Personal Data Encryption
Personal Data Encryption (PDE) is a security feature introduced in Windows 11 22H2 that provides file-based data encryption capabilities to Windows. PDE utilizes Windows Hello for Business to link data encryption keys with user credentials. When a user signs in to a device using Windows Hello for Business, decryption keys are released, and encrypted data is accessible to the user. When a user logs off, decryption keys are discarded and data is inaccessible, even if another user signs in to the device. PDE differs from BitLocker in that it encrypts files instead of whole volumes and disks. PDE occurs in addition to other encryption methods, such as BitLocker. To use PDE, the following prerequisites must be met: it must be using Windows 11, version 22H2 and later, and the devices must be Microsoft Entra joined. Domain-joined and Microsoft Entra Hybrid joined devices aren’t supported.
Users must sign in using Windows Hello for Business:
-
...