A BitLocker recovery key is a 48 digit recovery password that unlocks a Windows drive when BitLocker will not unlock it automatically. Seeing the recovery screen does not mean anything is broken: BitLocker checked the machine against how it looked when the drive was encrypted, found a difference, and refused to release the key.
Where the key lives depends entirely on how the device was set up. On a business device it should be in Microsoft Entra ID or Active Directory. If it was never saved anywhere, the data is gone.
- A 48 digit recovery password, not a file you can regenerate
- The screen means something in the boot path changed, not that the disk failed
- Where it lives is decided at encryption time, not at recovery time
- A firmware update is among the most common triggers, and it is avoidable
- Suspend BitLocker before planned firmware or hardware work
On this page
Find itWhere the key actually is
Start here, because this is what somebody looking at the BitLocker recovery screen needs. The answer was decided when the drive was encrypted, so the question is really which of these applies to the device.
| How the device was set up | Where the BitLocker recovery key is | Who can get it |
|---|---|---|
| Joined to Microsoft Entra ID | In Entra ID | The user, often, or the help desk |
| Joined to an Active Directory domain | In AD DS, under the computer object | A domain administrator |
| Personal, with a Microsoft account | In that Microsoft account online | The account holder |
| Encrypted with a printout | On paper, wherever it was filed | Whoever has the paper |
| Encrypted with a saved file | A text file on another device | Whoever has that device |
| Encrypted with a USB key | A .bek file on removable media | Whoever has the USB drive |
| Nothing was ever configured | Nowhere | Nobody, and the data is gone |
The detail behind each row is worth having.
A work or school device. The BitLocker recovery key is almost certainly held centrally, and the person to ask is whoever runs the IT. For a device joined to Microsoft Entra ID it is stored in Entra ID, which Microsoft recommends as the backup method for Entra joined devices; a user can often retrieve it themselves from the web, and a help desk can be delegated access.
For a Windows device joined to an Active Directory domain it is stored in AD DS, in a child object of the computer object.
A personal device with a Microsoft account. Sign in at the Microsoft account site on another device and look under the devices listed there. Microsoft describes storing the recovery password in a Microsoft account as the default recommended method for Windows devices that are not Entra joined or domain joined.
A printed copy or a text file. Both are offered when BitLocker encryption is switched on, so a printout or a file named for the key may exist in the paperwork or on another device. Not on the encrypted device, for the obvious reason.
A USB drive. A separate thing from the recovery password: a recovery key file, with a name in the form of a protector id followed by .bek, stored on removable media.
The last row is the one nobody wants. If the recovery information was never backed up when BitLocker encryption was turned on, the key does not exist anywhere to be found, and the data on that drive is not recoverable.
That is a policy failure rather than a user failure, and the policy that prevents it exists: Windows can be configured not to enable BitLocker at all until the recovery information has been successfully stored in the directory.
The recovery screen shows a key id, a partial identifier. Match it against the identifier next to the stored key, because a device that has been re-encrypted or has more than one protected volume will have more than one recovery key, and Active Directory keeps the history of every recovery password for a computer object rather than removing the old ones.
The triggersWhy the screen appeared
BitLocker seals its encryption key to a measurement of the early boot path taken by the TPM. If the measurement differs from the one recorded when the drive was encrypted, the seal does not open, Windows cannot unlock the drive on its own, and the recovery password is required instead.
That is the whole mechanism, and it means the BitLocker recovery screen is a report about a change. Microsoft lists the events that commonly cause a Windows device to enter recovery, and the useful thing is how ordinary most of them are.
| What changed | Why it triggers recovery |
|---|---|
| A BIOS or UEFI firmware upgrade | Early startup components are measured |
| The TPM turned off, cleared or hidden | The seal has nothing to open it |
| A new motherboard, with a new TPM | A different TPM cannot open the old seal |
| Boot order changed, on TPM 1.2 devices | The order is part of the measurement |
| A CD or DVD ahead of the disk | Common on virtual machines |
| PXE boot, or booting an ISO | A different early boot path entirely |
| Docking or undocking a laptop | The hardware present at boot changed |
| Changes to the boot manager | A measured component, by design |
| Changes to the NTFS partition table | The volume no longer matches |
| The drive moved to another computer | Which is exactly what BitLocker is for |
| Too many wrong PIN attempts | A deliberate lockout |
Read the last row before the PIN one. A drive moved into a different computer asking for the BitLocker recovery key is not a malfunction; it is the entire feature working. Every other row is the same behavior with a benign cause.
The first row is the one worth planning around, and the BIOS update page is the other half of this one. A firmware update on an encrypted fleet, applied without preparation, produces a BitLocker recovery prompt on every device at once and a help desk that cannot keep up.
PreventionThe thing to do before planned work
Microsoft states it plainly and almost nobody outside IT knows it: for a planned hardware or firmware change, BitLocker recovery can be avoided by temporarily suspending protection.
Suspending is not decrypting. The drive stays fully encrypted. What changes is that the encryption key is held in a way that does not depend on the boot measurement, so Windows starts without asking. Resuming afterward reseals the key against the new measurement, with nobody typing 48 digits.
That turns the standard firmware rollout from an incident into a maintenance window:
1. Suspend BitLocker protection on the devices in scope. 2. Apply the firmware or hardware change and let each device reboot. 3. Resume protection, which reseals against the new measurement. 4. Confirm the recovery password is still backed up centrally.
BitLocker also resumes protection by itself at the next reboot unless a reboot count was specified, which is a safe default and a thing to know before assuming a fleet of devices is still suspended.
PitfallsWhere people go wrong
Treating the screen as a hardware failure. It is an integrity check reporting a change. The disk is almost always fine, and the interesting question is what changed.
Rolling out firmware to an encrypted fleet without suspending. The single most avoidable mass incident in this category, and the fix is one step long.
Assuming the recovery key is on the device. It is not, and it cannot be. That is the point of it.
Never verifying the backup. The recovery password is stored at encryption time if policy says so. An organization that has never checked which devices actually have a key in the directory has not verified the only thing that matters here.
Storing the key somewhere the outage takes down. A key held only in a documentation system that lives on the encrypted network is a key you cannot reach during the event that needs it.
Ignoring the key id on the screen. With re-encrypted devices and retained history, the wrong key from the right computer is a common and confusing few minutes.
ComparisonThe four ways back into a locked drive
| Option | What it is | Where it can live |
|---|---|---|
| Recovery password | The 48 digit number | Entra ID, AD DS, a file, printed |
| Recovery key file | A .bek file on removable media | A USB drive |
| Key package | For repairing a damaged volume | A file or AD DS, never Entra ID |
| Data recovery agent | A certificate acting as a master key | Active Directory |
Two of these are worth knowing about before they are needed. The key package is not generated automatically. It is what the BitLocker repair tool uses to salvage data from a drive that is physically damaged rather than merely locked, and saving it alongside the recovery password is a Windows policy setting somebody has to switch on.
It also cannot be stored in Entra ID, which is a real gap in an Entra only estate. The data recovery agent is a certificate that unlocks any volume covered by the policy, without finding a per machine key.
It is the closest thing to a master key BitLocker has, and it is worth exactly as much protection as that description implies.
FAQFrequently asked questions
What is a BitLocker recovery key?
A 48 digit recovery password that unlocks a BitLocker protected drive when the normal unlock does not happen automatically. It is generated when the drive is encrypted and it cannot be regenerated later from the machine.
Where do I find my BitLocker recovery key?
It depends on how the Windows device was set up. On a work device, in Microsoft Entra ID or Active Directory, which means asking IT. On a personal device, usually in the Microsoft account used on that PC. Otherwise a printout, a text file or a USB drive.
Why is my computer asking for a BitLocker recovery key?
Because something in the early boot path changed and no longer matches what was measured when the drive was encrypted. A firmware update, a TPM change, a boot order change, a new motherboard or moving the drive to another device will all do it.
Can I bypass the BitLocker recovery screen?
No, and that is the design. Without the recovery password, the recovery key file, a key package or a data recovery agent, the drive stays locked.
What if I never saved my BitLocker recovery key?
Then it does not exist anywhere and the data cannot be recovered. It is worth checking every place it could have been stored first, because the key was written somewhere at encryption time if any policy asked for it.
What does the key id on the screen mean?
It identifies which key is needed. A machine can have several stored keys, from re-encryption or from more than one protected volume, and Active Directory retains the older ones, so matching the identifier matters.
How do I stop a BIOS update from triggering BitLocker recovery?
Suspend BitLocker protection before the update and resume it afterward. Suspending leaves the drive encrypted and reseals the key on resume, so nobody has to type the recovery password.
Does suspending BitLocker decrypt the drive?
No. The drive stays fully encrypted. Only the way the key is protected changes for the duration, which is why suspend and resume is quick where decrypt and re-encrypt is not.
Where should a business store BitLocker recovery keys?
In the directory the Windows devices are joined to: Microsoft Entra ID for Entra joined devices and AD DS for domain joined ones. Policy can require that the backup of the recovery keys succeeds before BitLocker is allowed to encrypt anything.
Can users retrieve their own recovery key?
For Entra joined devices, often yes, from the web, and access can also be delegated to a help desk. Whether it is allowed is a policy decision the organization makes deliberately.
Is a recovery key the same as a recovery password?
Not quite. The recovery password is the 48 digit number typed at the screen. The recovery key is a file on removable media with a name ending in .bek. Both unlock the drive and the terms get used interchangeably.
What is a BitLocker key package?
A separate item used with the BitLocker repair tool to salvage data from a damaged volume. It is not created automatically, it has to be enabled by policy, and it cannot be stored in Entra ID.
Does BitLocker recovery mean my drive is failing?
Almost never. It reports a change in the boot path rather than a fault in the storage. If the drive is genuinely damaged, that is what the key package and the Windows repair tool are for.
How long is a BitLocker recovery key?
Forty eight digits, shown as eight groups of six. It is typed at the pre boot screen, where the keyboard layout is the firmware default rather than the one Windows normally uses.
Where is the BitLocker recovery key on Windows 11?
On Windows 11 the BitLocker recovery key is stored where the device was set up to store it: the Microsoft account of the person who first signed in, Microsoft Entra ID or Active Directory for a work device, or a printout or file saved at the time.
Windows 11 turns on device encryption automatically on many PCs, so check the Microsoft account first.
Keep readingRelated concepts
Read next · Firmware and boot What a BIOS Update Does, and Why the Old Advice Changed The trigger worth planning around, and why the firmware update it describes is now harder to justify skipping. Open this next10 min- Firmware and boot · 15 min How to Enable Secure Boot, and What to Check Before You Do The other firmware setting measured into the same boot path, and what changing it does to an encrypted machine.
- Cryptography · 11 min Encryption Algorithms, and the Two Families They Fall Into What is protecting the drive underneath all of this, and why the key management is the part that actually fails.
- Cryptography · 10 min Full Disk Encryption, and What It Does Not Protect What disk encryption does not protect against, and why recovery key escrow is where businesses fail.
- Cryptography · 9 min FileVault Disk Encryption, and Why the Disk Is Already Encrypted The macOS equivalent, where the Secure Enclave takes the place of the TPM.