Fresh Install Windows 11 on USB Stick with BitLocker Enabled: Step-by-Step Guide
In this article, we will guide you through the process of performing a clean installation of Windows 11 on a USB stick, while setting up BitLocker encryption without saving the recovery key to your Microsoft account or being prompted for it.
Prerequisites
- A USB stick with at least 16GB of storage
- A valid Windows 11 license
- A PC that meets the minimum system requirements for Windows 11
Creating a Windows 11 Installation Media
First, you need to create a bootable USB stick with the Windows 11 installation media. You can do this by downloading the Windows 11 Media Creation Tool from the Microsoft website and following the on-screen instructions.
Performing a Clean Installation of Windows 11
Once you have created the installation media, plug it into the PC where you want to install Windows 11. Restart the PC and boot from the USB stick. Follow the on-screen instructions to perform a clean installation of Windows 11.
Setting up BitLocker Encryption
After installing Windows 11, you can set up BitLocker encryption to secure your data. To do this, follow these steps:
- Open the Start menu and search for "BitLocker".
- Click on "BitLocker Drive Encryption".
- Select the drive you want to encrypt and click "Turn on BitLocker".
- Choose how you want to unlock the drive (e.g., with a password or a smart card).
- Choose where you want to save the recovery key. Select "Save to a file" and save the recovery key to a secure location that is not your Microsoft account.
- Click "Next" and follow the on-screen instructions to encrypt the drive.
Preventing BitLocker from Saving the Recovery Key to Your Microsoft Account
By default, BitLocker will save the recovery key to your Microsoft account. To prevent this, follow these steps:
- Open the Group Policy Editor by searching for "gpedit.msc" in the Start menu.
- Navigate to "Computer Configuration" > "Administrative Templates" > "Windows Components" > "BitLocker Drive Encryption".
- Double-click on "Store BitLocker recovery information in Active Directory Domain Services".
- Select "Disabled" and click "OK".
- Double-click on "Choose how BitLocker-protected drives can be recovered".
- Select "Do not allow recovery information to be saved to Microsoft accounts" and click "OK".
Preventing BitLocker from Prompting for the Recovery Key
By default, BitLocker will prompt you for the recovery key if it detects a change in the hardware or software configuration of your PC. To prevent this, follow these steps:
- Open the Local Group Policy Editor by searching for "gpedit.msc" in the Start menu.
- Navigate to "Computer Configuration" > "Administrative Templates" > "Windows Components" > "BitLocker Drive Encryption".
- Double-click on "Require additional authentication at startup".
- Select "Enabled" and choose "Do not allow BitLocker without a compatible TPM" or "Allow BitLocker without a compatible TPM".
- Click "OK".
- Create a bootable USB stick with the Windows 11 installation media.
- Perform a clean installation of Windows 11.
- Set up BitLocker encryption and save the recovery key to a secure location.
- Prevent BitLocker from saving the recovery key to your Microsoft account.
- Prevent BitLocker from prompting for the recovery key.