I enabled BitLocker while looking for a way to protect a folder, but then turned it off because I didn't want a kernel-level drive lock. None of my drives are currently encrypted, but Windows still shows the option to turn BitLocker on. Is there a way to remove or permanently disable that option and return the system to its original state? Also, can I back up a BitLocker recovery key before enabling encryption?
1 Answer
There isn’t a separate recovery key until a drive is encrypted and a recovery protector is created. If you enable BitLocker again later, it will generate a new recovery key. Decrypting the drive removes the active encryption, but BitLocker remains a built-in Windows feature, so the option to turn it on will still be available.
If I enable it while using a local administrator account, does that prevent the key from being stored with my Microsoft account? I assume I’d need to retrieve or back it up manually, such as with manage-bde -protectors -get C:.

Got it—so if I enable BitLocker again later, I’ll need to create or back up a new recovery key. That makes sense now.