A blue screen asking for 48 digits is BitLocker doing its job rather than failing. The key is escrowed automatically far more often than people realise, so the first move is knowing where to look — and where the drive has failed as well, the order of work matters more than most people expect.
$ cdr triage /dev/sdb → Device: Dell XPS SSD · 512 GB → Status: BITLOCKER LOCKED — volume refuses to mount → Owner: verified · key supplied $ cdr engineer-working → Read-only image: taken · source untouched → BitLocker metadata: repaired → Unlock: key accepted $ cdr verify → ✓ documents — 41,900 files → ✓ mailbox — 1 PST rebuilt → ✓ data recovered — drive decrypted
In the overwhelming majority of cases the key exists and simply has not been looked for. Four places, worth checking now.
Said plainly because it is the honest position and because several firms will imply otherwise.
BitLocker uses AES with a 128 or 256-bit key. There is no back door, no master key, no vendor override and no computational shortcut. Brute force against a correctly generated key is not a matter of time or money; it is not achievable with any hardware that exists or is likely to.
So if the recovery key cannot be found and the password is not known, the data is unrecoverable. That is encryption doing exactly what it was chosen to do. Anybody claiming to break BitLocker is either going to attempt a dictionary attack on a weak user password, or is not being straight with you.
What we can do is establish whether the volume is actually BitLocked or merely unreadable, which is a distinction worth making — a great many drives assumed to be encrypted turn out to have an ordinary file system fault instead.
Before you conclude the key is gone. Ask your IT team even if you have left the organisation, and check the Microsoft account the machine was first set up with rather than the one you use now. These two account for most of the keys people believe are lost.
Where a BitLocked drive has also failed physically, both problems have to be solved and in a particular order. The drive is imaged first, exactly as any failing disk would be, producing a sector-level copy of the encrypted volume. Only then is the key applied, to the image rather than to the failing original.
That order matters, because attempting to unlock and mount a failing drive keeps it powered and working for far longer than imaging does. It also means a partial image can still yield a partial decryption, where an unlock attempt against a dying disk would simply fail.
You will need the key either way. Physical recovery does not bypass encryption and no honest laboratory will suggest it does.
Where the drive has failed and you hold the key, BitLocker work is £800 +VAT flat — a single figure rather than a range, because the decryption step is the same amount of work whatever the underlying fault turns out to be.
Where the key is genuinely lost, there is no charge, because there is no service to sell. The diagnostic establishes whether the volume is encrypted at all, and that costs nothing.
Usually a firmware or hardware change triggering recovery mode rather than a fault. Check account.microsoft.com/devices/recoverykey, or ask your IT team on a work machine. The key almost certainly exists.
No, and nor can anyone else. AES with a correctly generated key has no shortcut. Anybody claiming otherwise is attempting a dictionary attack on a weak password or misleading you.
Then this is ordinary recovery work. The drive is imaged first, then the key applied to the image. Turnaround and price are as any single-drive job.
Then we cannot help, and that is correct rather than obstructive. The key belongs to whoever owns the machine. We will not attempt to bypass encryption on a device the requester does not own.
Common on modern Windows, which enables device encryption during setup on many machines. The key was saved to the Microsoft account used at that time, which may not be the one you use now.
Different implementation, same position. Apple's FileVault is equally unbreakable without the password or recovery key, and equally recoverable with one.
A free diagnostic, a quick ownership check, and your encrypted drive opened and handed back decrypted — a failing disk included. Get in touch and we take it from there.