Enable and Verify Full‑Disk Encryption on Android
9 min read
Step‑by‑step guide to turn on device‑wide encryption on Android, verify its status, and troubleshoot common issues.
September 27, 2026 20:30
Before you start
Full‑disk encryption (FDE) protects all data stored on your phone by converting it into unreadable code until you unlock the device. Enabling it is safe, but you should be aware of a few prerequisites:
- Battery level: Keep the device charged to at least 50 % or connect it to a charger. The process can take several minutes and will reboot the phone.
- Backup your data: Although encryption itself does not erase data, a power loss during the operation could corrupt the storage. Use
adb backup or a cloud backup service.
- Screen lock set: Android requires a PIN, password, or pattern before encryption can be turned on.
- Android version: Encryption is built‑in from Android 6.0 (Marshmallow) onward. Older versions may use “encrypt SD card” instead of full‑disk encryption.
If your device is already running Android 10 or newer, it most likely uses file‑based encryption (FBE), which is always on. The steps below still apply for checking the encryption state and for devices that still rely on the older FDE model.
Understanding Android full‑disk encryption
Android’s encryption works by generating a master key that is itself encrypted with a key derived from your screen‑lock credential. When you power on the phone, the system asks for the lock credential, decrypts the master key, and then unlocks the entire data partition.
Why does this matter?
- If the phone is lost or stolen, an attacker cannot read the stored files without the lock credential.
- Some corporate policies require encryption before a device can enroll in a work profile or MDM solution.
- Encryption also protects app data, messages, photos, and any files you store on internal storage.
Check the current encryption status
Before you attempt to enable encryption, confirm whether it is already active. There are two quick ways: through the UI and via ADB.
- Using Settings (UI)
- Open
Settings → Security (or Security & privacy on some OEM skins).
- Look for an entry named Encryption, Encrypt phone, or Encryption status.
- If it reads Encrypted or Device encryption is on, you are already protected.
- Using ADB (command line)
Enable encryption (if it is not already on)
If the checks above show unencrypted, follow these steps. The exact wording may differ slightly between manufacturers, but the workflow is the same.
- Set a strong screen lock
- Navigate to
Settings → Security → Screen lock.
- Choose
PIN, Password, or Pattern. A PIN with at least 6 digits or a complex password is recommended.
- Locate the encryption option
- Go to
Settings → Security → Encryption & credentials (or Encrypt phone on older skins).
- If you see a button labeled Encrypt phone, tap it.
- Start the encryption process
- Read any warning dialogs – they usually remind you to keep the device plugged in.
- Tap Encrypt or Start encryption.
- The phone will reboot and display a progress bar. Do not interrupt the process.
- Wait for completion
- Depending on storage size and hardware, this can take 5–30 minutes.
- When finished, the device boots to the lock screen as usual.
After the reboot, the system automatically treats the data partition as encrypted. No further user action is required.
Verify encryption after setup
It is good practice to confirm that encryption succeeded, especially on devices that may silently skip the step due to hardware limitations.
- Repeat the UI check from the previous section. The status should now read Encrypted.
- Run the ADB command again:
adb shell getprop ro.crypto.state
The output must be encrypted.
- Optionally, test the lock‑screen behavior:
- Power off the device, then power it back on.
- The first screen you see should ask for your PIN/password before any apps load. This is the decryption prompt.
Troubleshooting common issues
Encryption can fail for several reasons. Below are the most frequent problems and how to address them.
1. “Encryption failed” or “Device not supported” message
- Insufficient storage space: Android needs free space (usually ~10 % of total storage) to create the encrypted container. Delete unused apps, media, or move files to an SD card.
- Device is already encrypted with file‑based encryption: Newer Android versions report
ro.crypto.type=file. In this case, you cannot enable classic FDE, but your data is already protected.
- Hardware limitation: Some low‑end SoCs lack the necessary cryptographic support. The Settings screen will gray out the encryption option.
2. Phone reboots repeatedly after starting encryption
- Boot into Recovery mode (usually Power + Volume Down) and select Wipe cache partition. Then reboot and try again.
- If the problem persists, consider performing a factory reset first (after backing up). A clean slate often resolves hidden filesystem errors.
3. ADB still reports unencrypted after the UI says “Encrypted”
4. Unable to set a screen lock because the option is missing
- Some devices shipped with a default “None” lock and hide the setting until a password is set via
Settings > Security > Set up screen lock. Choose a PIN or password first, then return to the encryption screen.
When encryption isn’t possible
Older phones (pre‑Android 6) or very cheap devices may not support full‑disk encryption. In those cases you have two practical alternatives:
- Use a third‑party app that encrypts individual files or folders (e.g., Solid Explorer or Cryptomator). This protects the most sensitive data without needing system‑level encryption.
- Upgrade the device’s OS if a newer Android version is available via the manufacturer’s OTA or through a custom ROM. Newer releases bring FBE, which is always on.
Remember that encryption only protects data at rest. For comprehensive security you should also enable a lock screen, keep the OS updated, and consider a VPN for network‑level privacy.
Summary of the workflow
- Back up your data and ensure the battery is ≥50 %.
- Set a strong screen lock (PIN, password, or pattern).
- Check the current encryption state via Settings or
adb getprop ro.crypto.state.
- If unencrypted, start the encryption process from Settings → Security → Encrypt phone.
- Wait for the device to finish rebooting and verify the status again.
- Troubleshoot any errors using the guidance above.
Following these steps guarantees that the data on your Android device remains unreadable to anyone who does not know your lock credential, giving you peace of mind whether the phone is misplaced, sold, or simply left unattended.