Call us — 01223 655015
Mon–Fri · 9am–5:30pm · No fix, no fee
Start a free diagnostic →
BitLocker · explained

You probably have a key. You just did not save it.

Windows backs the recovery key up automatically to a Microsoft account, and corporate estates escrow it centrally — so most people who believe they have no key turn out to have one saved for them. Start with one question: work machine, or personal?

Why it triggers
Where the key is stored
Minutes, if you have the key
// the short version

Nothing is broken. It wants proof.

BitLocker binds the volume to the machine around it. Alter something in that machine’s chain of trust — the TPM, the firmware, the boot order — and it stops and asks you to demonstrate the drive is yours.

48
Digits in the key
TPM
Usually the trigger
Minutes
With the key
None
Ways around it
×Nobody can bypass BitLocker without the key or password — and any service claiming otherwise is not telling you the truth. That includes us. Before assuming the key is lost, check every location listed below; it is recorded automatically far more often than people expect.
// the key almost always exists

It has not been lost. It has not been looked for.

BitLocker asks for a 48-digit recovery key when something changes that it did not expect — a firmware update, a hardware change, a motherboard replacement, sometimes nothing obvious at all. That prompt is not a fault and it does not mean anything has broken.

In the overwhelming majority of cases the key exists somewhere and has simply never been retrieved. Four places account for nearly all of them, and none costs anything to check.

If none of them has it, the honest position is that the data is unrecoverable. AES with a correctly generated key has no shortcut, no back door and no vendor override. Anyone claiming to break BitLocker is attempting a dictionary attack on a weak password or is not being straight with you.

// where to look

Four places, in this order.

Your Microsoft account. Go to account.microsoft.com/devices/recoverykey. Consumer machines with device encryption store the key here automatically during setup, and most people have no idea.

Azure AD or Intune. On any work machine, ask IT. This resolves more BitLocker enquiries than every technical measure combined, and it works even if you have left the organisation.

A saved file or printout. BitLocker offers to save or print the key when enabling it. That file is frequently sitting in Documents or on a USB stick in a drawer.

Active Directory. Older domain-joined estates store recovery information in AD rather than Azure. Your administrator can retrieve it.

// questions

Answered.

Usually a firmware or hardware change that BitLocker treats as suspicious. Nothing has failed. Enter the key and it will stop asking.

No, and nor can anyone. Without the key or password there is no route in, which is the entire point of it.

Then it is ordinary recovery work from £300 +VAT. The drive is imaged first, then the key applied to the image.

Then we cannot help, and that is correct rather than obstructive. The key belongs to whoever owns the machine.