The fastest way to password-protect a flash drive depends on your operating system
Windows 11 and 10 include built-in encryption through BitLocker To Go, which locks an entire drive behind a password. macOS has Disk Utility, which encrypts the drive the same way. If you use Linux, LUKS (Linux Unified Key Setup) is the standard tool. All three are free and come with your operating system — you do not need to buy or download anything.
The trade-off is that encrypted drives are slower to open and slower to read from than unencrypted ones, though the difference is usually small on modern computers. Once you set a password, you cannot recover it if you forget it — the drive becomes permanently locked. Write your password down somewhere safe, or use a password manager you trust.
If you want to encrypt only certain files rather than the whole drive, or if you need the drive to work on both Windows and Mac without extra setup, there are other options. Those take more steps but give you more control over what gets locked.
Key Takeaways
- Windows BitLocker To Go and macOS Disk Utility encrypt the entire drive with a password and come free with your operating system.
- Encrypted drives are slightly slower to use but prevent anyone without the password from reading any file on them.
- If you forget the password, the drive is permanently locked — there is no recovery option.
- Third-party tools like VeraCrypt work on Windows, Mac, and Linux, and let you encrypt just part of a drive if you want.
- Some flash drives come with built-in encryption software, which you can check by looking at the manufacturer's website or the drive itself.
How to encrypt a flash drive on Windows using BitLocker To Go
BitLocker To Go is built into Windows Pro, Enterprise, and Education editions. If you have Windows Home, you will need to use a different tool — see the section on third-party options below.
Plug in your flash drive. Right-click it in File Explorer and look for "Turn on BitLocker". If you do not see that option, your Windows version does not include BitLocker. Click it, and Windows will ask you to create a password. Use something you can remember but that others cannot guess — a mix of uppercase, lowercase, numbers, and symbols is stronger. Windows will then encrypt the drive, which can take several minutes to an hour depending on the drive's size. You can use the drive while this happens, but it will be slower.
Once encryption is done, every time you plug in the drive on any computer, you will be asked for the password before the drive shows up in File Explorer. On a Windows computer, you can choose to have Windows remember the password for that specific machine, so you do not have to type it every time. On a Mac or Linux computer, you will need third-party software to read the drive at all.
How to encrypt a flash drive on macOS using Disk Utility
Disk Utility is the Mac equivalent of BitLocker. Plug in your flash drive, open Disk Utility (search for it in Spotlight), and select the drive from the list on the left. Click the "Erase" button at the top.
A dialog will appear asking what format you want. Choose "APFS Encrypted" if the drive will only be used on Macs, or "ExFAT Encrypted" if you need to use it on Windows too. ExFAT is slower and older, but Windows recognizes it without extra software. Type a name for the drive and a password, then click "Erase". This will delete everything on the drive, so back up any files first.
Once done, the drive will ask for the password every time you plug it in on any Mac. On Windows, an encrypted ExFAT drive will prompt for the password, but you may need to download additional software to unlock it — check the drive manufacturer's website to see if they provide a tool.
Third-party tools that work across Windows, Mac, and Linux
VeraCrypt is free, open-source, and works on all three operating systems. It lets you create an encrypted container — a single locked file that holds other files inside it — or encrypt the entire drive. Download it from veracrypt.fr, install it, and run the program. Click "Create Volume" and choose whether you want to encrypt the whole drive or just create a container.
For a full-drive encryption, VeraCrypt will walk you through creating a password and choosing an encryption method. The process is slower than BitLocker or Disk Utility and more technical, but it gives you more options. For a container, you choose a size, set a password, and then mount it like a folder — files inside are encrypted, but the rest of the drive is not.
7-Zip is another free option if you only want to encrypt specific files rather than the whole drive. Compress the files you want to protect into a 7z archive, and 7-Zip will ask for a password during compression. The downside is that you have to decompress the files every time you want to use them, and you cannot edit them directly on the drive.
Flash drives with built-in encryption
Some manufacturers, including Kingston, SanDisk, and Corsair, sell flash drives with hardware encryption built in. These drives have a small keypad or button on the side, and you enter a PIN to unlock them. The advantage is that they work on any computer without installing software — the drive itself handles the unlocking.
Check the product page on the manufacturer's website to see if your drive has this feature. If it does, the drive usually comes with a setup tool to create your PIN. Hardware-encrypted drives are more expensive than regular ones, but they are simpler to use if you move the drive between many different computers.
What happens if you forget the password
There is no way to recover a password for an encrypted drive. BitLocker, Disk Utility, VeraCrypt, and hardware-encrypted drives all use encryption strong enough that even the manufacturer cannot break it. If you forget the password, the drive is permanently locked and unreadable.
The only exception is if you saved a recovery key when you first encrypted the drive. BitLocker offers this option — it generates a long string of numbers that can unlock the drive if you forget the password. Write this down or save it in a password manager, separate from the drive itself. Disk Utility and VeraCrypt do not offer recovery keys, so there is no backup if you forget.
Performance and compatibility notes
Encrypted drives are noticeably slower on older computers, especially when first opening or copying large files. On modern machines from the last five years, the slowdown is usually small enough that you will not notice it during normal use. If speed is critical, test the drive on your specific computer before relying on it.
An encrypted drive formatted for Windows will not open on a Mac without extra software, and vice versa. If you need to use the same drive on both systems, choose ExFAT as the format and use VeraCrypt or a third-party tool that both systems support. ExFAT is slower than NTFS or APFS, but it works on both.
Frequently Asked Questions
Can I encrypt just some files on a flash drive, not the whole thing?
Yes. Use VeraCrypt to create an encrypted container, or use 7-Zip to compress and password-protect individual files. Both leave the rest of the drive unencrypted. BitLocker and Disk Utility encrypt the entire drive, so you cannot choose which files to lock.
What if I need to use an encrypted drive on a computer that does not have the encryption software?
BitLocker-encrypted drives will prompt for a password on any Windows computer, but will not open on Mac or Linux without third-party software. Disk Utility encrypted drives work on any Mac but need software on Windows. VeraCrypt works on all three systems. If you need maximum compatibility, use VeraCrypt or a hardware-encrypted drive.
Is it safe to leave the password saved on my computer?
BitLocker lets you save the password for a specific computer, which is safe if your computer itself is password-protected. If someone gains access to your computer, they can use the saved password to unlock the drive. If your computer is shared or at risk of theft, do not save the password.
How long does encryption take?
BitLocker can take 30 minutes to several hours depending on drive size and computer speed. Disk Utility is faster, usually 5 to 15 minutes. VeraCrypt takes similar time to BitLocker. You can use the drive while encryption is happening, but it will be slower. Hardware-encrypted drives do not need encryption time — the protection is built in.
Can I remove encryption from a drive later?
Yes, but you need the password. In BitLocker, right-click the drive and choose "Turn off BitLocker". In Disk Utility, erase the drive and choose an unencrypted format. In VeraCrypt, delete the encrypted container or dismount the encrypted volume. Removing encryption erases the drive, so back up your files first.