PC stuck on a blue "BitLocker recovery" screen saying "Enter the recovery key for this drive"? Here's where to find the key, why it happens and how to prevent it.
You switch on your laptop and instead of Windows you get a blue screen titled "BitLocker recovery" or "Enter the recovery key to get going again", asking you to "Enter the recovery key for this drive". It shows a Recovery key ID and a web address. Without the 48-digit key, you can't get past it.
Don't panic, and don't reinstall Windows. The key exists somewhere, and for most business devices your admin can find it in minutes. Here's where to look and why it happened.
Quick answer
For a work device, the key is usually stored in your organisation's Entra ID or Intune. Look it up at myaccount.microsoft.com under Devices, or ask your IT admin. For a personal device, sign in at aka.ms/myrecoverykey with your Microsoft account. Match the Key ID on screen to the right key.
Why This Happens
BitLocker encrypts your drive so a stolen laptop can't be read. It uses the PC's security chip (TPM) to check that nothing about the startup process has changed. If something has, it asks for the recovery key instead of unlocking automatically. Common triggers:
- BIOS or firmware updates, especially if BitLocker wasn't suspended first.
- Changes to Secure Boot or TPM settings in the BIOS.
- Hardware changes, such as a new motherboard, replaced drive or repaired laptop.
- Docking stations, USB drives or network boot options changing the boot order.
- Windows updates that change boot components.
- Too many wrong PIN attempts, if a startup PIN is in use.
An unexpected BitLocker prompt isn't usually a sign of hacking, but if the device has been out of your control or someone may have tampered with it, mention it to your IT team.
Step 1: Note the Key ID
The recovery screen shows a Recovery key ID (sometimes the first eight characters). Write it down. You may find several keys for different devices or drives, and the ID tells you which one to use.
Step 2: Find the Key
Work or school devices (Entra ID joined):
- On another device, go to myaccount.microsoft.com and sign in with your work account.
- Open Devices, find the computer and look for View BitLocker Keys.
- Match the Key ID and enter the 48-digit recovery key.
If you can't see the option, your organisation may have restricted self-service key recovery, so contact your admin.
Personal devices (signed in with a Microsoft account): go to aka.ms/myrecoverykey and sign in with the Microsoft account used on the PC. The key may also be saved in a different account, for example a family member's.
Other places to check:
- A printout or PDF saved when BitLocker was turned on.
- A USB drive labelled for recovery.
- Your password manager.
- An on-premises Active Directory, if your business uses one.
For Your Microsoft 365 Admin
- Entra admin centre: go to Devices > All devices, select the device and look for Recovery keys or BitLocker keys. Match the Key ID.
- Intune admin centre: go to Devices, find the device and look for Recovery keys under its monitoring options.
- Viewing keys requires a suitable role, such as Cloud Device Administrator, Helpdesk Administrator or Intune Administrator. Access is audited.
- Verify the user's identity before reading a key over the phone.
- After the key is used, rotate it. Intune supports BitLocker key rotation as a device action, provided rotation is enabled in your BitLocker policy.
Step 3: If the Same Screen Comes Back
If you get the prompt after every restart, something is still changing at boot:
- Remove USB drives and disconnect docking stations, then restart.
- Check the BIOS for a recently changed setting, such as Secure Boot, and set it back if you know what it was.
- Once in Windows, open an elevated PowerShell and run
Suspend-BitLocker -MountPoint "C:" -RebootCount 1, restart, and let Windows re-seal the protectors. Then check BitLocker resumes withGet-BitLockerVolume.
If You Can't Find the Key
Without the recovery key, the data on the drive can't be recovered. That's what encryption is for. The only option is to reset or reinstall Windows, losing local data. For a business device using OneDrive, SharePoint and Exchange Online, most work will be safe in the cloud, which is a strong argument for not storing anything important only on a laptop.
How to Stop It Happening Again
BitLocker surprises are painful when nobody knows where the key is. Prevent them by:
- Escrowing keys automatically. Manage BitLocker with Intune's endpoint security disk encryption policy, and require recovery information to be stored in Entra ID before encryption is enabled.
- Backing up existing keys. For devices encrypted before Intune management, an admin can back up the key to Entra ID. In PowerShell, find the recovery password protector with
(Get-BitLockerVolume -MountPoint "C:").KeyProtector, then runBackupToAAD-BitLockerKeyProtector -MountPoint "C:" -KeyProtectorIdwith that protector's ID. - Suspending BitLocker before BIOS updates. Manufacturer update tools often do this, but manual updates may not.
- Keeping data in the cloud, with Known Folder Move in OneDrive, so a lost key doesn't mean lost work.
- Reporting. Check Intune's encryption report regularly so you know every device is encrypted and its key is escrowed.
When to Call in Help
If a director's laptop is locked and nobody can find the key, call us. If the key isn't escrowed, there's no way round it, but we can recover as much as possible from Microsoft 365 and get the device working. Our managed IT service and Intune setup make sure every key is stored before it's needed, and our IT support team can help now. Get in touch.
Related Reading
Common questions
For a work device, check myaccount.microsoft.com under Devices or ask your IT admin, who can find it in Entra ID or Intune. For a personal PC, sign in at aka.ms/myrecoverykey with the Microsoft account used on the device.
Usually because something changed at startup, such as a BIOS or firmware update, a Secure Boot or TPM change, a hardware repair, or a dock or USB device changing the boot order.
No. Without the recovery key, the encrypted data can't be accessed. The only option is to reset or reinstall Windows, which erases local data.
Suspend BitLocker before the update with Suspend-BitLocker or manage-bde, then let it resume after restarting. If the prompt keeps appearing, check BIOS settings and remove docks or USB devices.
Want to talk about this?
Book a free 15-minute call and we'll discuss how this applies to your business.
Get IT tips in your inbox
Practical advice for small businesses. No spam.
