I of the best means to protect your privacy is to encrypt important data on your reckoner. Whether y'all demand to ship personal information to someone, or simply want to brand sure that no one who gets access to your computer can see stuff you lot would rather go on individual, encryption is the way to go.

Editor's Note:
Invitee author Heinrich Long is a author at Restore Privacy, a web log dedicated to inform near all-time online privacy practices, secure your electronic devices, unblock restricted content and defeat censorship.

As a Windows x user, you have numerous options for encrypting information. In this guide we will prove you means to encrypt private files, file folders, and even unabridged disk drives. Each approach has its own benefits and drawbacks, so we'll cover those, besides. That fashion, you'll accept a better sense of which type of encryption you will need for various situations. Earlier we go further, hither are a couple of points to go along in listen:

  • With Windows 7 now unsupported, and Windows viii best forgotten as fast equally possible, this guide deals only with the Windows x operating arrangement.
  • If yous are encrypting a file to share with someone else and need to requite them the password, you should not send them that password using the same method that yous send them the file. For case, if you plan to electronic mail them the file, it would be a large security hazard to also email them the password. Ideally give them the password over the telephone, a secure messaging app like Signal or Wickr Me. At the very least send it via a different email service than the one you will utilise for the file.

At present allow'due south talk about when to use the three types of encryption that y'all can use:

  • Individual file encryption
  • Binder encryption
  • Hard drive / Deejay encryption

Individual file encryption

Equally the name implies, individual file encryption refers to encrypting ane file at a time. Each file has its own password or key.

Private file encryption is bang-up for files y'all program to share or shop in the cloud. Windows x users can encrypt individual files using a tool like 7-zip. Y'all can also encrypt individual Microsoft Role files from within their apps, although this is amend suited to casual person apply than protection confronting serious adversaries.

Folder encryption

Next upward is folder level encryption. This approach involves encrypting everything that is stored in a folder. Passwords or keys are assigned to the folder, not individual files.

Binder encryption is a corking organizational tool. For example, you lot could create a different encrypted folder for each fellow member of your family unit. Give Sally only the password for her folder, and Jimmy but the password for his, and each can have their ain private space on the same device.

Note that storing a file in an encrypted folder doesn't prevent yous from likewise encrypting files individually.

Difficult drive / Disk encryption

Hard drive or disk encryption protects the entire drive at in one case. To use a device with an encrypted difficult bulldoze y'all would need to enter the password or fundamental when you logged on, or zip on the deejay would be accessible.

This kind of encryption is a good first line of defence force in instance of theft. If someone stole your laptop, or ripped the drives out of one of your servers, they would need to defeat the hard bulldoze encryption to get any data at all.

You lot can still utilise binder level encryption and individual file encryption to an encrypted disk.

Password management and file encryption

Before we dive into the details of file encryption, we need to make an of import notation on passwords. You demand to exist using a good password managing director, along with good countersign hygiene.

Why is that? Well, if you lose or forget the password for accessing your encrypted files, then they'll probably exist gone for good. A proficient countersign manager is critical. Nosotros've reviewed many options, including 1Password, LastPass, and many more.

Run into our guide on the best password managers for the height recommendations and step-by-stride information for good password management. At present that we've hit the basics, it is time for some specifics. Let's showtime with…

How to encrypt files and folders on Windows x

Your options for encrypting files and folders on Windows 10 devices depend on which version of Windows 10 you have. Windows 10 Pro and Enterprise users have a built-in encryption tool called the Encrypting File System (EFS). Any Windows x user, including those with the Domicile edition, can besides apply third-party apps such equally 7-zip for file and binder encryption.

Beyond these options, Microsoft Role apps take a basic file locking / encryption characteristic built in, as does Adobe Acrobat. We'll round out our coverage of Windows 10 encryption by taking a look at these.

How to encrypt files and folders with the Encrypting File Organization (EFS)

The Encrypting File Organization (EFS) is congenital into the Professional and Enterprise versions of Windows 10. It is treated as an Advanced feature of the Windows File Explorer. This makes a lot of sense, since used carelessly, EFS can leave you with files you tin can never admission once more.

EFS does all its encryption work in the background, including automatically creating a File Encryption Cardinal (FEK), and encrypting that key so but the account that encrypted the file tin decrypt it. All this happens automatically and transparently.

Aside from a lock symbol that appears in the File Explorer next to a file or binder that is encrypted, there is no piece of cake mode to tell that a file or folder is encrypted with EFS.

Unfortunately, EFS has some quirks that make information technology a less than ideal choice for many uses. Knowing what these are will assist y'all decide whether EFS is the answer to your Windows 10 file encryption needs:

  • EFS but works on drives formatted with NTFS.
  • If y'all move an EFS-encrypted file to a deejay formatted with FAT32 or exFAT, it becomes decrypted.
  • If you motion an EFS-encrypted file across a network, or ship it with an e-mail message, it becomes decrypted.

If these quirks haven't scared you lot away, here'southward how to encrypt files and folders with EFS:

  1. Launch Windows File Explorer and navigate to the file or folder you want to encrypt using EFS.
  2. Correct-click the file or folder you want to encrypt.
  3. In the card that appears, select Properties.
  4. In the General tab of Properties, find and click the Advanced push button (it is circled in carmine in the following image).

  1. In the Advanced Attributes dialog box that appears, set the Encrypt contents to secure data checkbox.

  1. Click OK until you return to the document window.

That is all you need to practise, from now on, the encrypted file or folder will appear encrypted to anyone other than the user account that encrypted the item in the outset place.

How to encrypt files and folders with vii-nil

7-cypher is a freeware file compression program that can too encrypt files and folders using AES-256 encryption, which is the industry standard for nigh encrypted systems. If you plan to use 7-goose egg to encrypt files or folders you should know that the process creates an encrypted re-create of the file or folder. The original, unencrypted file or folder is unchanged.

If yous are creating the encrypted item because you plan to ship it somewhere, or shop information technology in the cloud or something like that, this is fine. Merely if your goal is to protect the files and folders on your own device, this isn't ideal.

In the rest of this section, nosotros'll start look at how to encrypt files and folders with 7-zip. After that nosotros'll talk well-nigh what else you demand to do if your goal is to protect the files and folders on your own device. The following instructions presume yous already have vii-aught installed on your system. If non, yous tin download it here.

How to encrypt Windows 10 files and folders using 7-zip

  1. Right-click the file or binder you want to encrypt.
  2. In the shortcut card that appears, select 7-Zip, then Add to annal…. This opens the Add together to Archive window.

  1. In the Annal field, enter the name for the archive you lot will create.
  2. In the Archive format list, select zip.
  3. In the Encryption section of the window, enter a potent password in the Enter password field, and over again in the Reenter password field.
  4. In the Encryption Method listing, select AES-256.
  5. Select OK. This creates the encrypted archive file, which appears in the same folder equally the file or folder you lot encrypted.

What to do afterwards you encrypt something with 7-zip

The result of encrypting something with seven-zilch the way we did hither is a zipped archive that is AES-256 encrypted. This archive appears in the same binder as the file or folder that you encrypted, aslope the original file or folder. What this ways to y'all depends on what y'all programme to practice with the encrypted file or folder.

If yous created the annal to share copies of the file or folder, this is fine. Just send the annal to the recipient. Assuming they take 7-naught or a similar program on their system (and you securely conveyed the countersign to them somehow), they will be able to unzip the archive, then double-click the file to enter the password in a dialog box like this one:

Once they exercise that, the operating organization should open the file in whatever app is advisable, and the recipient can view it, or save it, or do whatever is necessary with information technology. Note that they will nevertheless have the encrypted files on their system too.

If you created the archive to protect the files or folders on your organization, y'all should skip down to the section titled, "Eliminate whatsoever possible unencrypted copies of the file" once you lot are done encrypting files and follow the instructions at that place to make sure no unencrypted copies of things are lying around where some snoop tin detect them.

How to encrypt Microsoft Part files on Windows 10

Some applications now accept options to encrypt the types of files they themselves utilise. For example, Microsoft Word can encrypt Word files, and Adobe Acrobat can encrypt PDF files. We'll demonstrate this beneath.

How to encrypt files using Microsoft Office on Windows

Let'southward apply Microsoft Word to bear witness how it is done by encrypting a simple Word document.

  1. With the document you want to encrypt open in Word, select File, so Info.
  2. In the Info window, select Protect Document.
  3. In the menu that appears, select Encrypt with Countersign.

  1. In the dialog box that appears, enter the countersign you want to apply for this document.

From at present on, the just way to view this document volition be by entering the password when prompted from within a Microsoft Role application that supports the unencrypted file type. But please see the next department to eliminate any possible unencrypted copies of the file on your computer.

Eliminate any possible unencrypted copies of the file

If y'all utilize 7-zip or Microsoft Office to encrypt files, it is probable that Windows 10 still has one or more than temporary copies of the unencrypted files stashed on the deejay. To be safe, you will desire to delete all temporary files in one case y'all are done encrypting things.

How to delete any possible unencrypted copies of the file

  1. Click Beginning, then blazon temporary into the search box. In the menu that appears, select Delete temporary files. This opens the Storage settings window.
  2. Windows 10 scans your system and displays a list of file types that are stored on the various disk drives of your system. Select Temporary files to come across a list of the file types that are available to delete.
  3. In that list, ready the Temporary files and Recycle Bin checkboxes, then click the Remove Files button at the pinnacle of the list to obliterate any unencrypted copies of the file that might nonetheless be floating around on your system.

How to encrypt hard drives on Windows 10

When it comes to disk encryption on Windows 10, BitLocker Device Encryption is the tool that Microsoft provides. Built into Windows 10 Pro and Enterprise, BitLocker Device Encryption does exactly what it sounds similar – it encrypts all the storage devices in your system.

This sounds ideal, simply there are some drawbacks to using BitLocker.

  • If BitLocker Device Encryption wasn't preinstalled and configured on your estimator, it can be a real headache to install and configure. Check out this Overview of BitLocker Device Encryption posted on Microsoft.com.
  • BitLocker has different capabilities depending on what hardware your computer has built onto its motherboard.
  • As mentioned earlier, BitLocker only works on Windows ten Professional person and Enterprise systems.

Happily for us, there is a great alternative available. Called VeraCrypt, it addresses all of the drawbacks we just saw:

  • VeraCrypt is significantly easier to install than BitLocker.
  • VeraCrypt is not dependent on special hardware congenital into your computer.
  • VeraCrypt works on every version of Windows 10, non just Pro and Enterprise.

VeraCrypt is Free, Open Source Software (FOSS), which we really like. Without getting into the OpenSource vs Proprietary software statement that plagues the computer world, from our perspective, FOSS software is generally considered more secure, and of course is gratuitous to use. In one case VeraCrypt is installed, all you need to do is enter your VeraCrypt password whenever yous start the figurer.

Given all that, you know where we're going with this. In the following section we'll walk y'all through installing VeraCrypt on one of our lab machines. Ready?

How to install VeraCrypt for Windows 10 hard drive / disk encryption

While installing VeraCrypt is much simpler than the alternative, there is more than to it than just launching an installer and pressing Okay a few times. And if y'all mess upward, there is a chance you will lose files or fifty-fifty access to the unabridged deejay drive.

Nosotros propose you read through the instructions that follow before starting the process. If you are non confident you tin consummate the steps shown, or if you have a bad habit of losing important passwords, information technology is better to skip this type of encryption.

Installing VeraCrypt

Here are the steps to install VeraCrypt on Windows 10:

  1. You will need a standard USB drive for the VeraCrypt Rescue Disk yous will create later on. Find yourself a USB bulldoze y'all can dedicate to this, and format it as Fatty or FAT32 so it is set when we need information technology.
  2. You will too need a program that can unzip files. We recommend 7-cipher, the free and open source zip program we have discussed elsewhere in this guide. Y'all tin download vii-zip here.
  3. Get to the VeraCrypt download page and look for the Windows Installer.
  4. Launch the VeraCrypt setup program and take all the default options displayed in the Setup Wizard.
  5. After a moment, VeraCrypt should display a message stating that "VeraCrypt has been successfully installed."
  6. Click OK to shut the Wizard, then Finish to complete the installation process. VeraCrypt will display the message shown below.

  1. If yous are new to VeraCrypt, it is worthwhile to follow the advice given hither and view the tutorial. Click Yep to view the tutorial, or No to skip information technology. Either way yous go is fine since we will walk you lot through the rest of the steps right here.
  2. Launch VeraCrypt. Select the System menu, then Encrypt Organisation Partition/Bulldoze.

  1. The VeraCrypt Volume Cosmos Magician appears. The Wizard asks what blazon of system encryption you want: normal, or subconscious. Normal simply encrypts the system sectionalisation and is what we want, so select Normal, then click the Next push to proceed.
  2. Next the wizard volition ask y'all whether to encrypt just the Windows arrangement partition, or the unabridged drive. If you have multiple partitions with important information, you lot can encrypt the whole drive. If you but accept i partition on the drive (as we do on this computer), VeraCrypt volition only let y'all select the Encrypt the Windows system partition option. Make your choice and click Adjacent when prepare.

  1. The Sorcerer displays the Number of Operating Systems window. Is your organization dual-kick or multi-boot (you can start the system in various operating systems)? If so, select Multi-kick. Otherwise, select Unmarried-kick. Click the Next push to go along.
  2. The Sorcerer displays the Encryption Options window. Nosotros recommend you cull AES for the Encryption Algorithm, and SHA-256 for the Hash Algorithm. Both are widely-used algorithms that volition serve you well. Click the Next push to continue.
  3. The Magician displays the Password window. It is important to cull strong passwords if you want your system to be secure. Many password manager programs (such equally our top option, Bitwarden) include password generators that tin can help you create a strong ane. Notation: VeraCrypt will hassle you nearly information technology if you choose a password less than xx characters long. Click the Adjacent button to go along.
  4. The Wizard displays the Collecting Random Data window. Y'all will be required to motility your mouse around randomly within the window. This additional randomness increases the strength of your encryption keys. Once the randomness meter at the bottom of the window is full you tin can click the Next push to continue.
  5. The Wizard displays the Keys Generated window. There is zilch you need to do here except click the Next push button to continue.
  6. The Wizard now forces y'all to create a VeraCrypt Rescue Disk (VRD). The explanation for this appears in the following paradigm. If y'all want to alive dangerously you tin can set the Skip Rescue Disk verification checkbox to avoid being forced to create a physical rescue disk. Make note of where VeraCrypt says information technology will store the Nada image, and so click Next to go on.
  7. Unless you selected the Skip Rescue Disk verification option in the last pace you are now going to be forced to create a physical rescue disk and let VeraCrypt to audit it to see if you did it right. VeraCrypt doesn't tell yous how to practise this or assist in any way, but we can. Remember finding a spare USB drive a little while agone? It is time to insert that USB drive into your system. Now navigate to the location where VeraCrypt stored its Rescue Deejay in the previous step. Use vii-zip (or another Nada program) to extract the files in the VeraCrypt Rescue Disk.zip file directly to the root of the USB drive. Once that is done, click Side by side and so VeraCrypt can cheque your work.
  8. Assuming all went well, you should now see the Wizard's Rescue Deejay Verified window. Remove the USB drive from the calculator and click Side by side.
  9. The Magician displays the Wipe Mode window. For any normal uses, you don't need to worry virtually this. Make certain the Wipe Style is fix to None (fastest) and click Next to continue.
  10. We are getting there. The Sorcerer now displays the Organisation Encryption Pretest window. This is where VeraCrypt checks to make sure that the encryption process will actually work, rather than assuming it will work and trashing your arrangement if it doesn't. The image beneath explains what will happen in detail. Click Test to come across how it goes. Notation that VeraCrypt will probably ask you to impress some more warnings and emergency procedures and the similar before it really does the test, so be fix for that.
  11. Assuming everything went well, you should meet the following window one time you have successfully restarted your estimator and passed the system encryption pretest.

  1. VeraCrypt recommends you to make backup copies of all your important files before you encrypt your system. This will allow yous to recover if something desperate like a ability failure or system crash occurs in the middle of the encryption process. Once you are done with that, take a deep jiff and click Encrypt. VeraCrypt will display more documentation it wants you lot to print if possible, covering when to use the VeraCrypt Rescue Disk afterwards the encryption process is complete, so volition finally begin the actual encryption process. You'll be able to monitor the progress of the encryption, which is a dainty touch.

  1. Once the encryption is done, you lot will need to enter your VeraCrypt password every time you outset the computer.

What We Learned

Encrypting important information is one of the best things you can do to protect yourself from everyone who is trying and then hard to get their hands on your personal information.

In this guide we covered techniques that Windows ten users can utilize to encrypt individual files, folders, and entire drives on their Windows systems. While no 1 tin can guarantee that your data will be 100% condom against any and all attacks, the simple act of encrypting your most of import data can make a big deviation.

Masthead credit: eamesBot