Wealth management

Your laptop says it's encrypted. That doesn't always mean it is.

Windows now turns on drive encryption by itself on far more laptops than it used to.

1 min readOriginally posted on LinkedIn

Windows now turns on drive encryption by itself on far more laptops than it used to — Microsoft dropped several of the old hardware prerequisites starting with Windows 11 24H2. Sounds like good news. It's only half the story.

When a new machine finishes setup, encryption starts in a holding state. The drive is scrambled, but the key to unscramble it is sitting right there on the same drive. A locked door with the key taped to it.

That state only ends when the recovery key gets backed up to your company's Microsoft tenant. On a properly enrolled work laptop, that takes minutes. On a machine someone bought at Best Buy and signed into with a personal account, it can stay that way indefinitely — while Windows cheerfully reports the drive as encrypted.

Picture an advisor's laptop stolen out of a car in a West Palm parking garage. If the drive is genuinely locked, you replaced hardware. If it isn't, you're calling clients — and you'll remember those calls for years.

It cuts the other way too. If the recovery key was never saved anywhere you can reach, a routine firmware update can throw up a recovery screen and lock you out of your own machine.

Worth ten minutes before your next cyber renewal: pull the encryption report and confirm every laptop has a key on file.

ShareLinkedInEmail

Want the next one in your inbox?

One practical Microsoft 365, Copilot, Azure, or security move per week — plain English, no pitch.

Subscribe via email

All editions