The full-volume encryption feature built into Windows, which encrypts the contents of a drive so the data is unreadable without the correct key. It normally binds the key to the machine's TPM so the volume unlocks only when the system boots in an expected state, with optional PIN, password, or USB key as an additional factor. Recovery keys can be escrowed centrally so an administrator can restore access to a locked volume.