BitLocker Guide
BitLocker is Windows’ built-in disk encryption feature. If you plan to install Ubuntu alongside Windows in a dual boot setup, understanding and handling BitLocker is an important step before installation.
How BitLocker Affects Dual Boot Installation
Potential Issues
- Partition operations fail: The Ubuntu installer cannot shrink or modify BitLocker-encrypted partitions
- Windows won’t boot: After modifying UEFI settings (such as disabling Secure Boot), BitLocker may require a recovery key
- Cannot access the Windows partition: Ubuntu cannot read BitLocker-encrypted NTFS partitions by default
Why Changing BIOS Settings Triggers BitLocker
BitLocker uses the TPM (Trusted Platform Module) chip to store encryption keys. When it detects that the boot configuration has changed (e.g., Secure Boot disabled, boot order changed), it considers system security compromised and automatically enters recovery mode, requiring a 48-digit recovery key.
Checking BitLocker Status
Method 1: Windows Settings
- Open Settings -> Privacy & security -> Device encryption
- If you see “Device encryption is on,” BitLocker is enabled
Method 2: Command Line
Open PowerShell as administrator:
manage-bde -statusCheck the “Protection Status” and “Encryption Status” for each volume.
Method 3: Control Panel
Control Panel -> System and Security -> BitLocker Drive EncryptionBack Up the BitLocker Recovery Key
Before performing any operations, always back up the recovery key first:
Finding the Recovery Key
- Microsoft account: Visit https://account.microsoft.com/devices/recoverykey and log in with your linked Microsoft account
- Azure AD account: If it’s a company computer, contact your IT administrator
- Printout or USB drive: If you chose to print or save to USB during initial setup
Manual Backup
Run PowerShell as administrator in Windows:
# View recovery keys for all volumes
manage-bde -protectors -get C:Record the 48-digit recovery key somewhere safe (don’t save it only on the current computer).
Solutions
Option 1: Suspend BitLocker (Recommended)
After suspending BitLocker, the encrypted data is retained, but TPM verification is temporarily bypassed. This way, modifying UEFI settings won’t trigger recovery mode.
# Run PowerShell as administrator
# Suspend BitLocker (automatically resumes after one reboot)
manage-bde -protectors -disable C:
# Or suspend for multiple reboots
manage-bde -protectors -disable C: -RebootCount 3After suspending, you can safely:
- Modify UEFI settings
- Adjust the boot order
- Install Ubuntu
After installation, BitLocker will automatically re-enable protection.
Option 2: Fully Disable BitLocker
If you don’t need disk encryption, you can completely remove BitLocker:
# Turn off BitLocker (takes time to decrypt the entire disk)
manage-bde -off C:
# Check decryption progress
manage-bde -status C:Or via the GUI:
Control Panel -> System and Security -> BitLocker Drive Encryption -> Turn off BitLockerNote: Full decryption may take from tens of minutes to several hours, depending on disk size and speed. Do not shut down during this process.
Option 3: Keep BitLocker, Just Back Up the Recovery Key
If you want to keep BitLocker encryption:
- Make sure you’ve backed up the recovery key
- When modifying UEFI settings, BitLocker will trigger recovery mode
- Enter the 48-digit recovery key to unlock Windows
- After Windows boots, BitLocker will automatically adapt to the new boot configuration
Accessing a BitLocker Partition from Linux After Installing Ubuntu
If the Windows partition still uses BitLocker encryption, you can use the dislocker tool in Ubuntu to access it:
# Install dislocker
sudo apt install dislocker
# Unlock the BitLocker partition (using password)
sudo mkdir /mnt/bitlocker /mnt/windows
sudo dislocker -V /dev/nvme0n1p3 -u -- /mnt/bitlocker
# Mount the unlocked file system
sudo mount -o loop /mnt/bitlocker/dislocker-file /mnt/windowsFAQ
Windows asks for the recovery key after installing Ubuntu
This happens because installing Ubuntu changed the boot configuration. Enter the 48-digit recovery key you backed up earlier. If you didn’t back it up, try logging into https://account.microsoft.com/devices/recoverykey to find it.
Can’t find the recovery key
If you absolutely cannot find the recovery key, before installing Ubuntu:
- Disable BitLocker and complete decryption first
- Proceed with dual boot installation after decryption is done
- If needed, you can re-enable BitLocker after installation
Company-managed computers
BitLocker on company computers is usually managed centrally by the IT department, with recovery keys stored in the company’s management system. Consult your IT department before installing Ubuntu.