Windows backs the recovery key up automatically to a Microsoft account, and corporate estates escrow it centrally — so most people who believe they have no key turn out to have one saved for them. Start with one question: work machine, or personal?
BitLocker binds the volume to the machine around it. Alter something in that machine’s chain of trust — the TPM, the firmware, the boot order — and it stops and asks you to demonstrate the drive is yours.
BitLocker asks for a 48-digit recovery key when something changes that it did not expect — a firmware update, a hardware change, a motherboard replacement, sometimes nothing obvious at all. That prompt is not a fault and it does not mean anything has broken.
In the overwhelming majority of cases the key exists somewhere and has simply never been retrieved. Four places account for nearly all of them, and none costs anything to check.
If none of them has it, the honest position is that the data is unrecoverable. AES with a correctly generated key has no shortcut, no back door and no vendor override. Anyone claiming to break BitLocker is attempting a dictionary attack on a weak password or is not being straight with you.
Your Microsoft account. Go to account.microsoft.com/devices/recoverykey. Consumer machines with device encryption store the key here automatically during setup, and most people have no idea.
Azure AD or Intune. On any work machine, ask IT. This resolves more BitLocker enquiries than every technical measure combined, and it works even if you have left the organisation.
A saved file or printout. BitLocker offers to save or print the key when enabling it. That file is frequently sitting in Documents or on a USB stick in a drawer.
Active Directory. Older domain-joined estates store recovery information in AD rather than Azure. Your administrator can retrieve it.
Usually a firmware or hardware change that BitLocker treats as suspicious. Nothing has failed. Enter the key and it will stop asking.
No, and nor can anyone. Without the key or password there is no route in, which is the entire point of it.
Then it is ordinary recovery work from £300 +VAT. The drive is imaged first, then the key applied to the image.
Then we cannot help, and that is correct rather than obstructive. The key belongs to whoever owns the machine.