Security · Concept · 10 min read

The BitLocker Recovery Key, and Why the Screen Appeared

The recovery screen is not a failure. It is BitLocker reporting that something in the early boot path changed, most often a firmware update, which is the one case you can plan around.

Written by Marko Ristic, Editor Updated Sep 17, 2026
48Digits in the recovery password, in eight groups of six
1Step that turns a firmware rollout from an incident into a window
0Ways back in if the key was never backed up anywhere
17Ordinary events Microsoft lists as causing the recovery screen
Short answer

A BitLocker recovery key is a 48 digit recovery password that unlocks a Windows drive when BitLocker will not unlock it automatically. Seeing the recovery screen does not mean anything is broken: BitLocker checked the machine against how it looked when the drive was encrypted, found a difference, and refused to release the key.

Where the key lives depends entirely on how the device was set up. On a business device it should be in Microsoft Entra ID or Active Directory. If it was never saved anywhere, the data is gone.

  • A 48 digit recovery password, not a file you can regenerate
  • The screen means something in the boot path changed, not that the disk failed
  • Where it lives is decided at encryption time, not at recovery time
  • A firmware update is among the most common triggers, and it is avoidable
  • Suspend BitLocker before planned firmware or hardware work
On this page

Find itWhere the key actually is

Start here, because this is what somebody looking at the BitLocker recovery screen needs. The answer was decided when the drive was encrypted, so the question is really which of these applies to the device.

How the device was set upWhere the BitLocker recovery key isWho can get it
Joined to Microsoft Entra IDIn Entra IDThe user, often, or the help desk
Joined to an Active Directory domainIn AD DS, under the computer objectA domain administrator
Personal, with a Microsoft accountIn that Microsoft account onlineThe account holder
Encrypted with a printoutOn paper, wherever it was filedWhoever has the paper
Encrypted with a saved fileA text file on another deviceWhoever has that device
Encrypted with a USB keyA .bek file on removable mediaWhoever has the USB drive
Nothing was ever configuredNowhereNobody, and the data is gone

The detail behind each row is worth having.

A work or school device. The BitLocker recovery key is almost certainly held centrally, and the person to ask is whoever runs the IT. For a device joined to Microsoft Entra ID it is stored in Entra ID, which Microsoft recommends as the backup method for Entra joined devices; a user can often retrieve it themselves from the web, and a help desk can be delegated access.

For a Windows device joined to an Active Directory domain it is stored in AD DS, in a child object of the computer object.

A personal device with a Microsoft account. Sign in at the Microsoft account site on another device and look under the devices listed there. Microsoft describes storing the recovery password in a Microsoft account as the default recommended method for Windows devices that are not Entra joined or domain joined.

A printed copy or a text file. Both are offered when BitLocker encryption is switched on, so a printout or a file named for the key may exist in the paperwork or on another device. Not on the encrypted device, for the obvious reason.

A USB drive. A separate thing from the recovery password: a recovery key file, with a name in the form of a protector id followed by .bek, stored on removable media.

The last row is the one nobody wants. If the recovery information was never backed up when BitLocker encryption was turned on, the key does not exist anywhere to be found, and the data on that drive is not recoverable.

That is a policy failure rather than a user failure, and the policy that prevents it exists: Windows can be configured not to enable BitLocker at all until the recovery information has been successfully stored in the directory.

The recovery screen shows a key id, a partial identifier. Match it against the identifier next to the stored key, because a device that has been re-encrypted or has more than one protected volume will have more than one recovery key, and Active Directory keeps the history of every recovery password for a computer object rather than removing the old ones.

The triggersWhy the screen appeared

BitLocker seals its encryption key to a measurement of the early boot path taken by the TPM. If the measurement differs from the one recorded when the drive was encrypted, the seal does not open, Windows cannot unlock the drive on its own, and the recovery password is required instead.

That is the whole mechanism, and it means the BitLocker recovery screen is a report about a change. Microsoft lists the events that commonly cause a Windows device to enter recovery, and the useful thing is how ordinary most of them are.

What changedWhy it triggers recovery
A BIOS or UEFI firmware upgradeEarly startup components are measured
The TPM turned off, cleared or hiddenThe seal has nothing to open it
A new motherboard, with a new TPMA different TPM cannot open the old seal
Boot order changed, on TPM 1.2 devicesThe order is part of the measurement
A CD or DVD ahead of the diskCommon on virtual machines
PXE boot, or booting an ISOA different early boot path entirely
Docking or undocking a laptopThe hardware present at boot changed
Changes to the boot managerA measured component, by design
Changes to the NTFS partition tableThe volume no longer matches
The drive moved to another computerWhich is exactly what BitLocker is for
Too many wrong PIN attemptsA deliberate lockout

Read the last row before the PIN one. A drive moved into a different computer asking for the BitLocker recovery key is not a malfunction; it is the entire feature working. Every other row is the same behavior with a benign cause.

The first row is the one worth planning around, and the BIOS update page is the other half of this one. A firmware update on an encrypted fleet, applied without preparation, produces a BitLocker recovery prompt on every device at once and a help desk that cannot keep up.

PreventionThe thing to do before planned work

Microsoft states it plainly and almost nobody outside IT knows it: for a planned hardware or firmware change, BitLocker recovery can be avoided by temporarily suspending protection.

Suspending is not decrypting. The drive stays fully encrypted. What changes is that the encryption key is held in a way that does not depend on the boot measurement, so Windows starts without asking. Resuming afterward reseals the key against the new measurement, with nobody typing 48 digits.

That turns the standard firmware rollout from an incident into a maintenance window:

1. Suspend BitLocker protection on the devices in scope. 2. Apply the firmware or hardware change and let each device reboot. 3. Resume protection, which reseals against the new measurement. 4. Confirm the recovery password is still backed up centrally.

BitLocker also resumes protection by itself at the next reboot unless a reboot count was specified, which is a safe default and a thing to know before assuming a fleet of devices is still suspended.

PitfallsWhere people go wrong

Treating the screen as a hardware failure. It is an integrity check reporting a change. The disk is almost always fine, and the interesting question is what changed.

Rolling out firmware to an encrypted fleet without suspending. The single most avoidable mass incident in this category, and the fix is one step long.

Assuming the recovery key is on the device. It is not, and it cannot be. That is the point of it.

Never verifying the backup. The recovery password is stored at encryption time if policy says so. An organization that has never checked which devices actually have a key in the directory has not verified the only thing that matters here.

Storing the key somewhere the outage takes down. A key held only in a documentation system that lives on the encrypted network is a key you cannot reach during the event that needs it.

Ignoring the key id on the screen. With re-encrypted devices and retained history, the wrong key from the right computer is a common and confusing few minutes.

WHY THE SCREEN APPEARS, AND HOW TO NOT SEE ITThe key is sealed to a measurement of the early boot path.At boot, the TPM findsand sowhich meansNothing changedBoot path measures the same>Seal opens>Windows starts, nobodynoticesFirmware updatedBoot path measures differently>Seal stays shut>48 digits, per device, at thedeskSuspended firstThe seal is not consulted>Key releasedanyway>Update, reboot, resume,resealedThe screen is not a fault report. It is BitLocker saying the boot path changed.And the third row is the second row with one step added in front of it.
The second and third rows describe the same firmware update. The only difference is whether anybody suspended protection before starting.

ComparisonThe four ways back into a locked drive

OptionWhat it isWhere it can live
Recovery passwordThe 48 digit numberEntra ID, AD DS, a file, printed
Recovery key fileA .bek file on removable mediaA USB drive
Key packageFor repairing a damaged volumeA file or AD DS, never Entra ID
Data recovery agentA certificate acting as a master keyActive Directory

Two of these are worth knowing about before they are needed. The key package is not generated automatically. It is what the BitLocker repair tool uses to salvage data from a drive that is physically damaged rather than merely locked, and saving it alongside the recovery password is a Windows policy setting somebody has to switch on.

It also cannot be stored in Entra ID, which is a real gap in an Entra only estate. The data recovery agent is a certificate that unlocks any volume covered by the policy, without finding a per machine key.

It is the closest thing to a master key BitLocker has, and it is worth exactly as much protection as that description implies.

FAQFrequently asked questions

What is a BitLocker recovery key?

A 48 digit recovery password that unlocks a BitLocker protected drive when the normal unlock does not happen automatically. It is generated when the drive is encrypted and it cannot be regenerated later from the machine.

Where do I find my BitLocker recovery key?

It depends on how the Windows device was set up. On a work device, in Microsoft Entra ID or Active Directory, which means asking IT. On a personal device, usually in the Microsoft account used on that PC. Otherwise a printout, a text file or a USB drive.

Why is my computer asking for a BitLocker recovery key?

Because something in the early boot path changed and no longer matches what was measured when the drive was encrypted. A firmware update, a TPM change, a boot order change, a new motherboard or moving the drive to another device will all do it.

Can I bypass the BitLocker recovery screen?

No, and that is the design. Without the recovery password, the recovery key file, a key package or a data recovery agent, the drive stays locked.

What if I never saved my BitLocker recovery key?

Then it does not exist anywhere and the data cannot be recovered. It is worth checking every place it could have been stored first, because the key was written somewhere at encryption time if any policy asked for it.

What does the key id on the screen mean?

It identifies which key is needed. A machine can have several stored keys, from re-encryption or from more than one protected volume, and Active Directory retains the older ones, so matching the identifier matters.

How do I stop a BIOS update from triggering BitLocker recovery?

Suspend BitLocker protection before the update and resume it afterward. Suspending leaves the drive encrypted and reseals the key on resume, so nobody has to type the recovery password.

Does suspending BitLocker decrypt the drive?

No. The drive stays fully encrypted. Only the way the key is protected changes for the duration, which is why suspend and resume is quick where decrypt and re-encrypt is not.

Where should a business store BitLocker recovery keys?

In the directory the Windows devices are joined to: Microsoft Entra ID for Entra joined devices and AD DS for domain joined ones. Policy can require that the backup of the recovery keys succeeds before BitLocker is allowed to encrypt anything.

Can users retrieve their own recovery key?

For Entra joined devices, often yes, from the web, and access can also be delegated to a help desk. Whether it is allowed is a policy decision the organization makes deliberately.

Is a recovery key the same as a recovery password?

Not quite. The recovery password is the 48 digit number typed at the screen. The recovery key is a file on removable media with a name ending in .bek. Both unlock the drive and the terms get used interchangeably.

What is a BitLocker key package?

A separate item used with the BitLocker repair tool to salvage data from a damaged volume. It is not created automatically, it has to be enabled by policy, and it cannot be stored in Entra ID.

Does BitLocker recovery mean my drive is failing?

Almost never. It reports a change in the boot path rather than a fault in the storage. If the drive is genuinely damaged, that is what the key package and the Windows repair tool are for.

How long is a BitLocker recovery key?

Forty eight digits, shown as eight groups of six. It is typed at the pre boot screen, where the keyboard layout is the firmware default rather than the one Windows normally uses.

Where is the BitLocker recovery key on Windows 11?

On Windows 11 the BitLocker recovery key is stored where the device was set up to store it: the Microsoft account of the person who first signed in, Microsoft Entra ID or Active Directory for a work device, or a printout or file saved at the time.

Windows 11 turns on device encryption automatically on many PCs, so check the Microsoft account first.

Read next · Firmware and boot What a BIOS Update Does, and Why the Old Advice Changed The trigger worth planning around, and why the firmware update it describes is now harder to justify skipping. Open this next10 min
Also worth reading
One packet a weekA short, illustrated explainer every Tuesday. No vendor pitches, unsubscribe in one click.