The Manage-bde.exe tool is used to manage BitLocker from an elevated command prompt or from a remote computer. It can be used to view disk status, enable and disable encryption, and manage recovery keys.
When BitLocker is enabled on a drive, the system adds security mechanisms such as TPM, an external key, or a numeric password. The recovery key is stored in a location specified by the user, such as a separate drive or flash drive. This password must be kept in a safe place, as it will be required to access the encrypted partition in case of boot or hardware verification problems. After creating the recovery key and external key, the computer must be restarted to pass the hardware test. If the verification is successful, the process of encrypting the disk contents begins.
If necessary, BitLocker can be disabled by running the decryption process. At this point, the data becomes accessible again without protection.
The Manage-bde tool also allows you to set startup keys and recovery keys that can be used on multiple computers at once. This is convenient for users who work on multiple devices, or for lab and corporate environments where several people use different computers. Keep in mind that compromising one shared key will require replacing the keys on all devices where it was used.
For detailed information about the capabilities and parameters of Manage-bde.exe, you can call up the built-in help via the command line.