Encrypt USB drives with BitLocker To Go
Require removable-media encryption through Intune with BitLocker To Go: writes blocked on unencrypted sticks, reads preserved, and clear GDPR compliance.
A USB stick left on a train, an external drive lost in a taxi: it is one of the most ordinary causes of a data leak, and one of the hardest to prevent through user vigilance alone. BitLocker To Go encrypts removable media so their contents stay unreadable without a password, even if the drive falls into the wrong hands. And it is all driven from Intune, which spares you from trusting every employee to encrypt their stick by hand.
The stakes are simple: a customer file, an accounting export or a contract copied onto an unencrypted stick becomes, if lost, a potential data breach that you may have to report to regulators and to the people affected. With BitLocker To Go, the same incident is reduced to the loss of an object worth a few euros, with no consequence for the individuals concerned. It is a quiet control, but one that radically changes the scope of an incident and the cost of dealing with it.
Encrypt without blocking daily work
BitLocker To Go applies to USB sticks and external drives, independently of the system-disk encryption handled by classic BitLocker. The recommended policy is not to ban removable media, which often just pushes users to work around the rule, but to require encryption for any write.
- Require removable-media encryption before allowing writes.
- Block write access to unencrypted media while still allowing reads, so inbound exchanges keep working.
- Set an unlock method: a strong password or a smart card.
- Choose a modern algorithm, AES-XTS 256-bit.
That read-only setting on unencrypted media matters: a partner can still hand you a stick for you to read its contents, but your staff cannot copy company data onto it without encrypting it first. The protection therefore applies exactly where the risk is, at the point where data leaves the organisation, rather than getting in the way of the many legitimate reads that pose no threat.
Deploy the policy through Intune
In Intune, BitLocker is configured through a Disk encryption profile (Endpoint Security). The section for removable data drives holds the BitLocker To Go settings, separate from those for system and fixed drives.
- 1Create or edit a BitLocker disk encryption profile.
- 2In the removable-drive settings, enable encryption required for write access.
- 3Deny write access to devices not protected by BitLocker.
- 4Enable automatic escrow of the recovery key to Microsoft Entra.
- 5Assign the profile to a group of Windows devices and check the encryption state in the reports.
The first encryption of a stick triggers when it is plugged in: the user sets a password, and the drive is then reusable transparently. Plan a short informational message to explain this step to users, so they do not mistake the BitLocker prompt for a phishing attempt.
Common mistakes to avoid
Encrypting removable media is simple in principle, but a few configuration mix-ups can create unexpected blocks.
- Confusing the system, fixed and removable drive settings, and mistakenly blocking writes to the internal disk.
- Forgetting to enable recovery-key escrow, which makes a forgotten password unrecoverable.
- Banning removable media entirely instead of requiring encryption, pushing users towards unmanaged workarounds.
- Failing to document the recovery procedure, generating support calls on every forgotten password.
Escrow the recovery key
As with the system disk, BitLocker To Go generates a recovery key. If the password is forgotten, it is the only way to recover the data on the drive. Configure Intune to automatically store that key in Microsoft Entra: an administrator can retrieve it, and the user has nothing to keep themselves.
Without this escrow, a forgotten password means lost data and a USB stick to reformat. It is an easy step to overlook, but it makes the difference between a policy that is genuinely workable day to day and a recurring source of support calls. Document who is allowed to view these keys, because that access lets them decrypt any drive in the fleet.
An often-forgotten link in compliance
GDPR requires appropriate technical measures to protect personal data, and encryption of removable media is explicitly cited as a mitigation. If an encrypted stick is lost, the leak is generally deemed to pose no risk to the individuals concerned, which can exempt you from notifying the supervisory authority and the individuals. Removable-media encryption also sits among the controls expected by ISO 27001 and NIS2.
Guide users through the first encryption
The success of a BitLocker To Go rollout depends as much on communication as on the technical configuration. The first time a user plugs in a stick after the policy takes effect, a prompt asks them to set an unlock password. Without prior explanation, that unexpected window is often mistaken for a phishing attempt, and the user cancels it or calls support. A short heads-up message sent beforehand changes everything.
- 1Announce the date the policy takes effect and explain in one sentence why removable media must be encrypted.
- 2State that the BitLocker prompt is legitimate and remind users to choose a strong, memorable password.
- 3Point out that reading sticks received from outside still works with no extra steps.
- 4Give the support contact in case of doubt, so a user does not work around the rule with an unmanaged storage service.
This small onboarding effort noticeably cuts the volume of tickets in the first days and improves buy-in. A user who understands the measure respects it; a surprised user tries to bypass it. Because key escrow is enabled, you can also reassure everyone that a forgotten password never means permanently losing their data.
How AuPoint simplifies BitLocker To Go
Telling system, fixed and removable drive settings apart in the native console invites confusion, and one wrong setting can block writes everywhere. AuPoint is a SaaS that makes Intune security and compliance easy, with no PowerShell. It ships a ready-made BitLocker To Go policy, with key escrow on by default, an impact preview before applying and one-click reversibility. You connect your Microsoft tenant, see what changes, then encrypt your removable media cleanly.
Frequently asked questions
Will users still be able to read partners' sticks?
Yes. The recommended configuration blocks writes to unencrypted media but allows reads. Your staff can still view the contents of a stick received from outside; they simply cannot write data to it without encryption.
What happens if a user forgets their password?
If escrow is enabled, an administrator retrieves the recovery key from Microsoft Entra and gives it to the user to unlock the drive. Without escrow, the data is permanently lost and the stick has to be reformatted, which is why this setting matters so much and should be turned on from the very first deployment.
Does BitLocker To Go slow down access to sticks?
AES-XTS encryption is hardware-accelerated on modern processors and the performance impact is negligible for office use. Only the very first encryption of a drive takes a few minutes, and it runs in the background so the user can keep working while it completes.
Can an encrypted stick be read on a personal computer?
Yes, provided you know the unlock password. BitLocker To Go lets you unlock an encrypted drive on any recent Windows machine, including outside the company domain. macOS can read these drives with a third-party utility. The encryption therefore protects the data if the drive is lost, without tying it to a single machine.
Connect your Microsoft tenant to AuPoint and encrypt your removable media with BitLocker To Go in minutes, with an impact preview and guaranteed rollback, no PowerShell. Start free at aupoint.io.