The quickest way: right-click and use BitLocker or EFS

Windows 11 gives you two built-in encryption tools you can reach directly from File Explorer without installing anything. The fastest route depends on which version of Windows 11 you have and whether you want to encrypt just one folder or your entire drive.

BitLocker encrypts your whole drive or a removable device (USB drive, external hard drive). EFS (Encrypting File System) encrypts individual folders and files while leaving the rest of your drive unencrypted. For a single folder, EFS is usually what you want.

BitLocker is available in Windows 11 Pro, Enterprise, and Education editions. If you have Windows 11 Home, you can still use EFS, or you can encrypt a USB drive with BitLocker To Go. Check which version you own by typing "winver" into the search box and pressing Enter.

Key Takeaways

  • EFS encrypts individual folders and files directly from File Explorer by right-clicking, choosing Properties, then Advanced, then checking "Encrypt contents to find data."
  • BitLocker encrypts your entire drive or external devices and is available only in Windows 11 Pro and higher editions.
  • After you encrypt a folder with EFS, Windows automatically encrypts any new files you save there, but you must manually encrypt files that were already inside before encryption was turned on.
  • If you forget your password or lose access to your encryption key, Windows cannot recover your encrypted files — write down your recovery key or save it somewhere safe before you encrypt.
  • Encrypted folders still show in File Explorer normally, but their contents are unreadable to anyone without the correct password or key.

Encrypting a single folder with EFS in File Explorer

Open File Explorer and navigate to the folder you want to encrypt. Right-click on it and select Properties. In the General tab, click the Advanced button near the bottom of the window.

In the Advanced Attributes window, check the box next to "Encrypt contents to find data". Click OK, then click explore in the Properties window. Windows will ask whether you want to encrypt only the folder or the folder and all its contents — choose whichever matches what you need. Click OK again.

Windows will now encrypt the folder. The time this takes depends on how many files are inside and how large they are. Once it finishes, the folder name may appear slightly different (sometimes with a small lock icon or in a different color, depending on your settings), but it will still open and work normally when you are logged in.

What happens after you encrypt a folder

Any new files you save into an encrypted folder are automatically encrypted. If you move an unencrypted file into the folder, Windows encrypts it. If you copy an unencrypted file into the folder, the copy becomes encrypted but the original stays unencrypted.

Files that were already in the folder before you turned on encryption are encrypted when ready, but only if they were stored on an NTFS drive (the standard Windows file system). If your drive uses FAT32 or exFAT, EFS does not work — you would need to use BitLocker instead.

The encrypted folder remains encrypted even after you restart your computer. Only your user account can open it. If another person logs into the same computer with a different account, they cannot read the files inside, even if they have administrator rights.

Using BitLocker for full-drive encryption on Windows 11 Pro

If you have Windows 11 Pro or higher, BitLocker encrypts your entire drive at once. Open File Explorer, right-click on the drive you want to encrypt (usually C:), and select Turn on BitLocker. If you do not see this option, BitLocker is not available in your Windows edition.

Windows will walk you through a setup process. You will choose how to unlock the drive — with a password, a PIN, or a USB key. You will also be asked to save or print a recovery key. Save this recovery key in a safe place outside your computer (such as a USB drive, printed paper, or a password manager). If you forget your password or lose access to your unlock method, the recovery key is the only way to get back into your drive.

BitLocker then encrypts your entire drive in the background while you use your computer normally. Encryption can take hours on a large drive, but you do not have to wait for it to finish before using your files. You can check the encryption progress by right-clicking the drive and selecting Manage BitLocker.

Encrypting a USB drive or external hard drive with BitLocker To Go

If you have Windows 11 Home and want to encrypt a removable device like a USB drive, use BitLocker To Go. Plug in the device, open File Explorer, right-click on it, and select Turn on BitLocker. The process is the same as full-drive encryption: choose your unlock method, save your recovery key, and let Windows encrypt the device.

Once encrypted, anyone who plugs the device into a Windows computer will be asked for the password before they can see any files. The device will also work on Mac and Linux computers, but those systems cannot read BitLocker encryption — the files will be inaccessible unless you decrypt the device first on a Windows computer.

BitLocker To Go is available in all Windows 11 editions, including Home. It is a good choice if you carry sensitive files on a USB drive and want to protect them if the drive is lost or stolen.

The difference between EFS and BitLocker

FeatureEFSBitLocker
What it encryptsIndividual folders and filesEntire drive or device
Available in Windows 11 HomeYesNo (except To Go for USB drives)
Works on NTFS drivesYesYes
Works on FAT32 or exFAT drivesNoYes
Encrypts automatically when you add filesYesYes
Protects against theft of the physical deviceOnly if the device is powered offYes, even if powered on

What to do if you forget your encryption password

If you encrypted a folder with EFS and forget your password, Windows cannot decrypt the files. There is no "forgot password" recovery option. The only way to access the files is with the recovery key you should have saved when you first set up encryption.

For BitLocker, the same rule applies: if you forget your password or PIN, you need the recovery key. This is why saving the recovery key before you encrypt is critical. Write it down on paper and store it somewhere safe, or save it in a password manager like Bitwarden or 1Password that you can access from another device.

If you have neither the password nor the recovery key, the encrypted files are permanently inaccessible. Windows will not unlock them, and no third-party tool can break the encryption. Plan ahead: save your recovery key now, before you encrypt anything.

Frequently Asked Questions

Can I encrypt a folder if I use a Microsoft account instead of a local account?

Yes. EFS works with both local accounts and Microsoft accounts. Your encryption key is tied to your user account, so only you can decrypt the files when you are logged in as that account.

What if I encrypt a folder and then move it to an external drive?

If you move an EFS-encrypted folder to an external drive that uses NTFS, the encryption stays in place. If the external drive uses FAT32 or exFAT, Windows will ask whether you want to decrypt the folder before moving it, because those file systems do not support EFS. For external drives, BitLocker To Go is a better choice.

Does encryption slow down my computer?

EFS has minimal impact on speed for most users. BitLocker can cause a small slowdown on older computers, but modern Windows 11 machines with hardware encryption support (which most have) experience almost no performance loss. The security benefit outweighs any minor speed difference.

Can someone with administrator rights decrypt my encrypted folder?

No. Even a computer administrator cannot read files encrypted with EFS unless they have your password or encryption key. BitLocker also protects against administrator access. Encryption is tied to your user account, not to administrator status.

What happens if my computer crashes while encrypting a folder?

Windows will resume encryption the next time you log in. You do not have to start over. The folder remains partially encrypted until the process completes, and you cannot access the unencrypted files until encryption finishes.