Skip to Content

BitLocker Guide

BitLocker is Windows’ built-in disk encryption feature. If you plan to install Ubuntu alongside Windows in a dual boot setup, understanding and handling BitLocker is an important step before installation.

How BitLocker Affects Dual Boot Installation

Potential Issues

  1. Partition operations fail: The Ubuntu installer cannot shrink or modify BitLocker-encrypted partitions
  2. Windows won’t boot: After modifying UEFI settings (such as disabling Secure Boot), BitLocker may require a recovery key
  3. Cannot access the Windows partition: Ubuntu cannot read BitLocker-encrypted NTFS partitions by default

Why Changing BIOS Settings Triggers BitLocker

BitLocker uses the TPM (Trusted Platform Module) chip to store encryption keys. When it detects that the boot configuration has changed (e.g., Secure Boot disabled, boot order changed), it considers system security compromised and automatically enters recovery mode, requiring a 48-digit recovery key.

Checking BitLocker Status

Method 1: Windows Settings

  1. Open Settings -> Privacy & security -> Device encryption
  2. If you see “Device encryption is on,” BitLocker is enabled

Method 2: Command Line

Open PowerShell as administrator:

manage-bde -status

Check the “Protection Status” and “Encryption Status” for each volume.

Method 3: Control Panel

Control Panel -> System and Security -> BitLocker Drive Encryption

Back Up the BitLocker Recovery Key

Before performing any operations, always back up the recovery key first:

Finding the Recovery Key

  • Microsoft account: Visit https://account.microsoft.com/devices/recoverykey  and log in with your linked Microsoft account
  • Azure AD account: If it’s a company computer, contact your IT administrator
  • Printout or USB drive: If you chose to print or save to USB during initial setup

Manual Backup

Run PowerShell as administrator in Windows:

# View recovery keys for all volumes manage-bde -protectors -get C:

Record the 48-digit recovery key somewhere safe (don’t save it only on the current computer).

Solutions

After suspending BitLocker, the encrypted data is retained, but TPM verification is temporarily bypassed. This way, modifying UEFI settings won’t trigger recovery mode.

# Run PowerShell as administrator # Suspend BitLocker (automatically resumes after one reboot) manage-bde -protectors -disable C: # Or suspend for multiple reboots manage-bde -protectors -disable C: -RebootCount 3

After suspending, you can safely:

  • Modify UEFI settings
  • Adjust the boot order
  • Install Ubuntu

After installation, BitLocker will automatically re-enable protection.

Option 2: Fully Disable BitLocker

If you don’t need disk encryption, you can completely remove BitLocker:

# Turn off BitLocker (takes time to decrypt the entire disk) manage-bde -off C: # Check decryption progress manage-bde -status C:

Or via the GUI:

Control Panel -> System and Security -> BitLocker Drive Encryption -> Turn off BitLocker

Note: Full decryption may take from tens of minutes to several hours, depending on disk size and speed. Do not shut down during this process.

Option 3: Keep BitLocker, Just Back Up the Recovery Key

If you want to keep BitLocker encryption:

  1. Make sure you’ve backed up the recovery key
  2. When modifying UEFI settings, BitLocker will trigger recovery mode
  3. Enter the 48-digit recovery key to unlock Windows
  4. After Windows boots, BitLocker will automatically adapt to the new boot configuration

Accessing a BitLocker Partition from Linux After Installing Ubuntu

If the Windows partition still uses BitLocker encryption, you can use the dislocker tool in Ubuntu to access it:

# Install dislocker sudo apt install dislocker # Unlock the BitLocker partition (using password) sudo mkdir /mnt/bitlocker /mnt/windows sudo dislocker -V /dev/nvme0n1p3 -u -- /mnt/bitlocker # Mount the unlocked file system sudo mount -o loop /mnt/bitlocker/dislocker-file /mnt/windows

FAQ

Windows asks for the recovery key after installing Ubuntu

This happens because installing Ubuntu changed the boot configuration. Enter the 48-digit recovery key you backed up earlier. If you didn’t back it up, try logging into https://account.microsoft.com/devices/recoverykey  to find it.

Can’t find the recovery key

If you absolutely cannot find the recovery key, before installing Ubuntu:

  1. Disable BitLocker and complete decryption first
  2. Proceed with dual boot installation after decryption is done
  3. If needed, you can re-enable BitLocker after installation

Company-managed computers

BitLocker on company computers is usually managed centrally by the IT department, with recovery keys stored in the company’s management system. Consult your IT department before installing Ubuntu.

Last updated on