How to Turn On or Off BitLocker PIN and USB to Unlock OS at Startup in Windows 11

This article describes steps one can take to enable or disable additional BitLocker authentication by allowing one to unlock the PC OS drive using a PIN and USB when the computer starts in Windows 11.

BitLocker helps protect your data on your computer so only authorized users have access to it. New files created on a BitLocker-enabled drive will automatically be protected as well.

BitLocker will automatically check the PC at startup to make sure that the computer has not been tampered with, including BIOS changes and other security risks.

By default, a PC with a TPM chip which is recognized by BitLocker will automatically unlock the PC during startup. Users can add additional security measures to be used at startup to provide added protection for encrypted data.

You can require users to insert a USB drive that contains a startup key as well as a PIN at startup before the computer can fully boot up.

Below is how to do that.

How to require a BitLocker USB and PIN at startup on a PC with Windows 11

As described above, you can require users to insert a USB drive that contains a startup key as well as a PIN at startup before the computer can fully boot up.

Here’s how to do that.

You must first enable BitLocker on the OS drive. If you haven’t added BitLocker, read the post below to do so.

How to turn on or off Bitlocker in Windows 11

Enable PIN to unlock BitLocker at startup in Windows 11

With BitLocker enabled on your OS drive, open the Control Panel and browse to the BitLocker page.

Control Panel\System and Security\BitLocker Drive Encryption

Then click on the link that reads “Change how drive is unlocked at startup“.

windows 11 change how dirve is unlocked at startup
Windows 11 changes how the drive is unlocked at the startup

Next, select the “Enter a PIN (recommended)” link to continue.

windows 11 choose how to unlock your drive at startup enter pin
Windows 11 chooses how to unlock your drive at startup enter the pin

Enter and confirm the PIN and click Set PIN. A PIN of 6-20 numbers long is required.

windows 11 enter a pin to unlock bitlocker at startup
Windows 11 enters a pin to unlock Bitlocker at startup

Close the Control Panel app to exit.

Unlock BitLocker with a USB drive at startup on Windows 11

Now that you have set up a PIN to unlock BitLocker at startup, you can choose to also require a USB drive to unlock BitLocker.

To do that, go back to the Control Panel app, and browse to the System and Security -> BitLocker Drive Encryption.

Then click on the link that reads “Change how drive is unlocked at startup“.

windows 11 change how dirve is unlocked at startup
Windows 11 changes how the drive is unlocked at the startup

Next, click the link that reads “Insert a USB flash drive” to continue.

choose how to unlock your drive at startup insert usb drive windows 11
choose how to unlock your drive at startup insert USB drive windows 11

Then insert a USB flash drive and click Save.

windows 11 save your startup key on usb bitlocker
Windows 11 saves your startup key on USB BitLocker

If you wish to disable BitLocker requiring a USB flash drive or a PIN at startup, read the post below.

How to set up BitLocker to automatically unlock PC at startup via TPM in Windows 11

That’s it.

Conclusion:

This post showed you how to add additional BitLocker security by requiring a PIN and USB flash drive with a BitLocker key at startup on Windows 11.

If you find any error above or have something to add, please use the comment form below.