Windows now turns on drive encryption by itself on far more laptops than it used to — Microsoft dropped several of the old hardware prerequisites starting with Windows 11 24H2. Sounds like good news. It's only half the story.
When a new machine finishes setup, encryption starts in a holding state. The drive is scrambled, but the key to unscramble it is sitting right there on the same drive. A locked door with the key taped to it.
That state only ends when the recovery key gets backed up to your company's Microsoft tenant. On a properly enrolled work laptop, that takes minutes. On a machine someone bought at Best Buy and signed into with a personal account, it can stay that way indefinitely — while Windows cheerfully reports the drive as encrypted.
Picture an advisor's laptop stolen out of a car in a West Palm parking garage. If the drive is genuinely locked, you replaced hardware. If it isn't, you're calling clients — and you'll remember those calls for years.
It cuts the other way too. If the recovery key was never saved anywhere you can reach, a routine firmware update can throw up a recovery screen and lock you out of your own machine.
Worth ten minutes before your next cyber renewal: pull the encryption report and confirm every laptop has a key on file.
Want the next one in your inbox?
One practical Microsoft 365, Copilot, Azure, or security move per week — plain English, no pitch.
Subscribe via email