Skip to content

Recommendation

Recommended to disable

On a desktop home gaming PC, disable automatic BitLocker activation if it holds no data that requires protection against physical theft.

For a laptop, portable PC or a system with confidential data, leave encryption enabled.

Recommended state
Auto-DE disabled
Benefit
No software BitLocker overhead
Cost
No data protection in case of theft

Software BitLocker encrypts and decrypts data during input/output using the CPU. The additional load on the drive and processor is confirmed. Its magnitude depends on the platform and the workload: Microsoft states a typical impact within a single-digit percentage, while a Windows 11 Pro test on a Samsung 990 Pro showed a stronger drop in some random input/output metrics.

On a home desktop gaming PC without confidential data, it is recommended to disable Automatic Device Encryption. This will prevent automatic BitLocker activation in the future and the appearance of the load associated with software encryption. The gain in FPS and the improvement in 1% low were not measured here and are not guaranteed.

The recommendation does not apply to laptops, portable computers and systems with work documents, personal archives, financial data or other materials that must be protected in case of theft or removal of the drive. BitLocker is designed specifically to protect data from offline access to a lost, stolen or decommissioned device.

Windows 11 versus Windows 10. On a clean installation of Windows 11, device encryption turns on automatically: after OOBE completes, Windows initializes encryption of the system and fixed drives, first with a “transparent” key. Protection activates after signing in with a Microsoft account or an organization account; with a local account the data remains unprotected. Starting with Windows 11 24H2, Microsoft removed the Modern Standby/HSTI requirements and the requirement for no external DMA ports, so automatic encryption covers far more systems, including home editions. On Windows 10 this feature also exists, but it requires Modern Standby/HSTI and no external DMA ports — a typical desktop PC does not meet these requirements, so encryption there usually does not turn on by itself. Check the actual state in “System Information” (the “Device Encryption Support” line), not just by the Windows version.

Field Value
Hive and path HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\BitLocker
Name PreventDeviceEncryption
Type REG_DWORD
Disable Auto-DE 1
Allow Auto-DE delete the value

Microsoft recommends keeping device encryption enabled on supported systems. The BoosterX recommendation differs only for a home desktop gaming PC whose owner is willing to accept the risk of physical access to an unencrypted drive in order to avoid the software BitLocker overhead.

In BoosterX, open “Optimization” → “Security” → “Hardening (VBS/UAC)” → “Auto-encryption” and turn on the toggle: BoosterX will apply the ban on automatic encryption. Click “Apply” at the bottom of the page. If “Instant apply” is enabled, the change is made immediately.

To allow Automatic Device Encryption again, turn off the same toggle and apply the change. BoosterX will remove the ban and return control to Windows. This allows Windows to enable encryption in the future, but does not mean that BitLocker activates immediately.

Disabling Auto-DE does not decrypt an already protected drive and does not turn off BitLocker that was enabled manually. If BitLocker is already active, check its actual state in Settings → Privacy & security → Device encryption or in the BitLocker control panel.

Before changing an active BitLocker, make sure you have the recovery key. The BoosterX setting does not decrypt the drive, so toggling it on an already encrypted system provides no confirmed performance benefit.

Additional CPU operations and a drop in storage performance in software mode are confirmed. A universal impact on FPS, 1% low, frametime and game load times is not confirmed. The result of a third-party test on a single configuration cannot be transferred to all SSDs and processors.

The availability of Automatic Device Encryption depends on the Windows edition, hardware, TPM, Secure Boot and the state of the device. Check the actual status, not just the Registry policy.

Last check: 2026-09-20.