Full disk encryption (FDE) encrypts everything on a drive, the operating system, applications, temporary files and user data, so a lost, stolen or discarded device gives up nothing without the key. It works below the file system and is invisible once unlocked.
That is also its limit: FDE protects data at rest on a powered off device, and does nothing against malware, a logged in user or an unlocked laptop. In a business, the part that fails is rarely the encryption. It is the recovery key nobody stored.
- FDE protects a powered off disk, not a running computer
- BitLocker, FileVault and LUKS are the same design on three platforms
- Once the user signs in, every program reads the data in the clear
- A recovery key that was never escrowed turns a forgotten password into data loss
- File level encryption covers what full disk encryption cannot: data that leaves the disk
On this page
How it worksWhat full disk encryption is and how it works
Full disk encryption, also written whole disk encryption or simply disk encryption, turns every block written to a drive into ciphertext and turns it back on every read. It sits below the file system, so the operating system, the page file, the hibernation file, temporary files and deleted data are covered along with the documents.
The design is the same in every product. A random volume key encrypts the data, almost always with AES in XTS mode, one of the encryption algorithms built for storage. That volume key never changes in normal use. It is stored on the disk itself, wrapped by one or more other keys called protectors.
A hardware protector. A Trusted Platform Module (TPM) on a PC, or the Secure Enclave on a Mac, releases the key only if the boot process looks untampered. The user sees nothing.
A secret the user knows. A preboot PIN, a passphrase or the login password. The disk stays locked until somebody types it.
A recovery key. A long random key created at encryption time, for the day the other protectors fail.
Because only the small wrapped key depends on the password, changing a password takes a moment and does not re-encrypt the drive. Because current processors include AES instructions, users do not notice the encryption and decryption happening. Both points are why FDE became the default control for laptops.
There is also a hardware form. A self-encrypting drive does the encryption in its own controller, to the TCG Opal specification. The idea is identical, but you are trusting drive firmware you cannot inspect, which is why most organizations standardize on the software built into the operating system.
The limitsWhat full disk encryption protects, and what it does not
FDE answers one threat well: somebody has the hardware and does not have the key. A laptop left in a taxi, a server drive pulled from a rack, a computer sent for recycling, a disk returned under warranty.
Without the key the contents are noise, and no amount of booting from a USB stick or moving the drive to another computer changes that.
Everything outside that threat is outside its protection.
A running, unlocked machine. Once the disk is unlocked, the operating system decrypts on demand for whoever is using it. A laptop taken while open and signed in is an unencrypted laptop.
Malware and ransomware. Malicious code runs as the logged in user, and the disk hands it plaintext like any other program. Disk encryption does not replace business antivirus or patching.
The logged in user. An employee copying the customer list to a personal account is reading data they are authorized to read. FDE has no opinion about that.
Data that leaves the disk. An attachment sent by email, a file synced to a cloud service or copied to an unencrypted USB stick is no longer protected by the laptop's encryption.
Sleep. A sleeping computer keeps the key in memory. Microsoft's BitLocker countermeasures guidance, for scenarios that need protection against memory attacks, says to use a TPM with a PIN and to disable standby power management, so that the device shuts down or hibernates instead.
Network access. A file server with encrypted drives serves plaintext to anyone with share permissions. Encryption at rest on a server protects the disks when they leave the building, and little else.
The honest summary is that full disk encryption is a control for loss and disposal of physical devices. It belongs in every security baseline, next to multifactor authentication and endpoint protection, and it replaces none of them.
File levelFull disk encryption vs file level encryption
The file level encryption vs full disk encryption question comes up because the two sound like alternatives. They solve different problems, and most organizations need both.
Full disk encryption protects the container. Everything is covered automatically, nothing depends on a user remembering, and protection ends at unlock. File level encryption protects chosen files or folders with their own keys, so a file stays encrypted when it is copied, emailed, backed up or opened by another account on the same machine.
That makes file level encryption the right tool for a payroll folder on a shared server, or a document sent to an outside accountant. It is the wrong tool as the only control on a laptop, because it leaves the swap file, temporary files, browser caches and anything saved in the wrong folder exposed.
The productsHow BitLocker, FileVault and LUKS map to the same idea
Full disk encryption software is built into every major desktop operating system, so for most businesses the question is how to manage it, not which product to buy.
BitLocker on Windows. Microsoft's documentation lists Windows Pro, Enterprise, Pro Education/SE and Education as the editions that support BitLocker, and requires TPM 1.2 or later for the boot integrity check. A separate feature, device encryption, turns BitLocker on automatically on eligible hardware in any edition. With a TPM alone the disk unlocks with no prompt.
FileVault on macOS. Apple states that on a Mac with Apple silicon or the T2 chip, data is encrypted automatically, and turning on FileVault ties decryption to the login password. The page on FileVault disk encryption explains what that changes.
LUKS on Linux. LUKS is a header format on top of the kernel's dm-crypt. The cryptsetup documentation describes multiple passphrases, each in its own keyslot, that can be revoked one by one. LUKS2 is the default format. Most installers offer it as a checkbox, and it must usually be chosen at install time.
Third party tools such as VeraCrypt exist, and endpoint security suites sell management consoles for the native tools. For a business the console is what matters: proof that every device is encrypted, and one place where the recovery keys live.
Key escrowThe recovery key is the part businesses get wrong
Encryption that works is unforgiving. If the TPM refuses to release the key after a firmware update, or an employee forgets a passphrase, the recovery key is the only way back in. If nobody has it, the data is gone. There is no back door to call a vendor about.
Escrow means a copy of each device's recovery key is stored centrally, where an administrator can retrieve it and the user cannot lose it.
- Windows. BitLocker can back the key up to Microsoft Entra ID or Active Directory Domain Services. The page on the BitLocker recovery key covers where to look.
- macOS. Apple's FileVault page notes that a business or school can set its own recovery key, which in practice means escrow through an MDM.
- Linux. LUKS has no built in escrow. Add an administrative passphrase in a second keyslot and keep a header backup, because the cryptsetup FAQ warns that a damaged header usually means permanent data loss.
Three failures repeat. Devices encrypted by the user before enrollment, with the key saved to a personal account. Keys stored in a spreadsheet that the departing administrator took with them. Escrow configured, and never tested by actually unlocking a machine with an escrowed key.
Handle the recovery key like a password to everything on the device, because that is what it is. Restrict who can read keys, log every retrieval, and rotate a key after it has been read out to a user over the phone.
PitfallsWhere people go wrong
Treating FDE as ransomware protection. It is not. Ransomware runs inside the unlocked session and encrypts your files a second time with a key you do not have.
Encrypting first and escrowing later. Set the policy so that encryption does not start until the recovery key has been backed up. BitLocker policy has a setting for exactly this, which blocks encryption until the recovery information is stored in the directory.
Leaving laptops asleep in bags. Set the lid close action to hibernate or shut down for staff who travel, and add a preboot PIN where the data justifies the inconvenience.
Forgetting removable media and servers. The laptop is encrypted and the USB stick with the same files is not. Decide whether external drives must be encrypted before they can be written to.
Skipping it on desktops. Desktops get stolen in break ins and their drives get thrown away at end of life. Encrypting them makes disposal simple: destroy the keys and the data is unreadable.
Updating firmware without suspending protection. A BIOS or UEFI update changes what the TPM measures, and the next boot asks for the recovery key. Suspend protection first, update, then resume.
ComparisonFull disk, file level and self-encrypting drives, and what each one covers
| Criterion | Full disk encryption | File level encryption | Self-encrypting drive |
|---|---|---|---|
| What is encrypted | The whole drive | Chosen files and folders | The whole drive |
| Depends on the user | No | Yes, the file must be in the right place | No |
| Protects a lost or stolen device | Yes | Only the chosen files | Yes, if a password is set |
| Protects a file after it is copied or sent | No | Yes | No |
| Protects against malware in the session | No | No | No |
| Covers swap and temporary files | Yes | No | Yes |
| Central recovery key escrow | Built into BitLocker and MDM for FileVault | Depends on the product | Depends on the management tool |
The row that decides most designs is the fourth. Full disk encryption stops protecting a file the moment it leaves the drive, so anything sensitive that is shared needs file level encryption or access control that travels with it.
The fifth row is the reminder that no form of encryption at rest stops an attacker who is already inside the session.
FAQFrequently asked questions
What is full disk encryption?
Full disk encryption is a method that encrypts every block of a drive, including the operating system, swap and temporary files, so the contents cannot be read without a key. It protects a lost, stolen or discarded device and works automatically once the device is unlocked.
What does FDE stand for?
FDE stands for full disk encryption. The same thing is called whole disk encryption, drive encryption or simply disk encryption. BitLocker on Windows, FileVault on macOS and LUKS on Linux are all FDE implementations built into the operating system.
How does FDE encryption work?
A random volume key encrypts every sector, usually with AES in XTS mode. That key is stored on the disk, wrapped by protectors such as a TPM, a PIN, a passphrase and a recovery key. Unlocking any one protector releases the volume key, and reads and writes are then transparent.
Does full disk encryption protect against malware or ransomware?
No. Malware runs inside the unlocked session, where the operating system decrypts data for every program. Full disk encryption protects a device that is powered off and in the wrong hands. Ransomware, phishing and data theft by a logged in user need other controls.
Is a laptop protected while it is asleep or locked?
Only partly. The key stays in memory during sleep, so attacks on memory remain possible. Hibernation or a full shutdown removes the key from memory. For sensitive data, combine a TPM with a preboot PIN and make closing the lid hibernate the machine.
What is the difference between file level encryption and full disk encryption?
Full disk encryption covers the whole drive automatically and ends at unlock. File level encryption protects individual files with their own keys, so they stay encrypted when copied or sent. Use full disk encryption on every device and file level encryption for sensitive data that is shared.
Does full disk encryption slow a computer down?
On current hardware users do not notice it. Processors include dedicated AES instructions, and the work happens as data is read and written. The initial encryption of a drive that already holds data takes time, and the machine remains usable while it runs.
Do I need to buy full disk encryption software?
Usually not. Windows includes BitLocker in its business editions, macOS includes FileVault and Linux distributions include LUKS. What businesses pay for is management: a console, often part of an MDM or endpoint suite, that enforces encryption, reports status and escrows recovery keys.
What happens if I lose the recovery key and forget the password?
The data is unrecoverable. There is no master key and the vendor cannot help. This is the reason business devices should escrow recovery keys centrally, in Microsoft Entra ID, Active Directory or an MDM, before encryption is allowed to start.
Is a TPM required for disk encryption?
No, but it helps. BitLocker can use a startup key on a USB drive or a password on a device without a TPM, and LUKS works with a passphrase alone. A TPM adds a check that the boot process was not tampered with and allows unlocking without a prompt.
Should servers and desktops use whole disk encryption too?
Yes, with a plan for unattended restarts. Drives leave buildings through theft, warranty returns and disposal. Servers need a way to unlock after a reboot without someone typing a passphrase, such as a TPM or a network based unlock.
Does full disk encryption make it safe to throw a drive away?
It makes disposal far simpler. If the drive was always encrypted and the keys are destroyed, the remaining data is unreadable. Many organizations still wipe or physically destroy drives that held regulated data, because a policy auditor can verify that.
Keep readingRelated concepts
Read next · Cryptography The BitLocker Recovery Key, and Why the Screen Appeared Where a BitLocker recovery key is stored, what triggers the recovery screen, and how to avoid it. Open this next10 min- Cryptography · 11 min Encryption Algorithms, and the Two Families They Fall Into AES, RSA and the other ciphers behind disk, file and network encryption, and which are still safe.
- Cryptography · 9 min FileVault Disk Encryption, and Why the Disk Is Already Encrypted What turning on FileVault changes on a Mac whose drive is already encrypted in hardware.