If Windows is asking for a 48-digit BitLocker recovery key, the good news is it isn’t lost — BitLocker saved a copy the moment it was switched on. Here are the six places it hides, how to match it using the Key ID on screen, and what your options are if the drive itself has failed.
BitLocker generates a 48-digit recovery key when it turns on and files a copy automatically — in your Microsoft account, on a USB stick, on paper, or with your IT department. Finding it is nearly always about remembering where.
A 48-digit safety net, generated automatically the day BitLocker switched on.
BitLocker is the drive encryption built into Windows 10 and 11 Pro, and it is switched on by default on many newer laptops and Microsoft accounts. Day to day it unlocks invisibly using the TPM chip on the motherboard, sometimes with a PIN or password on top. The recovery key is the fallback for when that normal path can’t run — a single 48-digit number, in eight groups of six, that unlocks the drive on its own.
You meet the blue recovery screen when something about the machine changes and the TPM no longer trusts the boot: a motherboard or firmware/BIOS update, moving the drive into another computer, a hardware change, a Secure Boot setting, or simply a forgotten PIN. Nothing is wrong with your data — BitLocker is doing its job and asking you to prove the drive is yours.
Every key is tied to a Key ID: a short string whose first eight characters are shown on the recovery screen, for example A1B2C3D4. If a machine has had more than one key over its life, the Key ID is how you tell which saved key is the right one.
Work down the list — on a personal PC it’s almost always the first one.
1. Your Microsoft account. The commonest by far. Sign in at account.microsoft.com/devices/recoverykey (Microsoft’s short link is aka.ms/myrecoverykey) with the same Microsoft account the PC was set up with, and every key saved to it is listed against its Key ID. Try any personal accounts you or a family member might have used to set the machine up.
2. A work or school (Azure AD) account. If the device belongs to an employer or was enrolled in Intune, the key is stored against the organisation’s directory, not your personal account — your IT team can retrieve it, and on many company machines only they can.
3. A printout. BitLocker offers a “print the recovery key” option at setup, so a paper copy may be filed with your important documents.
4. A USB stick. It can be saved as a small text file named BitLocker Recovery Key <ID>.txt. Open it on another PC — the 48-digit key is inside.
5. A saved file. The same text file may have been saved to another drive, a network share or OneDrive. Searching your files for BitLocker Recovery Key often turns it up.
6. On-premises Active Directory. On a domain-joined business PC, keys are frequently escrowed to AD; an administrator can look them up by computer name or Key ID.
Found several keys? Read the eight characters after Key ID: on the recovery screen and match them to the entry with the same ID — that’s the one that will work.
At the recovery screen, type the 48-digit key (no spaces needed) and Windows boots straight to your desktop with everything intact. If it keeps returning after every restart, the underlying trigger hasn’t been resolved — usually a firmware setting. The fix is to get into Windows with the key, then either suspend BitLocker before you apply a BIOS or firmware update (it resumes automatically afterwards), or, if you no longer need encryption, turn BitLocker off to fully decrypt the drive.
Once you have the key, save it somewhere safe — back to your Microsoft account is simplest — so the next hardware change isn’t another lock-out.
There’s no backdoor — but there are still places to check.
If the key isn’t in the account you expected, it was almost certainly saved to one of the other five places above — most often a different Microsoft account. Check any address you or whoever set the PC up might have used, including a Hotmail, Outlook or Xbox login, and check other family members’ accounts.
If the machine was set up by an employer, a school or a repair shop, the key may only exist in their directory — ask them directly. And be clear-eyed about one thing: there is no legitimate tool that “removes” or “bypasses” a BitLocker key. Software promising to crack it is, without exception, malware or a scam. If every avenue is genuinely exhausted and you don’t have the key or the password, the encrypted data cannot be recovered — by anyone.
A locked drive is one problem; a failing encrypted drive is another.
Sometimes the issue isn’t the key at all — you have it, but the drive is failing, corrupt or no longer showing up, and it drops out before it can unlock. This is where a BitLocker drive becomes a data recovery job rather than a password one. We image the failing drive read-only, sector by sector, so nothing degrades further, then unlock and mount the copy using your recovery key or password — recovering the files even where the encryption metadata is damaged or the volume won’t mount normally.
What we don’t do is break the encryption: if you can’t supply the key, the password or the credentials, we’ll tell you straight rather than take the job. Where you can, our BitLocker & encrypted drive recovery service handles it in-house at a fixed £800 +VAT, with a free diagnostic and a written quote before any chargeable work — and your data never leaves the UK. If a failing drive is also clicking, overheating or undetected, power it down and send it in; every extra hour powered risks turning a recoverable drive into a lost one.
It’s a 48-digit numeric password that BitLocker generates automatically when drive encryption is switched on. It unlocks the drive when the normal method — the TPM chip, or your PIN or password — can’t run, typically after a hardware or firmware change. Each key is identified by a short Key ID.
Check, in order: your Microsoft account at aka.ms/myrecoverykey; a work or school (Azure AD) account via your IT team; a printout from setup; a USB stick holding a “BitLocker Recovery Key” text file; that same file saved to another drive or OneDrive; and, on a domain PC, on-premises Active Directory. On a personal machine it’s nearly always the Microsoft account.
It was saved somewhere else at setup — a printout, a USB text file, a file on another drive, or your organisation’s directory if the PC was set up by an employer or school. Also try any other Microsoft account (Outlook, Hotmail, Xbox) you or a family member might have used. There is no tool that bypasses the key; anything claiming to is malware.
It’s a short identifier that pairs a recovery screen with the right key. The recovery screen shows the first eight characters of the Key ID; when you have more than one saved key, you match those characters to the correct entry so you enter the key that actually unlocks that drive.
No. BitLocker is strong encryption; without the recovery key, your password or the credentials, the data cannot be decrypted by anyone, including us. If you do have the key or password but the drive has physically failed or won’t mount, that we can help with — we image it read-only and unlock the copy with your credentials.
Our BitLocker and encrypted-drive recovery is a fixed £800 +VAT, handled in-house with a free 48-hour diagnostic and a written quote before any chargeable work. That covers recovering the data from a failing or corrupt BitLocker drive where you can supply the recovery key or password — it isn’t a service for breaking encryption you can’t unlock.
If you have the recovery key but the drive has failed, or you’re not sure what you’re looking at, tell us what’s happened — you’ll get an honest answer, free, before any money changes hands.