How to Create BitLocker Encrypted Container File with a VHD or VHDX File in Windows


You can use BitLocker Drive Encryption to help protect your files on an entire drive. BitLocker can help block hackers from accessing the system files they rely on to discover your password, or from accessing your drive by physically removing it from your PC and installing it in a different one. You can still sign in to Windows and use your files as you normally would.

New files are automatically encrypted when you add them to a drive that uses BitLocker. However, if you copy these files to another drive or a different PC, they're automatically decrypted.

BitLocker can encrypt the drive Windows is installed on (the operating system drive) as well as fixed data drives (such as internal hard drives). You can also use BitLocker To Go to help protect all files stored on a removable data drive (such as an external hard drive or USB flash drive).

You can also use BitLocker to encrypt a VHD or VHDX (virtual hard disk) file mounted as a drive. You can copy and move this VHD or VHDX file to any Windows computer as a portable encrypted container file. When you mount the VHD or VHDX file on a computer and try to open the encrypted drive for it, you will be prompted for your BitLocker password before it will open.

You can save files into this BitLocker drive for VHD or VHDX file when unlocked like any other drive, and lock or unmount the drive when you like to secure it.

This tutorial will show you how to create a portable BitLocker encrypted container file using a mounted VHD or VHDX file in Windows 7, Windows 8, and Windows 10.

BitLocker Drive Encryption is only available in the Windows 7 Ultimate, Windows 7 Enterprise, Windows 8 Pro, Windows 8 Enterprise, Windows 10 Pro, Windows 10 Enterprise, and Windows 10 Education editions.

You must be signed in as an administrator to mount a VHD or VHDX file and encrypt with BitLocker.

warning   Warning
When you unlock the BitLocker encrypted mounted VHD/VHDX container file (drive) with your BitLocker password, all users on the computer will be able to access the drive just like any other fixed data drive until you either lock or unmount the drive or change permissions for the drive.

If you want to copy or move the VHD or VHDX file to another location or computer, be sure you unmount the drive for it first.


EXAMPLE: VHD or VHDX file mounted as BitLocker encrypted drive
Create BitLocker Encrypted Container File with VHD or VHDX in Windows-locked.jpg Create BitLocker Encrypted Container File with VHD or VHDX in Windows-bitlocker_password_prompt.jpg
Create BitLocker Encrypted Container File with VHD or VHDX in Windows-unlocked.jpg




Here's How:

1. If you don't already have one, create and set up a new VHD or VHDX file.

2. Mount the VHD or VHDX file as a drive.

3. In File Explorer (Win+E), right click or press and hold on the drive (ex: "F") for the mounted VHD or VHDX file, and click/tap on Turn on BitLocker. (see screenshot below)

Create BitLocker Encrypted Container File with VHD or VHDX in Windows-turn_on_bitlocker_for_vhd_or_vhdx-1.jpg

4. Check Use a password to unlock the drive, enter a password you want to use to unlock the drive with, reenter your password to confim, and click/tap on Next. (see screenshot below)

Create BitLocker Encrypted Container File with VHD or VHDX in Windows-turn_on_bitlocker_for_vhd_or_vhdx-2.png

5. Select how (Microsoft account, USB, file, and/or print) you want to back up your BitLocker recovery key for this drive, and click/tap on Next when finished. (see screenshots below)

Create BitLocker Encrypted Container File with VHD or VHDX in Windows-turn_on_bitlocker_for_vhd_or_vhdx-3.png Create BitLocker Encrypted Container File with VHD or VHDX in Windows-turn_on_bitlocker_for_vhd_or_vhdx-4.png

Note   Note
Microsoft account = This option is only available when you are signed in to Windows 10 with a Microsoft account. It will save the BitLocker recovery key to your OneDrive account online at https://onedrive.live.com/recoverykey.

Create BitLocker Encrypted Container File with VHD or VHDX in Windows-bitlocker_recovery_key_save_to_microsoft_account.png

USB flash drive = This option will save the BitLocker recovery key to a selected USB flash drive.

Create BitLocker Encrypted Container File with VHD or VHDX in Windows-bitlocker_recovery_key_save_to_usb.png

File = This option will save the BitLocker recovery key .TXT file to a location you select.

Create BitLocker Encrypted Container File with VHD or VHDX in Windows-bitlocker_recovery_key_save_to_file-1.png

Print = This option will print the BitLocker recovery key to the selected printer.

Create BitLocker Encrypted Container File with VHD or VHDX in Windows-bitlocker_recovery_key_print.png

6. Select (dot) Encrypt entire drive, and click/tap on Next. (see screenshot below)

Create BitLocker Encrypted Container File with VHD or VHDX in Windows-turn_on_bitlocker_for_vhd_or_vhdx-5.png

7. Select (dot) New encryption mode or Compatible mode for what is best for how you will use the mounted VHD or VHDX drive, and click/tap on Next. (see screenshot below)

New encryption mode (XTS-AES 128-bit) = Select this mode if this drive will only be used on devices running Windows 10 version 1511 or higher. It will not work on an older version of Windows (ex: Vista, Windows 7, or Windows 8/8.1).

Compatible mode (AES-CBC 128-bit) = Select this mode if this drive is going to be used on an older version of Windows (ex: Vista, Windows 7, or Windows 8/8.1). It will still work on all versions of Windows 10.

Create BitLocker Encrypted Container File with VHD or VHDX in Windows-turn_on_bitlocker_for_vhd_or_vhdx-6.png

8. Click/tap on Start encrypting when ready. (see screenshot below)

Create BitLocker Encrypted Container File with VHD or VHDX in Windows-turn_on_bitlocker_for_vhd_or_vhdx-7.png

9. When encryption has finished, click/tap on Close. (see screenshot below)

This could take a long time to finish depending on the size of the drive and how much data on the drive is being encrypted.

Create BitLocker Encrypted Container File with VHD or VHDX in Windows-turn_on_bitlocker_for_vhd_or_vhdx-8.png


That's it,
Shawn Brink