Firmware or BIOS updated
The update alters the measurements the TPM recorded, so the key is no longer released automatically. Much the commonest trigger — and why it catches whole fleets at once when an estate updates overnight.
Windows backs the recovery key up automatically to a Microsoft account, and corporate estates escrow it centrally — so most people who believe they have no key turn out to have one saved for them. Start with one question: work machine, or personal?
BitLocker binds the volume to the machine around it. Alter something in that machine’s chain of trust — the TPM, the firmware, the boot order — and it stops and asks you to demonstrate the drive is yours.
The route to your key depends entirely on who set the laptop up, so start there rather than searching randomly.
A work machine. Do not spend an afternoon hunting — ask whoever administers your IT. Corporate estates escrow BitLocker keys centrally, to Azure AD or Entra on modern setups, to Active Directory on older domains, or through Intune where devices are managed. Retrieving one takes an administrator a couple of minutes.
A personal machine. If Windows was set up with a Microsoft account signed in, the key was almost certainly uploaded to that account automatically. Sign in at the Microsoft recovery-keys page and it will be listed against the device.
This single question resolves more BitLocker enquiries than any technical work. People assume the key is lost because they never consciously saved one — and in most cases it was saved for them.
In order of how often each turns out to have it.
A personal Windows device backs the key up automatically when BitLocker is enabled with a Microsoft account signed in. Check the recovery-keys page for that device — and check any other Microsoft accounts you have used.
On a work laptop the key is usually escrowed to the tenant. Your IT team can retrieve it from the admin centre in minutes.
Domain-joined machines often escrow keys to AD where policy was configured to do so, which is common in established estates.
Windows offers to print the key or save it to a file when encryption is switched on, and people frequently accepted without registering what it was. Search your documents for a 48-digit number.
Managed estates hold keys centrally. Regularly overlooked because the user never saw it happen.
Older and manually configured installs sometimes store the key on removable media. Worth checking any sticks that came with the machine.
BitLocker ties the volume to the machine it lives in, and recovery mode is it noticing that something changed.
The update alters the measurements the TPM recorded, so the key is no longer released automatically. Much the commonest trigger — and why it catches whole fleets at once when an estate updates overnight.
Secure boot toggled, boot order altered, or a new device added ahead of the disk. All make the environment unrecognisable to BitLocker.
The key is sealed to the original TPM, so only the recovery key opens it elsewhere. That is the behaviour working exactly as designed — a stolen disk should not read in another computer.
A failing drive, a stalled Windows update, or repeated incorrect PIN entries will each drop the volume into recovery. The first of those is the one to take seriously.
Stated precisely, because a good deal of misleading material exists here.
The cipher itself is not attackable. There is no analysis of BitLocker metadata that reveals a key, and no laboratory technique that reads an encrypted volume without one. Any firm suggesting otherwise is describing something that does not exist.
What is attackable is the password, where one was used. We run professional GPU-accelerated password recovery guided by whatever you can remember — a partial memory, your usual pattern, a date or name that would have been in it. That succeeds on short, reused or partly-recalled passwords and fails against a long random passphrase. No amount of hardware changes that arithmetic.
The 48-digit recovery key itself is not a realistic target. It is designed specifically to resist exactly this. What password recovery reaches is a user-chosen PIN or password, which is a very different proposition — and we will tell you honestly which position you are in. Encrypted drive work in Manchester is £800 +VAT flat where the drive has also failed, after a free 48-hour diagnostic.
On a work machine, ask IT — it is almost certainly escrowed to Azure AD, Active Directory or Intune and takes minutes to retrieve. On a personal machine, check your Microsoft account’s recovery-keys page, then any printout or file saved at setup.
Very probably. Windows backs the key up automatically to a Microsoft account when BitLocker is enabled with one signed in, and corporate estates escrow centrally. Most people who think they have no key turn out to have one saved for them.
Because something it trusted changed — most often a firmware or BIOS update, which alters the measurements the TPM recorded. It also happens after boot configuration changes, moving the drive to another machine, or repeated incorrect PIN entries.
Not by attacking the encryption — nobody does that, including Microsoft. Where a user-chosen password was used, we can attempt professional password recovery, which works on weak or partly-remembered passwords and not against a long random one.
No. It is designed specifically to resist brute force and it is not a realistic target at any scale of computing. What password recovery can reach is a user-chosen PIN or password, which is a completely different proposition.
Imaging, before any unlocking. A decryption pass reads the entire volume, and on a failing drive that is hours of stress it may not survive. The drive is imaged read-only first and the volume opened from that copy instead.