Linsey Knerl | September 15, 2026

How to Encrypt Files: A Guide to Protecting Your Data

How to Encrypt a File

Encryption converts readable data into an encoded form that cannot be understood without the appropriate key or credentials. It can help protect sensitive files if a device is lost, stolen, shared with someone else, or accessed without authorization.

You can encrypt files in several ways depending on what you are trying to protect. Windows and macOS include built-in encryption features for devices, drives, files, and folders. Mobile devices also use encryption to protect stored data.

The right approach depends on whether you need to protect an individual file, an entire drive, a removable storage device, or data while it is being transferred.

Why should you encrypt files?

Encryption can help protect information such as:

  • Financial documents
  • Tax records
  • Personal identification documents
  • Business records
  • Customer information
  • Password and credential files
  • Photos and videos
  • Intellectual property
  • Confidential work documents

Encryption is particularly useful if a laptop, USB drive, or external hard drive is lost or stolen. Without encryption, someone who gains physical access to the storage may be able to access the files. Drive encryption helps prevent offline access to the data.

Encryption is also different from simply setting a password on your computer. A device password helps control who can sign in, while encryption protects the underlying data if someone attempts to bypass the normal sign-in process.

File encryption vs. drive encryption

Before choosing an encryption method, decide what you actually need to protect.

File or folder encryption

File-level encryption protects selected files or folders. This can be useful when you need to protect specific information while leaving other files accessible.

Windows supports Encrypting File System (EFS), which provides cryptographic protection for individual files and directories on supported NTFS volumes.

Drive encryption

Drive encryption protects an entire storage volume. It is often the better choice for a laptop because it can protect the operating system, applications, and stored files if the device is lost or stolen.

Windows BitLocker, for example, encrypts drives and is designed to prevent someone from reading the contents by accessing the storage outside the normal Windows environment.

Device encryption

Some modern devices can use automatic or simplified device encryption. Windows provides both Device Encryption and BitLocker Drive Encryption, with availability and management options depending on the Windows edition and device configuration.

How to encrypt files on Windows

Windows provides several ways to protect data, depending on your version and edition.

Option 1: Encrypt individual files or folders with EFS

On supported Windows editions, you can use Encrypting File System to encrypt individual files or folders.

  1. Right-click the file or folder.
  2. Select Properties.
  3. Select Advanced.
  4. Select Encrypt contents to secure data.
  5. Select OK.
  6. Select Apply, then follow the prompts.

Microsoft notes that file encryption is not available in Windows Home edition.

EFS uses certificates and encryption keys associated with users, so it is important to understand how encrypted files will be backed up and recovered before relying on EFS for important information.

Option 2: Encrypt the entire Windows drive with BitLocker

For laptops and other PCs containing sensitive information, whole-drive encryption can provide broader protection.

BitLocker can encrypt operating-system drives, fixed data drives, and removable drives. On supported hardware, BitLocker can work with a Trusted Platform Module (TPM) to help protect the device against offline attacks and tampering.

To check BitLocker settings in Windows:

  1. Open Settings.
  2. Search for BitLocker.
  3. Open the BitLocker or device-encryption settings available for your PC.
  4. Follow the prompts to enable encryption if it is not already enabled.

Important: Save your BitLocker recovery key somewhere secure. Microsoft warns that you may be unable to access an encrypted drive if BitLocker requires the recovery key and you do not have it.

What about Windows Home?

Windows Home does not support EFS, but some Windows devices can support Device Encryption depending on the hardware and configuration. Check your Windows security settings to see whether the feature is available on your PC.

If you need to protect individual files rather than the entire device, consider whether your application or cloud-storage service provides an appropriate encryption option instead of automatically installing third-party encryption software.

How to encrypt files on a Mac

Mac computers provide several built-in options for protecting data.

Use FileVault to encrypt your Mac

FileVault provides full-volume encryption for Mac storage.

To turn on FileVault:

  1. Open System Settings.
  2. Select Privacy & Security.
  3. Select FileVault.
  4. Follow the instructions to turn on encryption.

Apple describes FileVault as a way to protect the contents of Mac volumes using strong encryption. On supported Macs, hardware security features also work with the encryption system.

For most Mac users, FileVault is the appropriate starting point for protecting the data stored on the internal drive.

Create an encrypted disk image

If you only need to protect a collection of files, macOS Disk Utility can create an encrypted disk image.

  1. Open Disk Utility.
  2. Choose File > New Image.
  3. Select the option for creating a new disk image.
  4. Configure the image size and location.
  5. Choose an encryption option when available.
  6. Create a password for the encrypted image.
  7. Save the disk image.

Apple specifically supports encrypted disk images for storing confidential documents and other files.

Encrypt an external drive on a Mac

Newer versions of macOS support encrypted APFS volumes. When formatting an external storage device in Disk Utility, APFS (Encrypted) is an available format on supported systems.

Be careful when formatting an external drive. Erasing or reformatting a drive can permanently delete the data stored on it. Always back up important files first.

Apple also notes that encrypted Mac OS Extended volumes will not be compatible with macOS 28 and later, so APFS is the better choice for new encrypted Mac storage intended for future compatibility.

How to encrypt files on Android

Modern Android devices use encryption to protect stored user data.

Android supports file-based encryption, which allows different storage areas to use different encryption keys. New devices launching with Android 10 and later are required to use file-based encryption.

For most Android users, the important step is to use a strong device lock, such as a sufficiently long PIN or password, and keep the device's operating system and security updates current.

If you need to protect a specific file or group of files separately, check whether the app or storage service you are using provides its own encryption or protected-storage feature.

How to encrypt files on an iPhone or iPad

Apple's Data Protection system encrypts user data when you set a device passcode.

To set or change your passcode:

  1. Open Settings.
  2. Select Face ID & Passcode or Touch ID & Passcode, depending on your device.
  3. Select Turn Passcode On or Change Passcode.
  4. Follow the instructions to create your passcode.

Apple states that setting a passcode turns on Data Protection, which encrypts iPhone data.

For most users, the combination of device encryption, a strong passcode, current software, and secure backups provides the foundation for protecting files stored on an iPhone or iPad.

How to encrypt a USB drive or external hard drive

Portable storage deserves special attention because it is easy to lose.

On Windows

BitLocker can encrypt removable drives through BitLocker To Go on supported Windows editions. This can protect the contents of a USB flash drive or external storage device if it is lost.

On Mac

Mac users can format supported external storage using an encrypted APFS format through Disk Utility.

Before encrypting or reformatting removable storage, make a backup of anything you need to keep.

How to encrypt a Word document

Microsoft Word includes password-based document encryption.

In the desktop version of Word:

  1. Open the document.
  2. Select File > Info.
  3. Select Protect Document.
  4. Select Encrypt with Password.
  5. Enter and confirm a password.
  6. Save the document.

Microsoft notes that Word cannot recover a forgotten document password in the normal process, so store the password securely. Word for the web also cannot password-encrypt a document.

Other Microsoft Office applications, including Excel and PowerPoint, provide similar password-protection options.

How to encrypt a PDF

PDF applications can provide password-based protection and encryption, but the exact steps depend on the software and version you use.

If you regularly exchange sensitive PDFs, check the application's current security settings and distinguish between:

  • A password required to open the document
  • Permissions that restrict editing or printing
  • Actual encryption protecting the document contents

A password that merely restricts editing is not necessarily the same as encrypting the contents of a file.

What about ZIP files?

ZIP archives can sometimes be password-protected, but support and encryption strength vary depending on the application and ZIP format being used.

If the information is particularly sensitive, do not assume that putting files into a ZIP archive automatically makes them secure. Use a current encryption method supported by a reputable application and verify what encryption standard it uses.

How to protect encrypted files

Encryption is powerful, but it does not eliminate every security risk. Keep these practices in mind.

Protect your encryption keys and passwords

Encryption works only if you can access the key or credentials required to decrypt the data.

Keep recovery keys and important passwords in a secure location. Do not store the only copy of an encryption key alongside the encrypted files.

Encrypt your backups

An encrypted laptop does not automatically mean that every copy of your data is encrypted.

If you copy sensitive files to an external drive, backup system, or cloud service, consider how that copy is protected.

Use strong authentication

Encryption and authentication work together.

Use a strong device passcode or password, enable multi-factor authentication where available, and avoid sharing credentials.

Keep software updated

Encryption protects data, but it does not prevent every attack against the applications or operating system that access that data.

Keep your operating system, browsers, security software, and other applications updated.

Be careful when sharing encrypted files

If you send an encrypted document to someone, protect the password or decryption key separately from the file whenever possible.

For example, avoid sending a sensitive document and its password in the same message.

Know what encryption protects

Encryption primarily protects data from unauthorized access to the encrypted storage or file.

It does not automatically protect a file after you unlock it and open it on a compromised computer. Malware, compromised accounts, or an attacker with access to an already-unlocked session can create different risks.

Do you need to encrypt every file?

Not necessarily.

For most people, device or drive encryption is a practical baseline because it can protect large amounts of stored data without requiring you to manually encrypt every individual file.

Individual file encryption becomes more useful when you need to protect a particularly sensitive document, share an encrypted file with another person, or create a protected collection of files.

A simple approach is:

What you need to protectConsider
Entire Windows PCDevice Encryption or BitLocker
Specific Windows filesEFS, where supported
Entire MacFileVault
Specific Mac filesEncrypted disk image
USB or external driveBitLocker To Go or encrypted APFS
Word documentWord's password encryption
iPhone or iPadDevice passcode and Data Protection
Android deviceDevice encryption and strong device lock
Cloud or backup copiesEncryption offered by the service or encryption before upload

Frequently asked questions

What is file encryption?

File encryption converts readable information into an encoded form that requires the appropriate key or credentials to decrypt. It helps prevent unauthorized people from reading the contents of the file.

Is encryption the same as password protection?

No. Password protection and encryption can work together, but they are not automatically the same thing. Some password-protection features control access or editing without providing the same type of encryption as a properly encrypted file or drive.

Is it better to encrypt individual files or the entire computer?

It depends on your needs. Full-device or full-drive encryption provides broad protection for stored data, while file-level encryption gives you more targeted control over specific files or folders.

What happens if I lose my encryption password?

Depending on the encryption technology, you may not be able to recover the data without a recovery key or another authorized recovery method. Microsoft's BitLocker guidance specifically emphasizes keeping a recovery key backed up.

Does encryption protect files in the cloud?

Encryption can protect cloud-stored data, but you need to understand where and when encryption occurs. Some services encrypt data during transmission and while stored, while others may offer additional end-to-end encryption options.

If you need strong control over highly sensitive information, consider encrypting the file before uploading it and securely managing the encryption key.

Keep your data protected

Encryption is one of the most effective ways to reduce the risk of unauthorized access to stored data. Instead of treating encryption as something you only need for highly technical situations, think of it as part of normal device and data security.

For most people, start with the basics: enable device or drive encryption, use a strong passcode or password, protect recovery keys, encrypt sensitive backups, and keep your software current.

When you need additional protection for individual files, use the encryption capabilities built into your operating system or trusted applications. The specific steps vary by device, but the goal is the same: make sensitive information unreadable to anyone who does not have permission to access it.

About the Author

Linsey Knerl is a contributing writer for HP Tech Takes. Linsey is a Midwest-based author, public speaker, and member of the ASJA. She has a passion for helping consumers and small business owners do more with their resources via the latest tech solutions.

Disclosure: