BitLocker Recovery Key Required After a Windows Update: How to Find It and Stop the Loop

Reviewed by IT Cares technicians · Updated October 1, 2026

Laptop showing a blue BitLocker recovery screen asking for a recovery key after a Windows update
BitLocker recovery screen after an update: your data is intact, you need the 48-digit key that matches the Key ID.

Quick fix (4 steps)

  1. Photograph the blue screen and note the first 8 characters of the Key ID. Do not reset or reinstall Windows.
  2. On a phone or another PC, open aka.ms/myrecoverykey (work PC: ask your IT department) and find the key with the same ID. See where to find it.
  3. Type the 48 digits on the blue screen. Keyboard dead? Use a wired USB keyboard or F1 to F10 as digits. See keyboard fixes.
  4. In Windows, run manage-bde -protectors -disable C:, restart, then manage-bde -protectors -enable C: to stop the prompt. See stop the loop.

Why BitLocker suddenly asks for a recovery key after a Windows update

BitLocker asks for the recovery key when it can no longer prove that the computer started in the same trusted state as when the drive was locked. A Windows update, a BIOS or firmware update, a Secure Boot change or a hardware change can alter that state, so BitLocker refuses to unlock automatically and falls back to the 48-digit key. It is a safety feature doing its job, not a sign that your files are gone.

Here is what happens behind the scenes. When BitLocker protects your drive, it normally seals the encryption key inside the TPM, a small security chip on the motherboard (or a firmware TPM built into the processor). At every start, the TPM compares measurements of the boot process, such as the firmware settings, the Secure Boot configuration and the boot manager, against the values recorded earlier. If everything matches, the TPM releases the key and Windows starts without any prompt. If something differs, the TPM keeps the key locked, and the blue recovery screen appears.

That design is exactly what protects a stolen laptop. A thief who removes the drive, boots from a USB stick or tampers with the firmware changes those measurements, and the data stays encrypted. The side effect is that legitimate changes can look the same as tampering. Updates that touch the boot chain are the most common legitimate cause, and that is why the prompt so often shows up right after a restart that installed something.

If you are looking at the blue screen right now, do not panic and do not keep forcing restarts. Your data is intact on the drive. You need one thing: the recovery key that matches the Key ID displayed on screen. The next sections show where to find it, how to enter it, and how to stop the prompt from coming back. If you are in a hurry, the quick-fix box at the top has the fastest route.

What can trigger the recovery screen (and how likely each one is)

The most common triggers are a BIOS or UEFI firmware update, a change to Secure Boot keys or settings, a TPM change, a boot order or boot mode change, a hardware swap, and, less often, a Windows servicing update that modifies the boot manager. Most monthly cumulative updates do not trigger the prompt at all. The prompt appears when the update touches something the TPM measures.

TriggerWhy BitLocker reactsHow commonPrevent it by
BIOS or UEFI firmware updateFirmware measurements stored in the TPM changeVery commonSuspending BitLocker before a manual flash
Secure Boot database or key updateSecure Boot state is part of what the TPM measuresCommon during certificate rolloutsHaving the key ready before updating firmware or Secure Boot settings
Windows feature update (for example a new annual release)Boot components are replaced; Windows usually suspends protection by itself, but not alwaysOccasionalConfirming the key is backed up before upgrading
Monthly cumulative update touching the boot managerBoot manager or boot configuration changesRare, but it has happened with some releasesBacking up the key; installing on a day you can spare an hour
Changing boot order or boot mode (legacy vs UEFI)Boot configuration measurements differCommon after BIOS tinkeringLeaving boot settings alone, or suspending first
Clearing or disabling the TPMThe sealed key is lost to the TPMCommon when resetting BIOS defaultsNever clearing the TPM on an encrypted PC without the key
Motherboard, CPU or drive swap or dock/boot-device changeHardware identity differsCommon after repairsWriting the key down before any repair
Too many wrong PIN attemptsLockout protectionOccasional on PIN-protected PCsUsing a PIN you remember, and keeping the key
Booting an external device or WinRE with different settingsBoot path changedOccasionalUnplugging USB drives before restarting

You may have read that a specific update caused the prompt for many people. Such reports do appear from time to time after Patch Tuesday, especially on PCs from certain manufacturers or with particular firmware, and they usually involve the Secure Boot or boot manager components rather than the Windows desktop itself. Because the exact causes differ from one release to another, treat the cause as secondary. The immediate task is the same in every case: find the key, unlock the drive, and make sure the key is backed up before it happens again.

One more cause deserves attention in 2026. Secure Boot certificates that Microsoft originally issued in 2011 are scheduled to expire in 2026, and the replacement certificates are being delivered through Windows updates and firmware. Changes to the Secure Boot database are part of what the TPM measures, so on some machines the transition can lead to a recovery prompt. We cover that deadline separately in our guide to the Secure Boot certificate expiry; here, the practical lesson is simply to check that your key is saved before any firmware or Secure Boot related update lands on your PC.

What the recovery key looks like and how to read the Key ID

A BitLocker recovery key is a 48-digit number split into eight groups of six digits, such as 123456-123456-123456-123456-123456-123456-123456-123456. The recovery screen also shows a Key ID, which is the first eight characters of an identifier, and you must match that ID to the correct stored key. If you have several keys saved, only the key whose ID matches the one on screen will unlock this drive.

The blue screen usually says something like "Enter the recovery key for this drive" and then shows two lines of text. One tells you where the key might be stored, for example "Your recovery key can be found in your Microsoft account" or "contact your system administrator". The other shows the Key ID. Write the first eight characters down or take a photo with your phone before you search. A single account can hold several keys, because each encrypted drive, and sometimes each re-encryption of the same drive, has its own key.

Read the screen before you go hunting

Key ID. The first 8 characters are what you compare against the list in your account. If the characters differ even by one, it is a different key.

The hint line. It often tells you whether the key was saved to a Microsoft account, to a work or school account, to a file, or printed. That single line can save you an hour of searching.

The drive label. If you see "Recovery key for drive D:" rather than C:, you are unlocking a data drive, not the system drive, and the key may be stored somewhere else.

Keep in mind that the number must be typed exactly. The screen accepts the digits only; dashes are added for you. A transcription mistake in one digit fails the whole attempt, and repeated failures are normal at this stage, so go slowly. When you find the key on a phone screen or on paper, read it in groups of six and check each group before pressing Enter.

Finally, remember that the recovery key is as powerful as the password to your drive. Anyone who has it and your computer can read your files. Share it only with people you trust or with your own IT provider, and never type it into a website that is not the official Microsoft account page. We return to scams around recovery keys in a later section.

Where to find your BitLocker recovery key: 6 places to check

Check, in this order: your personal Microsoft account at aka.ms/myrecoverykey, your work or school account, Active Directory or your IT department, a saved file or USB drive, a printout, and finally any other Microsoft account you may have used to set up the PC. The key is almost always saved in one of these places, because Windows prompts for a backup when encryption is turned on.

Use a second device, such as your phone or another computer, to look up the key. You cannot sign in on the locked PC, but you do not need to.

1. Your personal Microsoft account

On any phone or computer, open aka.ms/myrecoverykey, which redirects to the BitLocker recovery keys page of your Microsoft account, and sign in with the account you used when you first set up the PC. The page lists one entry per device, showing the device name, the Key ID, the key itself and the date it was saved. Compare the Key ID on the blue screen with the list. If your account shows several keys for the same device name, the ID is the only reliable way to pick the right one.

This is the single most common success path. When you sign in to Windows 11 with a Microsoft account and the device meets the requirements, Windows turns on device encryption and uploads the recovery key to that account automatically, often without any visible message. Many people are surprised to learn that their laptop has been encrypted since the first day.

If the page is empty, try again with any other Microsoft addresses you own, including an old Hotmail or Outlook address, a work address that is also a personal Microsoft account, or the account of a family member who set up the computer for you. People often sign in with the wrong account and conclude that there is no key.

2. Your work or school account

If the PC belongs to an employer or school, the key is usually stored in Microsoft Entra ID (the new name for Azure Active Directory) or in on-premises Active Directory. A user can often view it by signing in to the My Account portal and opening the Devices section, where a "Get BitLocker keys" option may appear for a device. Many organizations disable that self-service option on purpose, and in that case the administrator retrieves the key from the Microsoft Entra admin center or Intune.

Do not try workarounds on a managed laptop. Contact your help desk, give them the Key ID and the device name, and they can read out the key. For a company with only a few computers and no formal IT department, the person who enrolled the devices or your managed service provider is the one to ask.

On older domain-joined networks, the key may be stored as an attribute of the computer object in Active Directory Domain Services. An administrator can search by the Key ID in the BitLocker Recovery tab of the computer account, or with the BitLocker Recovery Password Viewer tool. If you manage such a network, confirm now that recovery information is actually being backed up. Many offices discover during an incident that the policy was never enforced.

4. A saved file or USB drive

When BitLocker is switched on manually, Windows offers to save the key to a file, to a USB flash drive, to your account, or to print it. A saved key file is a plain text file, typically named "BitLocker Recovery Key" followed by the Key ID, ending in .TXT. Search your other computers, your cloud storage, your email attachments and any USB sticks in a drawer. Search the whole system for the first characters of the Key ID if you do not remember the file name.

5. A printout

The printed version is easy to lose, because it often ends up in a folder with the laptop's warranty paperwork or with a folder of tax documents. Check the box the laptop shipped in, a home office filing cabinet, and any envelope marked with the computer's name. If the printout was done by a former IT person, ask them.

6. Another account or a backup in a password manager

If you store important secrets in a password manager, search it for "BitLocker" or "recovery". Some users save the key as a secure note years ago and forget about it. Our password manager guide explains how to set one up so that exactly this kind of information is findable at the worst moment.

Where the key may beTypical PCHow to get itChance it exists
Personal Microsoft accountHome laptop signed in with Microsoft accountaka.ms/myrecoverykey on another deviceHigh on recent Windows 11 PCs
Work or school account (Entra ID)Company or school laptopMy Account portal or ask ITHigh if enrolled in management
Active DirectoryDomain-joined office PCAdministrator, BitLocker Recovery tabDepends on policy being enforced
Text file or USBPC where BitLocker was turned on manuallySearch other devices and drives for the Key IDMedium
PrintoutSame as aboveCheck paperwork and filingLow to medium
Password manager noteCareful usersSearch for "BitLocker" or the Key IDLow, but cheap to check

Key-hunt checklist (work through it before you give up)

  • I photographed the blue screen and wrote down the first 8 characters of the Key ID.
  • I opened aka.ms/myrecoverykey on another device and signed in with my main Microsoft account.
  • I tried every other personal email address I have ever used with Microsoft, including old ones.
  • I asked the person who set up the PC (family member, employee, former IT contact) which account they used.
  • If the PC is from work or school, I contacted the help desk with the device name and Key ID.
  • I searched my cloud storage, email and USB drives for a file named "BitLocker Recovery Key".
  • I checked my password manager and the paperwork that came with the laptop.
  • I did not reinstall Windows, reset the PC or format the drive while looking.

The last item matters more than anything else on this list. Resetting the PC or reinstalling Windows to "get rid of" the blue screen erases the encrypted data permanently. If the key is still being hunted for, leave the computer powered off and untouched until you have exhausted every option.

How to match the correct key when you have several

Match the Key ID on the blue screen against the Key ID next to each stored key, comparing at least the first eight characters. Use the key whose ID matches exactly, not the newest one and not the one with the right device name. A computer can have a different key for each protector, and a re-encryption or a reset creates a new one.

Duplicate device names are common after a motherboard replacement, a Windows reinstall or a Microsoft account re-registration. The account page may show three entries named "DESKTOP-ABC123" with three different dates. Only one of them was generated for the key protector now on your drive. The date helps as a tiebreaker, but the ID decides. If none of the stored IDs match, the stored list is out of date, and you should keep looking in the other five places before concluding anything.

When none match, it usually means one of three things: the drive was re-encrypted after the last backup, you are looking at the wrong account, or the key was never uploaded because the PC used a local account at setup. All three are common, and the first two are fixable by searching harder. The third is covered in the next section.

Illustration of a digital key unlocking an encrypted laptop drive protected by BitLocker

Can't find the recovery key: what is realistically possible

If the key is not in any account, file or printout, there is no legitimate way to bypass BitLocker, and neither Microsoft nor any technician can decrypt the drive for you. Your realistic options are to keep searching, to restore from a backup, or to accept the loss and reinstall Windows on a wiped drive. This is harsh, but it is the entire point of disk encryption.

It helps to be honest about what does and does not work. BitLocker with a TPM and a strong recovery key uses AES encryption, and the key cannot be guessed. Websites and videos that promise a "BitLocker bypass" for a locked, modern, TPM-protected drive either do not work, require the key anyway, or are scams. Some older tricks relied on weaknesses in unusual configurations, such as drives that were encrypted in suspended state, or on access to a machine that still booted into a logged-in session. None of them is a reliable plan when you are staring at the blue recovery screen.

What not to do

Do not pay anyone who promises to "crack" or "remove" BitLocker. A legitimate technician will ask you for the key; a fraudster will ask you for money or remote access, and may lock you out further.

Do not reset the PC, reinstall Windows or format the drive while there is any chance the key can still be found. That step is irreversible.

Do not enter your key on any web page that is not the official Microsoft account site. Recovery key phishing exists, and a stolen key is as bad as a stolen password.

If Windows still starts in any way

If you can reach a working Windows desktop (for example the prompt only appeared once and you got through with another method), you can read the key from inside. Open an elevated Command Prompt and run manage-bde -protectors -get C:. The output shows the numerical password for the drive together with its ID. Copy it somewhere safe immediately, and back it up to your account as described later.

When the key is truly gone: your options

  1. Restore from backup. If you have a recent backup of your files (File History, OneDrive, an external drive, a business backup), you do not need the encrypted drive at all. Reinstall Windows on a clean drive, then restore the files. Backups of an encrypted drive are encrypted only if you chose that option, and your cloud sync folders are usually readable from another computer.
  2. Look for synced copies. OneDrive, iCloud, Google Drive and Dropbox often hold the Documents, Desktop and Pictures folders. Sign in on the web from another device and check.
  3. Ask who else has the key. A previous IT provider, the company that sold you the computer, or the person who set up your Microsoft account may have a copy.
  4. Reinstall Windows. This is the last resort. It erases the encrypted contents and gives you a working computer again. The old data is not recoverable by any professional tool without the key.

Professional data recovery labs can help with physical drive failures, but they cannot defeat modern BitLocker encryption. If a drive is both encrypted and damaged, the lab still needs the key to read anything useful. We explain what recovery work can and cannot do in our guides to data recovery after a Windows update or reinstall and why SSD recovery is harder than hard drive recovery. For an SSD, the drive's built-in cleanup (TRIM) makes things even harder after a reset.

How to enter the recovery key and get back into Windows

Type the 48-digit key on the blue screen and press Enter. If it is accepted, Windows starts normally, and you should then back up the key and fix the underlying cause so the prompt does not repeat. Entering the key does not decrypt the drive permanently; it only unlocks it for this session.

  1. Locate and read the Key ID on the recovery screen, then retrieve the matching key using the places in the previous section.
  2. Type the key using the keyboard. The screen adds the dashes, so type digits only. If you make a mistake, press Esc to go back and start again.
  3. Press Enter. Windows should continue to the sign-in screen.
  4. Sign in and wait a few minutes for the system to settle, especially if an update was in progress.
  5. Immediately confirm the key is backed up to your account or to your organization.
  6. Restart once to see whether the prompt returns. If it does, move on to the loop section below.

If the key is rejected, check three things. First, that the Key ID matches exactly. Second, that every digit is correct, since one wrong digit is the usual reason for rejection. Third, that you are not entering the key for the wrong drive, which happens on PCs with two or more encrypted drives. If the screen offers "Skip this drive" and your system drive is not the one asking, you can skip a secondary data drive to start Windows and deal with it afterwards.

The keyboard does not work on the BitLocker screen

This is a classic problem. Some wireless or Bluetooth keyboards are not active at the BitLocker pre-boot screen, because the receiver or driver has not loaded. Try these in order:

If the keyboard still fails, the problem is likely hardware or firmware, and the BIOS may need updating. That is a good moment to use a remote technician rather than experimenting, because a mistake in firmware settings can trigger yet another recovery prompt.

Symptom on the blue screenMost likely causeWhat to do
Key accepted, Windows starts, prompt returns on next restartTPM protector no longer sealed to the current boot stateSuspend and resume BitLocker to reseal it (see the loop section)
Key rejectedWrong Key ID or a mistyped digitCompare IDs and retype slowly
Keyboard types nothingWireless keyboard or dock not available before Windows loadsWired USB keyboard; F1 to F10 as digits
Screen mentions a PINPIN-protected PC, too many wrong attemptsUse the recovery key, then reset the PIN
Screen says to contact your administratorManaged device, key stored with the organizationCall the help desk with the Key ID
No Key ID shown at allUnusual firmware screen or a non-BitLocker promptPhotograph it; it may be a BIOS password or another tool

How to stop BitLocker from asking for the key at every restart

If the prompt returns after you enter the key, suspend BitLocker and then resume it, which makes the TPM take fresh measurements and reseal the key to the current, healthy boot state. In most cases this ends the loop within two restarts. You do not need to decrypt the drive or reinstall Windows.

Once Windows is running, open the Start menu, type cmd, right-click Command Prompt and choose Run as administrator (or open Terminal as administrator). Then follow this sequence.

  1. Check the status. Run manage-bde -status C:. Note the protection status, the encryption method and the key protectors listed. "Protection On" with "Numerical Password" and "TPM" protectors is the normal healthy layout.
  2. List the protectors. Run manage-bde -protectors -get C:. Copy the numerical password and its ID to a safe place, such as your password manager.
  3. Suspend protection. Run manage-bde -protectors -disable C:. This keeps the drive encrypted but stores the key in the clear on the drive so the next start will not ask for it. Windows will resume protection automatically after the next restart unless you extended the count.
  4. Restart once and let Windows load fully.
  5. Resume protection. Run manage-bde -protectors -enable C:. Windows reseals the key against the current measurements.
  6. Restart again and confirm there is no prompt.

PowerShell users can do the same with Suspend-BitLocker -MountPoint "C:" -RebootCount 1 followed by Resume-BitLocker -MountPoint "C:". The RebootCount parameter sets how many restarts the suspension should last. A value of 1 or 2 is enough for most cases. Do not leave BitLocker suspended for days; a suspended drive is unprotected against someone who finds the machine.

If the loop continues after suspend and resume

If the prompt still returns, something in the boot configuration is changing on every start, or the TPM is not working properly. Work through these checks:

As a last resort, remove and re-add the TPM protector. From an elevated prompt, with the recovery key safely written down, run manage-bde -protectors -delete C: -type TPM followed by manage-bde -protectors -add C: -TPM. Think carefully before doing this, because a mistake at this point means you cannot unlock the drive without the key. If you are not completely sure, stop and ask for help.

Clearing the TPM is not part of this routine. It destroys the sealed key and forces a recovery prompt, and on a PC with an unknown key it can turn a recoverable situation into a permanent one.

How to back up the key now so you never get stuck again

Save the recovery key in at least two places that do not live on the encrypted PC: your Microsoft account (or Entra ID for work), and a second copy such as a password manager or a printed sheet kept with your important documents. Five minutes of effort today replaces the worst hour of your week later.

To verify that your account holds the key, open aka.ms/myrecoverykey from another device and compare the IDs with manage-bde -protectors -get C:. If the account does not list your drive, upload the key from Windows. On Windows 11 Pro, open Control Panel, then BitLocker Drive Encryption, choose "Back up your recovery key" and select "Save to your Microsoft account". On a work device, your administrator controls the destination. PowerShell can also back up to Entra ID with BackupToAAD-BitLockerKeyProtector, and to Active Directory with manage-bde -protectors -adbackup, where those directory services apply.

Recovery-key insurance checklist (save this)

  • I know whether my drive is encrypted (manage-bde -status shows Protection On).
  • My key appears at aka.ms/myrecoverykey (or in Entra ID or Active Directory for work PCs), and the Key ID matches my drive.
  • I saved a second copy of the key in a password manager or printed it and stored it away from the laptop.
  • I never store the only copy of the key on the encrypted drive itself.
  • For office PCs, I keep a spreadsheet of computer names and where each key is stored (not the keys themselves in plain email).
  • I know my Microsoft account password and have two-factor authentication methods that I can still reach.
  • I have a recent backup of my files that does not depend on unlocking this PC.

Account recovery is part of this picture. If you cannot sign in to the Microsoft account that holds the key because you lost your phone or changed the number, you have the same problem one level up. Review your sign-in methods now. Our guide to recovering a hacked Microsoft or Outlook account covers what to do when the account itself is the problem, and passkeys are a safer and easier alternative to passwords for protecting it.

Suspend BitLocker before BIOS updates, hardware changes and big updates

Before you flash a BIOS, change Secure Boot settings, swap a drive or reinstall firmware components, suspend BitLocker with manage-bde -protectors -disable C: -RebootCount 2, do the change, and let it resume afterwards. This prevents the recovery prompt in the large majority of cases. Windows usually does this automatically for vendor-delivered updates, but manual changes need your help.

Planned changeSuspend first?Notes
BIOS or UEFI update by flashing from the vendor tool or a USB stickYesThe most common manual trigger; do it before you flash
BIOS update through Windows Update, Dell/HP/Lenovo toolsUsually handled, but a suspend is cheap insuranceHave the key available anyway
Changing Secure Boot keys or settingsYesSecure Boot state is measured by the TPM
Replacing the motherboardYes, and expect a prompt regardlessA new board has a new TPM; the key is required
Replacing or cloning the SSDDecrypt or suspend; keep the keyCloning an encrypted drive carries the encryption with it
Windows feature update (annual release)OptionalWindows normally manages this; confirm the key backup first
Monthly cumulative updateNoRarely needed, but have the key reachable
Booting a USB repair tool or WinRENoJust have the key; the tool may ask for it

The habit is simple: before a change, find the key; after the change, check the prompt did not return. Suspend only when the change affects firmware or hardware, and resume immediately afterward. For Dell, HP and Lenovo business laptops, the vendor's own update utilities typically cooperate with BitLocker, but if a BIOS update is scheduled to run on the next boot, make sure the key is in your account before you restart. For other brands, read the release notes of the BIOS version; many mention BitLocker.

If your PC already booted into the recovery screen after a firmware update and you needed the key, treat it as a lesson rather than a failure. Follow the earlier steps, back up the key, and the next update should pass without a prompt.

Windows 11 Home vs Pro: why many people did not know their PC was encrypted

Windows 11 Home uses "device encryption", a simplified form of BitLocker that turns on automatically when you sign in with a Microsoft account on supported hardware, while Windows 11 Pro offers the full BitLocker management tools. Both rely on the same recovery-key mechanism, and both can show the same blue screen. That is why a family laptop can suddenly demand a key even though nobody ever "turned on BitLocker".

The difference matters in practice. On Home, the key is normally uploaded to the Microsoft account used at setup, so aka.ms/myrecoverykey is your best first move. On Pro, you can choose where to save keys, and many people clicked through the prompt without reading it. Recent Windows 11 releases have also widened automatic encryption on new installations and reinstalls, so a PC you reset last year may be encrypted today without you having changed a setting. Microsoft's documentation describes the exact conditions, and they vary by edition, hardware and sign-in type, so confirm your own status with manage-bde -status or in Settings, Privacy and security, Device encryption.

FeatureWindows 11 HomeWindows 11 ProWork or school PC
Name in SettingsDevice encryptionBitLocker Drive EncryptionBitLocker, controlled by policy
How it turns onOften automatic with a Microsoft account sign-inManual or automatic, depending on setupBy Intune or Group Policy
Where the key goesMicrosoft accountAccount, file, USB, print, or directoryEntra ID or Active Directory
Who can view the keyYouYou (if saved to your account)Administrator, sometimes the user
Best first move after the promptaka.ms/myrecoverykeyaka.ms/myrecoverykey, then files and printoutsCall your help desk

One important trap: if you set up the computer with a local account instead of a Microsoft account, the automatic backup may not have happened at all, so no key might exist in any cloud account. In that case the only copies are the ones you saved manually. If you can still start Windows, back up the key right now, as shown earlier. If you are sitting at the blue screen with no key anywhere, the situation is the one described in the "can't find the key" section.

Three realistic scenarios (illustrative)

The same blue screen has very different outcomes depending on one detail: where the key was saved. These three composite, illustrative scenarios show the typical ranges of time and cost when the key is found quickly, when it takes some digging, and when it cannot be found. They are not real client cases; the numbers are realistic estimates.

Scenario A: Home laptop after a firmware update (key found in 10 minutes)

A home user installs a manufacturer BIOS update delivered through Windows Update, restarts, and sees the blue screen. The laptop was set up with a Microsoft account three years ago. The user takes a photo of the Key ID, opens aka.ms/myrecoverykey on a phone, finds two entries for the same device name with different dates, and matches the ID. The 48 digits go in, Windows starts, and the user runs the suspend and resume commands. Total time: about 10 to 15 minutes. Cost: nothing. Lesson: the photo of the Key ID saved the day, because the two entries would otherwise have been confusing.

Scenario B: Five-person office, three laptops prompted after a Secure Boot related update (key found, 2 hours)

A small Quebec accounting office has five Windows 11 Pro laptops, enrolled by a former contractor. After an update on a Monday morning, three laptops show the recovery screen. Nobody knows where the keys are. The office manager checks the shared inbox and finds nothing, then asks the former contractor, who remembers the laptops were registered under a single work account. Two keys are found there, and the third was saved on a USB stick in a desk drawer. Three people lose roughly two hours each, about 6 hours of work in total. At an internal rate of about 40 dollars an hour, the lost time is around 240 CAD before anyone fixes the underlying issue. The office then writes down every key in a password manager and adds a firmware update procedure with suspend steps. Lesson: the time cost of an unfindable key scales with the number of machines.

Scenario C: Freelancer with a local account and no backup (key not found)

A freelance designer set up a Windows 11 Pro laptop with a local account and turned on BitLocker manually for client confidentiality, saving the key to a text file on the same laptop. After a firmware update the blue screen appears, and the only copy of the key is on the locked drive. There is no Microsoft account copy, no print and no USB. The last file backup is five months old. The designer must reinstall Windows, restore the five-month-old backup, and recreate the missing work, which is about two weeks of projects. The lesson is blunt: a key stored on the encrypted drive protects nothing, and a backup older than a few weeks is not a backup. An hour of preparation would have cost nothing.

What this costs in Canadian dollars: DIY vs paying a technician

If the key is in your Microsoft account, the fix is free and takes 10 to 30 minutes. If you need help finding the key or breaking a recovery loop, a remote technician session costs 119.99 CAD for a 60-minute Expert Consultation at IT Cares. If the key is lost, no payment can bring the data back, and the cost becomes the value of the lost files plus a reinstall.

SituationDIY costTimePaid helpNotes
Key in Microsoft account0 CAD10 to 30 minRarely neededMatch the Key ID
Key exists, prompt loops0 CAD30 to 60 min119.99 CAD for a 60-minute remote sessionSuspend, resume, check TPM and firmware settings
Several office PCs prompting0 CAD plus staff time2 to 6 hours total119.99 CAD per 60-minute sessionPlan an inventory of keys afterwards
Key lost, backup existsWindows reinstall (free) plus a few hours3 to 6 hours119.99 CAD for guided reinstall and restoreData after the backup date is lost
Key lost, no backupReinstall onlyHoursNo tool can decrypt without the keyThe files are gone; rebuild from other copies

Compare these figures with the price of a typical outcome of doing nothing: the cost of a day of downtime for a small business is usually many times the 119.99 CAD consultation, and a replacement laptop costs far more than any repair session. Our guide to data recovery costs in Canada explains what lab work normally costs when a drive is physically damaged, which is a different problem from a lost BitLocker key.

Business owners also have a legal angle. Encrypting laptops is a recognized safeguard for personal information, and Quebec's Law 25 expects reasonable security measures. Encryption without key management, however, swaps one risk (stolen data) for another (inaccessible data). Our article on encryption as a legal requirement for small businesses explains the obligations, and the practical rule is simple: every encrypted device needs a documented, tested way to recover it.

For small businesses: a simple BitLocker key policy that works

Every encrypted company computer should have its recovery key stored in a central place the owner controls (Entra ID, Active Directory or a managed password vault), documented in an inventory, and tested once a year. The test is simple: pick one laptop, retrieve its key without touching the laptop, and confirm the ID matches. If you cannot do that in five minutes, your policy is not finished.

The common failure points in offices are predictable. Laptops were set up by an employee or a contractor under a personal Microsoft account that has since been closed. Keys were saved to local files that lived on the encrypted drive. A reseller enrolled devices and never handed over the admin access. New laptops arrive with encryption already turned on and nobody knows. Fixing these takes a few hours once, and the payoff is that a firmware update never becomes an emergency.

Office BitLocker policy checklist

  • List every Windows PC, whether it is encrypted, and where its key is stored.
  • Move keys from personal accounts to a business-controlled location (Entra ID, Active Directory or a business password manager).
  • Require key backup before BitLocker is enabled (Group Policy or Intune setting), so a drive never becomes encrypted without a stored key.
  • Write a short procedure: who retrieves keys, who approves, and how the retrieval is logged.
  • Add "suspend BitLocker" to your BIOS and firmware update procedure.
  • Keep an up-to-date, tested backup of user files that does not depend on unlocking any one laptop. Our guide to automated backups for small businesses covers the options and costs.
  • Test one key retrieval per year and record the date.

Recovery key scams and safety: what to watch for

Microsoft will never call you to ask for your BitLocker recovery key, and the key should only ever be entered on the blue boot screen or shown on your own Microsoft account page. Anyone asking you to read the key aloud or type it into a website is trying to scam you. Fake support pop-ups use the panic of a locked computer to sell remote access.

Warning signs include a phone call or message claiming "your BitLocker is compromised", a search result for "unlock BitLocker without key" that leads to a paid download, and a pop-up in the browser with a phone number. The Canadian Anti-Fraud Centre and your bank can help if you have given money or remote access to a stranger. If you gave a stranger remote access to a computer, disconnect from the internet, change your passwords from another device, and have a technician check the machine. We cover that in more detail in our article on getting back into Windows safely, which compares legitimate recovery options with risky ones.

Also be careful with the key itself. Do not email it to yourself unencrypted if the mailbox is shared, do not post a photo of the screen with the full key on social media, and do not save it in a note app that syncs to an account other people can access. A copy in a proper password manager protected by a strong master password is safer than any of those.

Common myths about BitLocker recovery

BitLocker does not mean your PC is infected, a Windows update has not destroyed your files, and the recovery prompt is not a bug you can remove by resetting the PC. Most of what makes this experience frightening is based on a few misunderstandings.

When to call a professional

Call a professional if you cannot find the key and the data matters, if the prompt keeps returning after a suspend and resume, if several office PCs are locked at once, or if you suspect someone else has had access to the machine. A short session often saves hours of risky experimenting.

IT Cares has provided remote and on-site IT support in Quebec and across Canada since 2014. In a remote session, we connect to your device only with your permission, while you watch. We can help you locate the correct key, remove a recovery loop, check TPM and firmware settings, and set up key backups so the next update is uneventful. A 60-minute Expert Consultation is 119.99 CAD. We cannot decrypt a drive without its key, and we will tell you so honestly rather than promise the impossible.

To talk to someone now, call 1 (888) 711-9428 or book a remote session. If you are looking at the blue screen right now, say so on the call so we can triage it first, and keep the photo of your Key ID handy.

Summary: the whole process in one minute

Photograph the Key ID, open aka.ms/myrecoverykey on another device (or ask your IT department), match the ID, type the 48 digits, then suspend and resume BitLocker and back up the key in two places. That sequence solves the large majority of post-update recovery prompts.

  1. Do not reset or reinstall Windows while the key might still be found.
  2. Check your Microsoft account, work account, files, USB drives and printouts, and match the Key ID.
  3. Enter the key; use a wired keyboard or F1 to F10 if the keyboard does not respond.
  4. In Windows, run manage-bde -protectors -get C: to copy the key and back it up.
  5. Run manage-bde -protectors -disable C:, restart, then manage-bde -protectors -enable C:, to stop a loop.
  6. Suspend BitLocker before any BIOS, Secure Boot or hardware change.

The recovery key is a small piece of text with a big job. Treat it like the spare key to your house: keep copies in more than one place, and know where they are before you need them.

Still stuck? Get a technician on it now

Remote support from IT Cares: we connect to your device, fix it with you watching, and explain what happened.

Frequently asked questions

Why is BitLocker asking for a recovery key after a Windows update?
BitLocker asks for the key when the TPM sees that the boot state differs from when the drive was last sealed. Updates that touch firmware, Secure Boot settings or the boot manager, a BIOS update, a TPM change or a hardware swap can all cause it. Your data is not damaged. The prompt is a safety check, and entering the matching 48-digit key unlocks the drive.
Where do I find my BitLocker recovery key?
Check, in order, your personal Microsoft account at aka.ms/myrecoverykey, your work or school account (Microsoft Entra ID) or IT department, Active Directory, a saved text file or USB drive, a printout, and any other Microsoft account that may have been used to set up the PC. Use a second device, and match the Key ID shown on the blue screen.
What is the BitLocker Key ID and why does it matter?
The Key ID is the identifier shown on the recovery screen, and the first 8 characters let you pick the right key when an account lists several. Each protector has its own key, so only the one with a matching ID unlocks this drive. Comparing the ID prevents typing the wrong key several times.
Can Microsoft unlock my BitLocker drive without the key?
No. Microsoft can only show you a key that was uploaded to your own Microsoft account. It cannot create a replacement or decrypt a drive without the key. If the key was never backed up and you cannot find a saved copy, the data on the encrypted drive cannot be recovered by Microsoft or by a technician.
I cannot find my recovery key anywhere. What can I do?
Keep searching: other Microsoft accounts, a family member who set up the PC, your employer's IT team, USB drives and printouts. Restore from a backup or a cloud sync folder if you have one. If nothing works, the last resort is to reinstall Windows, which erases the encrypted contents. Never pay anyone who promises to crack BitLocker.
How do I stop BitLocker asking for the key every time I restart?
After entering the key, open an administrator prompt and run manage-bde -protectors -disable C:, restart once, then run manage-bde -protectors -enable C:. This makes the TPM take fresh measurements and reseal the key. If the prompt still returns, check that the TPM is enabled in tpm.msc, that Secure Boot and boot settings were not reset, and that no USB devices are altering the boot path.
My keyboard does not work on the BitLocker screen. What should I do?
Plug in a wired USB keyboard, ideally in a port directly on the PC, because wireless keyboards and some docks do not work before Windows loads. On the recovery screen the function keys F1 to F9 enter digits 1 to 9 and F10 enters 0. On a tablet or 2-in-1, try the touch keyboard if one appears.
How do I check whether my PC is encrypted with BitLocker?
Open an administrator Command Prompt and run manage-bde -status. Protection On means the drive is encrypted. In Windows 11 you can also look in Settings, Privacy and security, Device encryption (Home) or Control Panel, BitLocker Drive Encryption (Pro). Many people have device encryption turned on without remembering that they enabled it.
Should I suspend BitLocker before a BIOS update?
Yes, for manual BIOS or UEFI flashing, Secure Boot changes and hardware changes. Run manage-bde -protectors -disable C: -RebootCount 2 before the change so the drive is not locked at the next start. Vendor tools and Windows Update often handle this automatically, but make sure the recovery key is backed up first regardless.
Does a BitLocker recovery prompt mean my PC has a virus?
Usually not. The common causes are firmware or Secure Boot updates, TPM or boot-order changes, and hardware repairs. It is a sign that something in the boot chain changed. If the change was not something you or your IT team did, it is reasonable to have the machine checked, but malware is not the typical reason.
Will resetting or reinstalling Windows remove the BitLocker prompt?
It removes the prompt by erasing the encrypted data, so only do it when you have accepted the loss or have a full backup. A reset on an encrypted drive without the key permanently destroys the files. Look for the key and backups first, and consider a short session with a technician if the data matters.
Is it safe to store my BitLocker recovery key in my Microsoft account?
Yes, it is the recommended default for personal PCs, as long as the account is protected with a strong password and two-factor sign-in or a passkey. Keep a second copy in a password manager or a printout stored away from the laptop, because losing access to the account would mean losing access to the key as well.
How do I back up the BitLocker key for a small office?
Store each key in Microsoft Entra ID, Active Directory or a business password manager, keep an inventory of computer names and key locations, and require key backup before encryption is enabled. Test the retrieval of one key per year without touching the laptop itself.
Does IT Cares charge to help with a BitLocker recovery screen?
A 60-minute remote Expert Consultation is 119.99 CAD. A technician can help you find the correct key, remove a recovery loop, check TPM and firmware settings and set up key backups. No technician can decrypt a drive without its key, and we will say so plainly if that is your situation.

Sources and official references

Last verified: October 1, 2026

Need Help?