A blue screen asking for 48 digits is BitLocker doing its job rather than failing. The key is escrowed automatically far more often than people realise, so the first move is knowing where to look — and where the drive has failed as well, the order of work matters more than most people expect.
$ mdr triage /dev/sdb → Device: Dell XPS SSD · 512 GB → Status: BITLOCKER LOCKED — volume refuses to mount → Owner: verified · key supplied $ mdr engineer-working → Read-only image: taken · source untouched → BitLocker metadata: repaired → Unlock: key accepted $ mdr verify → ✓ documents — 41,900 files → ✓ mailbox — 1 PST rebuilt → ✓ data recovered — drive decrypted
No recovery firm can open a BitLocker volume without the 48-digit recovery key or the credentials it is tied to. Check your Microsoft account, Azure AD or Entra, Active Directory, a printout made at setup, a file on a USB stick, and your password manager first.
The route to the key depends entirely on who set the laptop up, so start there.
A personal machine. If Windows was set up with a Microsoft account signed in, the key was almost certainly uploaded to that account automatically — sign in at the Microsoft recovery-keys page and it will be listed against the device. Failing that, look for a printout or a text file saved at setup: Windows offers both and people accept without registering what they are accepting. Password managers are worth searching too, as is any USB stick in a drawer.
A work machine. Do not spend an afternoon hunting — ask whoever administers your IT. Corporate estates escrow BitLocker keys centrally, to Azure AD or Entra on modern setups, to Active Directory on older domains, or through Intune where devices are managed. Retrieving one takes an administrator a couple of minutes. This single question resolves more BitLocker enquiries than anything else we do.
The volume is sealed to the machine it lives in, so the prompt means the machine no longer looks the way it did.
The TPM releases the key automatically only when the boot environment matches what it measured when encryption was switched on. A firmware or BIOS update changes those measurements, which is why the prompt so often appears the morning after an update ran overnight — and why it catches out entire fleets at once when an estate updates together.
The same applies to anything else that alters the boot path: secure boot toggled, boot order changed, a new device added ahead of the disk, or the drive moved into a different machine entirely. That last one is the behaviour working exactly as intended — a stolen disk should not open in another computer. Repeated incorrect PIN entries and stalled Windows updates will also drop a volume into recovery, as will a drive that has begun failing, which is the case worth taking seriously.
Not every lost key is the end of the job — but it depends entirely on what the password was.
Where the 48-digit recovery key cannot be found anywhere, there is a second route: attacking the password itself. We run professional password recovery against BitLocker volumes using GPU-accelerated tooling, working from whatever you can tell us — a partial memory, the pattern you normally use, a date or a name that would have been in it, an old password from the same era.
Be clear about what that is. It is not breaking the encryption; the cipher is untouched. It is testing candidate passwords very quickly, and it succeeds when the password was short, reused, based on something guessable, or when you remember enough of it to narrow the search. It does not succeed against a long random passphrase, and no amount of hardware changes that arithmetic — anyone telling you otherwise is selling something that does not work.
The 48-digit recovery key itself is not a realistic target for this. It is designed to resist exactly that. What password recovery reaches is a user-chosen PIN or password, which is a very different proposition.
The case where a lab genuinely adds something, because the order of operations decides the outcome.
If the drive holding a BitLocker volume is also failing, unlocking it first is the wrong move. A decryption pass reads the entire volume — hours of sustained work on a disk that may not survive it, spent before a single file has been secured.
The drive is imaged read-only first, and the volume unlocked from that image rather than from failing hardware. That order preserves every read the drive has left and means an unstable disk only has to hold together once. Where there are bad sectors, the image is taken past them with the gaps logged, and BitLocker’s own integrity checks then tell us precisely which regions could not be recovered rather than producing silently corrupt output.
The honest split, because they are not the same job.
Where the drive is healthy and you have the key, unlocking and extracting is a short job rather than a recovery, and we price it as one. Where the drive has failed, encrypted drive work is £800 +VAT flat, with the imaging setting the timescale — typically three to four working days.
Every job opens with a free 48-hour diagnostic and a written quote. Where the key genuinely no longer exists anywhere, we will tell you at that point and there is nothing to pay — because no amount of work changes that answer.
Send the device over with a short account of what happened to it. The diagnostic costs nothing and commits you to nothing, and the figure that follows is fixed in writing before anything is opened.
Nothing can begin until the device is on the bench, which makes this the only step that needs anything from you. Pack it properly, put your details in with it, and send it over. What follows is a free diagnostic and a written figure, in that order.
Posting it? Use something tracked and insured — whatever is on the drive is worth considerably more than the postage. Bringing it in? Weekdays, 9am to 5:30pm, and it still wants packing as above for the journey.
Tell us what the device is, what it is doing, and anything already tried — an engineer will come back with a realistic view of the odds and a price band, before you commit to posting anything.
We’ll be in touch shortly. For anything urgent, call 0161 871 0788.
The questions we are asked most about recovering BitLocker and encrypted drives.
Possibly. Where the key is genuinely gone we can run professional password recovery against the volume — GPU-accelerated tooling testing candidates very fast, guided by whatever you remember of the password. That succeeds on short, reused or partly-remembered passwords. It does not succeed against a long random passphrase, and the 48-digit recovery key itself is designed to resist it. We will tell you honestly which position you are in.
Whoever administers your IT, almost certainly. Corporate estates escrow keys to Azure AD, Active Directory or Intune, and an administrator can retrieve one in a couple of minutes. Ask before assuming it is lost — this resolves more enquiries than any technical work we do.
Because the TPM only releases the key when the boot environment matches what it measured at setup, and firmware or BIOS updates change those measurements. It is the commonest trigger by a distance, and it catches whole fleets at once when an estate updates together.
It changes the order. Unlocking first means a full decryption pass across a disk that may not survive it, spent before a single file is secured. The drive is imaged read-only first and the volume opened from that copy instead.
You can, and it will ask for the recovery key when you do — the key is sealed to the original machine’s TPM. That behaviour is deliberate, and it is why a stolen laptop’s disk is not readable elsewhere.
£800 plus VAT flat where the drive has physically failed, quoted after a free 48-hour diagnostic. Where the drive is healthy and you have the key, it is a short extraction job and priced as one. Where the key genuinely no longer exists, we tell you and there is nothing to pay.
A free diagnostic, a quick ownership check, and your encrypted drive opened and handed back decrypted — a failing disk included. Get in touch and we take it from there.