Microsoft has announced a new hardware-accelerated BitLocker encryption feature for Windows 11 and Windows Server, designed to address performance bottlenecks caused by traditional software-based encryption on high-speed NVMe drives. By offloading encryption and decryption tasks to dedicated cryptographic engines within modern CPUs or system-on-chip (SoC) processors, the new approach significantly reduces CPU overhead, improves storage performance, and enhances battery life for intensive workloads such as gaming and video editing. The updated BitLocker implementation also introduces hardware-protected keys and defaults to the robust XTS-AES-256 algorithm on supported hardware, with administrative tools updated to detect and report this mode.
Previously, Microsoft had forced software-based BitLocker encryption by default on new Windows 11 Pro installations, which could reduce SSD performance by up to 45% and negatively impact battery life. The new hardware-accelerated solution, first announced at Ignite 2025, is available in the latest Windows 11 (25H2) and Windows Server (2025 September Update) releases, but requires upcoming CPUs with built-in cryptography accelerators that are not yet widely available. This change is expected to nearly double storage performance in some scenarios and aligns with industry trends toward leveraging hardware-based security features for both performance and protection.

See real exploitation activity before you spend the cycle.
2 events from the most recent confirmed update back to the earliest known activity.
Microsoft announced a new hardware-accelerated BitLocker implementation for Windows 11 and Windows Server 2025 that offloads encryption work to dedicated cryptographic hardware on supported SoCs. The company said the change is intended to reduce the storage-performance penalties and CPU overhead of software-based BitLocker while improving battery life and key protection.
On supported devices, Microsoft said hardware-accelerated BitLocker is enabled by default beginning with the September 2025 Windows 11 24H2 and 25H2 updates. Initial support is tied to Intel vPro systems using future Core Ultra Series 3 processors, with broader platform support planned later.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See real exploitation activity behind this advisory so you can triage it against everything else in the queue.
2 references tracked. Mallory keeps watching after this page renders.
cybersecuritynews.com
Open sourcetomshardware.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.