System tower · floor

How to password protect a folder, and what Windows has instead

The honest starting point for how to password protect a folder is that the protections Microsoft documents do not work at the level of a folder. They work at the level of a drive, and on a good number of machines one of them is already switched on.

“When you first sign in or set up a device with a Microsoft account, or work or school account, Device Encryption is turned on and a recovery key is attached to that account. If you’re using a local account, Device Encryption isn’t turned on automatically.”

Microsoft, read 22 August 2026. Two things follow from that sentence and both surprise people. A great many Windows machines are already encrypted and their owners have never thought about it. And the key that unlocks them is not written down anywhere in the house — it is attached to the Microsoft account used at setup.

If you signed in with a local account instead, none of it is on, and nothing told you.

So the first useful move is not to install anything. It is to find out what is already true about the machine in front of you, because the answer changes what you should do next — and because a recovery key attached to an account you can no longer sign into is a problem worth discovering today rather than on the morning the disk asks for it.

There are two tiers, and Microsoft is unusually clear about which editions get which.

Device Encryption“A Windows feature that enables BitLocker encryption automatically for the Operating System drive and fixed drives.” Available “on a wider range of devices, including those running Windows Home.” Settings › Privacy & security › Device encryption.
BitLocker Drive EncryptionThe manageable version, and Microsoft is explicit about the limit: it is “available on Windows Pro, Enterprise, or Education editions”. If you are on Home, this is not a setting you are failing to find.

That distinction resolves a lot of frustrated searching. If you are on Windows Home and following a guide that says to right-click the drive and choose “Turn on BitLocker”, the command is not missing because something is broken — the edition does not have it. What Home has is Device Encryption, which does the same underlying job with fewer controls, and which is switched on automatically only under the account condition quoted above.

Finding out where you actually stand

From Start, type System Information, right-click it, Run as administrator. In System Summary look for Device Encryption Support. Microsoft’s own values:

Meets prerequisites
It is available on this device.
TPM is not usable
“Your device doesn’t have a Trusted Platform Module, or the TPM isn’t enabled in the BIOS or in the UEFI.”
WinRE is not configured
The Windows Recovery Environment is not set up.
PCR7 binding is not supported
“Secure Boot is disabled in the BIOS/UEFI, or you have peripherals connected to your device during boot.”

The three failure values are worth reading as a shopping list rather than a verdict. A TPM that is present but disabled in the firmware is a setting; Secure Boot disabled is a setting; a missing recovery environment is fixable. None of the three means the machine cannot be encrypted — they mean something has to be changed first, and the message names which thing.

Now the part where the original question deserves a direct answer rather than a redirection. If what you want is that one folder be unreadable to somebody else using this computer, the documented tools sit either side of it: whole-drive encryption protects everything against somebody who has the machine but not your sign-in, and file-level passwords — the kind Office documents and PDFs support — protect one file against everyone. There is no documented middle setting that puts a password on a folder in Windows.

Which is worth knowing before adopting one of the methods that circulate for this. A folder that is hidden is not a folder that is encrypted: hiding changes what a file browser displays, and the contents remain exactly as readable to anybody who looks properly. That is not an argument about any particular trick — it is what the two words mean, and it is the question to put to any method before trusting it with something that matters.

One last thing that applies whichever route you take, and that this island has already documented elsewhere: compressing encrypted files removes the encryption. Microsoft’s own advice on zipped folders is to avoid it, “which might result in unintentional disclosure of personal or sensitive information”. Protection and transport interact, and not helpfully.

The floors below take it four ways: what is already on, turning it on properly, protecting a single file instead, and the recovery key that decides whether any of this is survivable.

Where to start

Four ways in.

“I do not know if anything is encrypted.”
Start at what is already on
“There is no BitLocker option.”
That is the edition — turning it on
“I only need one file protected.”
Go to one file instead
“Where is my recovery key?”
That is the recovery key

What is already on

Ten minutes of looking before ten minutes of installing. Most people do not know the state of their own disk, and Microsoft publishes the way to check.

Device Encryption SupportThe System Information value, and what each of the four answers means.Being built
Microsoft account or local accountThe condition that decides whether encryption came on by itself.Being built
On a MacThe equivalent question on the other system, and where its key goes.Being built

Turning it on

Two tiers, two editions, and three named reasons the option may be greyed out. None of them is the computer being broken.

Home against ProWhich encryption each edition gets, quoted from Microsoft rather than guessed.Being built
TPM and Secure BootThe firmware settings behind two of the four status values.Being built
Upgrading to Windows 11The other place these same requirements decide what your machine can do.Open this floor →

One file instead

When the goal is one document rather than a disk. These protections are older, narrower and travel with the file.

The recovery key

The single most consequential detail on this floor. Encryption without a retrievable key is a very effective way to lose everything.

What this tower will not do

It will not give you a folder password. Microsoft documents drive-level encryption and file-level passwords; there is no documented setting between them.

It will not treat hiding as protecting. A hidden folder is displayed differently and read identically.

And it will not skip the recovery key. Encryption you cannot unlock is not protection, it is deletion with extra steps. What holds instead is simple: the two encryption tiers, the edition limits, the account condition and the four support values are quoted from Microsoft’s own documentation.

Where this page got its facts

  1. Microsoft Support — Device Encryption in Windows (that Device Encryption enables BitLocker automatically, the Microsoft-account condition and the recovery key attached to it, the availability on Windows Home against BitLocker Drive Encryption on Pro, Enterprise and Education, the Settings route, and the four Device Encryption Support values) — support.microsoft.com, read 22 August 2026.
  2. Microsoft Support — Zip and unzip files (the warning that encrypted files are unencrypted when they are unzipped) — support.microsoft.com, read 22 August 2026.

Written by Alberto Gulotta

Founder and editor of AI Tools Primer, writing from Palermo, Italy. Thirty-five years of taking computers apart, starting with a Commodore 64 — the long version is on the about page.

Something wrong on this page? Write to aitoolsprimer@gmail.com and it gets fixed.

Written on 22 August 2026.

Independence and limits

No affiliate links and no paid placements anywhere on this site. Nobody pays to appear here, and no company has seen this page before you did.

This is general information, not professional advice. Where a page touches money, health, safety or the law, it names its source and the date it was read — and your situation may still differ. See the privacy page and the cookie policy.