manage-bde -on Volume [{-RecoveryPassword|-rp} [NumericalPassword] ] [{-RecoveryKey|-rk} PathToExternalKeyDirectory] [{-StartupKey|-sk} PathToExternalKeyDirectory] [{-Certificate|-cert} {-cf PathToCertificateFile| -ct CertificateThumbprint}] [{-TPMAndPIN|-tp}] [{-TPMAndStartupKey|-tsk} PathToExternalKeyDirectory] [{-TPMAndPINAndStartupKey|-tpsk} -tsk PathToExternalKeyDirectory] [{-Password|-pw}] [{-ADAccountOrGroup|-sid} {SID|domain\user|domain\group} [-service]}] [{-UsedSpaceOnly|-used}] [{-EncryptionMethod|-em} {aes128| aes256}] [{-SkipHardwareTest|-s}] [{-Synchronous|-sync}] [{-DiscoveryVolumeType|-dv} {FAT32|[none]|[default]}] [{-ForceEncryptionType|-fet} {Hardware|Software}] [{-RemoveVolumeShadowCopies|-rvsc}] [{-ComputerName|-cn} ComputerName] [{-?|/?}] [{-Help|-h}] Description: Encrypts the volume and turns BitLocker protection on. Parameter List: Volume A drive letter followed by a colon, a volume GUID path or a mounted volume. Example: "C:", \\?\Volume{26a21bda-a627-11d7-9931-806e6f6e6963}\ or "C:\MountVolume" -RecoveryPassword or -rp Adds a Numerical Password protector. -RecoveryKey or -rk Adds an External Key protector for recovery. -StartupKey or -sk Adds an External Key protector for startup. -Certificate or -cert Adds a public key protector for the data volume. -TPMAndPIN or -tp Adds a TPM And PIN protector for the OS volume. -TPMAndStartupKey or -tsk Adds a TPM And Startup Key protector for the OS volume. -TPMAndPINAndStartupKey or -tpsk Adds a TPM And PIN And Startup Key protector for the OS volume. -Password or -pw Adds a password key protector for the volume. -ADAccountOrGroup or -sid Adds a SID-based Identity protector for the volume. -UsedSpaceOnly or -used Performs encryption of the existing used space on the volume. -EncryptionMethod or -em Configures the encryption algorithm and key size. -SkipHardwareTest or -s Begins encryption without a hardware test. -Synchronous or -sync Forces manage-bde to wait until the -on command has finished before displaying the command prompt. -DiscoveryVolumeType or -dv Specify file system to use for the discovery volume. -ForceEncryptionType or -fet Forces BitLocker to use either software or hardware encryption. -RemoveVolumeShadowCopies or -rvsc Forces deletion of Volume Shadow Copies for the volume. -ComputerName or -cn Runs on another computer. Examples: "ComputerX", "127.0.0.1" -? or /? Displays brief help. Example: "-ParameterSet -?" -Help or -h Displays complete help. Example: "-ParameterSet -h" Examples: manage-bde -on C: -RecoveryPassword manage-bde -on C: -RecoveryKey e:\ -RecoveryPassword manage-bde -on C: -rp -rk "f:\Folder" -SkipHardwareTest manage-bde -on E: -pw manage-bde -on E: -UsedSpaceOnly manage-bde -on E: -sid Domain\User manage-bde -on E: -sid Domain\Machine$ -service
manage-bde -changepassword Volume {-ComputerName|-cn} ComputerName {-?|/?} {-Help|-h} Description: Modifies password for ...
manage-bde -changepin Volume {-ComputerName|-cn} ComputerName {-?|/?} {-Help|-h} Description: Modifies PIN for a volume. ...
manage-bde -lock Volume {-ForceDismount|-fd} {-ComputerName|-cn} ComputerName {-?|/?} {-Help|-h} Description: Prevents access ...
manage-bde -off Volume {-ComputerName|-cn} ComputerName {-?|/?} {-Help|-h} Description: Decrypts the volume and turns BitLocker ...
manage-bde -on Volume {-RecoveryPassword|-rp} NumericalPassword {-RecoveryKey|-rk} PathToExternalKeyDirectory {-StartupKey|-sk} ...
manage-bde -on Volume {-RecoveryPassword|-rp} NumericalPassword {-RecoveryKey|-rk} PathToExternalKeyDirectory {-StartupKey|-sk} ...
manage-bde -pause Volume {-ComputerName|-cn} ComputerName {-?|/?} {-Help|-h} Description: Pauses encryption, decryption, ...
manage-bde -protectors -adbackup Volume -ID KeyProtectorID {-ComputerName|-cn} ComputerName {-?|/?} {-Help|-h} Description: ...
manage-bde -protectors -add Volume {-ForceUpgrade} {-RecoveryPassword|-rp} NumericalPassword {-RecoveryKey|-rk} PathToExternalKeyDirectory ...