosing Turn on BitLocker.
- Choose the supported unlock method and save the recovery key to a separate secure location. Do not store its only copy on the encrypted backup drive.
- Complete encryption while the drive remains connected and power is stable. Label the disk without writing the password or key on the label.
- Copy a few representative backup files and safely eject the drive. Reconnect it and unlock it using the intended passphrase or smart card.
- On a second trusted Windows PC, confirm the drive unlocks and the sample files open. Test recovery-key access privately without exposing the secret in support screenshots.
- Run or update the actual backup job, record its date and store the drive securely and disconnected when not needed.