---
title: How to disable Bitlocker via Group Policies
description: How to disable bitlocker via group policies
---

[Skip to content](https://support.horizondatasys.com/knowledge-base/how-to-disable-bitlocker-via-group-policies#main-content)

[Submit a Ticket](https://support.horizondatasys.com/knowledge-base/kb-tickets/new) [Support Portal](https://support.horizondatasys.com/tickets-view)

[![Horizon DataSys - Making It Simple](https://support.horizondatasys.com/hs-fs/hubfs/HorizonDataSys_logo-tagline.png?width=175&height=38&name=HorizonDataSys_logo-tagline.png)](https://horizondatasys.com/)

- [Tickets](https://support.horizondatasys.com/tickets-view)
- [Knowledgebase](https://support.horizondatasys.com/knowledge-base)
- [Login](https://support.horizondatasys.com/_hcms/mem/login)

Open main navigation

Close main navigation

- [Tickets](https://support.horizondatasys.com/tickets-view)
- [Knowledgebase](https://support.horizondatasys.com/knowledge-base)
- [Login](https://support.horizondatasys.com/_hcms/mem/login)
- [Submit a Ticket](https://support.horizondatasys.com/knowledge-base/kb-tickets/new)
- [Support Portal](https://support.horizondatasys.com/tickets-view)
- [Contact us](https://horizondatasys.com/contact/)

[Contact us](https://horizondatasys.com/contact/)

 How can we help you?

- There are no suggestions because the search field is empty.

1. [Horizon DataSys Knowledge Base](https://support.horizondatasys.com/knowledge-base)
2. [FAQs](https://support.horizondatasys.com/knowledge-base/faqs)

March 10, 2026

# How to disable Bitlocker via Group Policies

## Reboot Restore and RollBack cannot be installed on a drive with Bitlocker enabled. Here's how to disable Bitlocker prior to deploying.

### Step 1: Update the Group Policy (GPO)

First, you must ensure the policy is not actively forcing encryption or requiring specific protectors.

1. Open the **Group Policy Management Console (GPMC)**.
2. Create a new GPO (e.g., "BitLocker Deactivation Policy") and link it to the target **Organizational Unit (OU)**.
3. Navigate to:
   
   `Computer Configuration > Administrative Templates > Windows Components > BitLocker Drive Encryption > Fixed Data Drives` (and **Operating System Drives**).
4. Set **"Choose how BitLocker-protected drives can be recovered"** to **Disabled** or **Not Configured**.
5. Specifically, ensure any policy that says **"Enforce drive encryption type"** is set to **Disabled**.

### Step 2: Push a Decryption Script

Group Policy defines the "law," but it doesn't execute the "action" of decrypting a drive. You will need to deploy a startup script or use a management tool (like Intune or SCCM) to run a PowerShell command.

**The PowerShell Command:**

You can deploy a script that checks for encryption and disables it:

PowerShell

```
$BLV = Get-BitLockerVolumeforeach ($volume in $BLV) {    if ($volume.VolumeStatus -eq 'FullyEncrypted') {        Disable-BitLocker -MountPoint $volume.MountPoint    }}
```

### Step 3: Monitoring the Progress

Decryption is a resource-heavy process that can take hours depending on drive size and speed (HDD vs. SSD). You can monitor the status across the network using the following command in your management console:

| **Command** | **Purpose** |
| --- | --- |
| `manage-bde -status` | Checks the percentage of decryption completed. |
| `Get-BitLockerVolume` | Provides a detailed object-oriented view of encryption status in PowerShell. |

 

**Related articles:** 

[SysPrep for System Imaging Deployments](https://support.horizondatasys.com/knowledge-base/deployment-options-for-reboot-restore-enterprise-0)

[Deployment Options for Reboot Restore Enterprise](https://support.horizondatasys.com/knowledge-base/deployment-options-for-reboot-restore-enterprise)

- [News and Updates](https://support.horizondatasys.com/knowledge-base/news-and-updates)
- [Reboot Restore Enterprise & Standard](https://support.horizondatasys.com/knowledge-base/reboot-restore-enterprise-standard)
- [RollBack Rx Pro](https://support.horizondatasys.com/knowledge-base/rollback-rx-pro)
- [Endpoint Manager](https://support.horizondatasys.com/knowledge-base/endpoint-manager)
- [Troubleshooting](https://support.horizondatasys.com/knowledge-base/troubleshooting)
- [FAQs](https://support.horizondatasys.com/knowledge-base/faqs)

<http://www.facebook.com/HorizonDataSys> <http://twitter.com/horizondatasys> <https://www.linkedin.com/company/horizon-datasys-corporation> <https://www.youtube.com/user/HorizonDataSysCorp>

Copyright © 2025, Horizon DataSys Corporation