Snapdragon X laptops are known for long battery life, and many of them are sold as Copilot+ PCs. Out of the box they are reasonably well protected: Windows Hello sign-in and, often, encryption that is already on. Still, a password that has to be entered before Windows even starts is worth adding.
Here is what protects an ARM laptop by default, where the gaps are and how to add a pre-boot password.
What Windows on ARM laptops are
Snapdragon X processors use the ARM architecture rather than the x86/x64 architecture of familiar Intel and AMD chips. They run a 64-bit version of Windows 11 built for ARM. Everyday apps run either as native ARM versions or through built-in emulation.
Software that works at the boot level is different: emulation doesn’t help there, and it has to be built for ARM. So when you pick boot protection for such a laptop, make sure it supports Windows on ARM.
Copilot+ PC is Microsoft’s label for laptops with a dedicated AI processor (NPU). The first ones were Snapdragon X models, but Intel and AMD laptops can carry the label too. This article is about the ARM models.
What protection you already have
Windows Hello
Sign-in with your face, fingerprint or a PIN. It’s convenient and safer than a short password, but it only protects the Windows sign-in.
Device encryption and BitLocker
On new laptops, encryption of the system drive is often on by default: on Windows Home it’s called Device encryption, on Pro it’s BitLocker. Often, but not always: it depends on the Windows edition and on how the laptop was set up the first time.
Check it yourself:
- Open Settings > Privacy & security > Device encryption. On Pro you can also find BitLocker settings by searching the Start menu.
- Make sure encryption is turned on.
- Find your recovery key. It is usually saved to your Microsoft account. Keep a copy somewhere other than the laptop: without the key you can lose access to your data after a firmware update or a hardware change.
Secure Boot
Secure Boot is on by default: the firmware only starts boot loaders with a trusted signature. That protects the boot chain from tampering, so leave it on.
Why a password before Windows starts still helps
Windows Hello and the Windows password protect the sign-in, not the startup. With the usual Device encryption setup, the drive unlocks automatically when you turn the laptop on, and Windows boots to the lock screen. Anyone who picks up the laptop gets a running system, and everything depends on the sign-in screen.
A pre-boot password adds another barrier:
- without it Windows doesn’t start at all, so a stranger never even sees the sign-in screen;
- the password is still asked if the drive is moved to another computer or the program is uninstalled;
- in stealth mode no password prompt is shown, and the laptop looks frozen;
- a UEFI password isn’t available on every ARM model, while a pre-boot password is set from Windows and doesn’t depend on what the firmware menu offers.

Disk Password Protection 5.6 on an ARM laptop
Disk Password Protection sets a password on boot, before the operating system starts. Since version 5.6 it works on Snapdragon laptops:
- 64-bit Windows on ARM is supported;
- the UEFI modules are signed with Microsoft UEFI CA 2023, the certificate new computers are built around, so Secure Boot stays on;
- the boot protection module on UEFI systems is compatible with BitLocker, so you don’t have to turn Device encryption off;
- the password is checked with PBKDF2, which makes brute-force guessing much slower.
One important caveat. On some laptops, especially Secured-core PCs (many Copilot+ PCs are), the UEFI firmware by default doesn’t trust third-party modules signed with the Microsoft UEFI CA. In that case, before installing boot protection, enable the UEFI setting that allows the Microsoft third-party UEFI CA (its name depends on the manufacturer). Secure Boot stays on. If there is no such setting, check with the manufacturer. Either way, test on your own device first and keep your BitLocker recovery key at hand: if Device encryption is on, changing UEFI settings can trigger the BitLocker recovery screen.
See the Disk Password Protection 5.6 release notes for details.
How to set a pre-boot password
- Download Disk Password Protection and install it.
- Before making changes, make sure your BitLocker recovery key is saved and you can reach it.
- In the main window, find the system disk and choose “Install boot protection…”.
- Enter the password twice. Add a “Password hint” if you like, and check “Enable hidden protection mode” if you don’t want a password screen to appear.
- Click “OK” and restart the laptop. A password prompt now appears before Windows starts.

You’ll type this password on the laptop keyboard, so a long passphrase of several words works better than a short string of symbols. For a detailed walkthrough, see how to set a password on computer startup, and for all options, the boot protection page.
UEFI settings on ARM laptops
The UEFI setup menu on ARM laptops varies a lot between models, and it may offer fewer options than you’re used to on other PCs. On some models you can set a UEFI password and disable USB boot; on others these options don’t exist. Check the manufacturer’s documentation.
If the options are there, use them:
- set a UEFI administrator password;
- disable booting from USB and external drives;
- keep Secure Boot on.
This matters because booting from a USB stick skips the Disk Password Protection prompt. If you can’t disable USB boot, Device encryption still protects the data: it can’t be read from a USB stick without the key.
Hiding partitions
Besides the boot password, Disk Password Protection can hide partitions. It removes the partition’s entry from the partition table: Windows and other programs don’t see it, and Disk Management shows unallocated space in its place. The partition stays hidden on other computers and after the program is uninstalled. To bring it back, you need Disk Password Protection and the password.
On an ARM laptop all data usually lives on the system partition C:, and the partition with the running Windows can’t be hidden. The feature is useful if you have a separate data partition or an external drive. Read more in how to hide a partition in Windows.
What Disk Password Protection doesn’t do
- It doesn’t encrypt data. Data on a hidden partition can be found with data recovery tools. To encrypt data on an ARM laptop, use the built-in Device encryption or BitLocker.
- It doesn’t stop booting from USB. That’s why a UEFI password and disabled USB boot matter, where your model allows them.
- There is no master password. Pick a password you won’t forget and add a hint.
A solid setup for an ARM laptop: Device encryption or BitLocker with a saved recovery key, Windows Hello for sign-in, a pre-boot password from Disk Password Protection and, where possible, a UEFI password with USB boot disabled.
FAQ
Can I set a startup password on a Snapdragon laptop?
Yes. Some models offer a UEFI password. In addition, Disk Password Protection 5.6 supports 64-bit Windows on ARM and asks for a password before Windows starts.
Is encryption on by default on Copilot+ PCs?
Often, but not always. Check Settings > Privacy & security > Device encryption and save your recovery key.
Do I need to disable Secure Boot for Disk Password Protection?
No. The UEFI modules in version 5.6 are signed with Microsoft UEFI CA 2023 and work with Secure Boot on. On some models, especially Secured-core PCs, you first have to allow the Microsoft third-party UEFI CA in the UEFI settings. Secure Boot stays on.
Does Disk Password Protection work with BitLocker?
Yes. In version 5.6 the boot protection module on UEFI systems is compatible with BitLocker. Encryption protects the data, and the pre-boot password keeps the system from starting.
Does a pre-boot password replace encryption?
No. Disk Password Protection doesn’t encrypt data, so keep Device encryption or BitLocker turned on.