Same Day IT

Guide · BitLocker lockout

BitLocker recovery key not found: where your key actually is

Your recovery key almost certainly exists. Windows does not turn BitLocker on without saving that key somewhere, the trick is knowing everywhere it might be stashed. Work this list from your phone before you panic, and definitely before you let anyone wipe the machine.

Last updated 14 August 2026 · by Alien IT Solutions

First, the short version

The blue recovery screen means the drive is locked, not lost. Your files are sitting there encrypted and intact, waiting for a 48-digit key that was saved somewhere the moment the drive was encrypted. Most people find it in under ten minutes once they know where to look, and it is usually in a Microsoft account.

So do not reformat, do not let a shop talk you into a rebuild yet, and stop guessing passwords, the recovery key is not a password. Grab your phone and work through the locations below, most likely first.

There are only three ways this ends. You find the key and everything comes back, which is the usual outcome. Someone else holds it, an employer, a school or the person who set the machine up, and you ask them. Or the key is genuinely gone, in which case the files are unrecoverable by anyone, at any price, and the only honest path is a wipe and reinstall. No service, lab or tool can bypass a lost BitLocker key. Anyone who says otherwise is selling you something that does not exist.

Start here: which situation are you in

Four branches, and they lead to different places. Find yours before you start hunting, it saves the wrong search.

! A personal laptop you set up yourself

Your key is almost certainly in a Microsoft account, even if you never chose to put it there. Go straight to the Microsoft account check below. If you have several accounts, and most people do, check every one of them.

! A work, school or university machine

Do not hunt at all, ask. The key is held centrally in the organisation's system and reading it out is a one-minute job for their IT team. This is true even for a machine you have had at home for years.

! Second-hand, inherited, or set up by someone else

The key went to whoever was signed in when encryption started, not to you. That means the previous owner, the relative, or the shop that supplied it. Windows 11 can tell you which account to chase, see the account hint below.

! Nobody has it, and every account is a dead end

Read the honest section further down before you spend a cent. The answer there is uncomfortable, but it will stop you paying someone to do something that is not possible.

Why it is suddenly demanding a key

BitLocker ties the drive to a security chip in your machine, the TPM. When the machine looks different to that chip at startup, it refuses to unlock and asks for the recovery key instead. That is the feature working, not breaking. The usual triggers:

BIOS or firmware updates

The most common one. The manufacturer pushes a firmware update, the machine restarts, and to the TPM it now looks like different hardware. Up comes the blue screen.

Windows updates

Some updates touch the boot chain. The measurements the TPM checks at startup no longer match, so it plays it safe and demands the key.

Motherboard or TPM repairs

A board swap or TPM replacement means the drive is now paired to a chip it has never met. Normal after a repair, and exactly when you need the key.

Boot and hardware changes

A new dock, a changed boot order, an added drive, even some USB gear plugged in at startup. Anything that changes how the machine starts can trip it.

Microsoft publishes the full list, and some entries surprise people: docking or undocking a laptop, having a CD or DVD drive ahead of the hard drive in the boot order, changes to the boot manager or the partition table, clearing or disabling the TPM, a TPM self-test failure, moving the drive into a different computer, booting over the network, and entering the wrong PIN too many times. See Microsoft's BitLocker recovery overview for the complete set. The pattern behind all of them is the same: the machine no longer looks the way it did when the drive was locked.

Nobody turned BitLocker on. Windows did.

This is the part that catches most people out, and it is why the recovery screen feels like it came from nowhere. You never opened a menu and chose to encrypt anything. Windows did it in the background, the day the machine was set up.

The feature is called device encryption. On machines that qualify, it turns BitLocker on automatically as soon as first-time setup finishes, and it backs the recovery key up on its own to whichever account was signed in at the time. That might be a personal Microsoft account, or a work or school account. Nobody is told, because from Microsoft's point of view nothing has gone wrong, the drive is protected.

It also got much more common recently. Device encryption used to require particular hardware features, which left a lot of machines unencrypted. Microsoft removed those prerequisites in Windows 11 version 24H2, so far more new and freshly reinstalled PCs now encrypt themselves from day one. If your machine is recent, assume it is encrypted whether or not you asked for it.

Two practical consequences. First, the key exists, which is good news, you just have to work out which account received it. Second, it is on the built-in drive only. Device encryption covers the Windows drive and other fixed drives inside the machine, and does not touch USB sticks or external drives, so anything you copied off is unaffected.

Where the key actually lives, in order of likelihood

Work down this checklist from any device that still works, a phone is fine. You are hunting a 48-digit number. Tick each one off rather than jumping around, because the common mistake is to give up at step one when the key is sitting at step two.

0. Read the recovery screen first

Before you go anywhere, look at the locked machine itself. The screen shows a recovery key ID, which you will need to match later. On Windows 11 version 24H2 and newer it also shows a hint of the Microsoft account the key was saved to, usually a partly hidden email address. That hint turns the entire hunt into a single sign-in. Photograph the screen so you have the ID and the hint with you.

1. Your Microsoft account

Go to account.microsoft.com/devices/recoverykey, which Microsoft also publishes as the short link aka.ms/myrecoverykey, and sign in with the same Microsoft account you use to log in to that machine. On most home and small business machines Windows saved the key here automatically, and this is where the hunt usually ends. Two things people miss: check every Microsoft account you own, not just the obvious one, and check the account of whoever originally set the machine up, because the key lands in whichever account was signed in when BitLocker went on.

2. Your work or school account

If an employer or a school set the laptop up, the key is almost certainly held in their system, Microsoft calls it Entra ID (previously Azure AD). Ask IT. It is a one-minute lookup, and holding your key is exactly what that system is for.

3. A printout or a USB stick from setup

When someone turns BitLocker on manually, Windows makes them save the key as a printout, a file or a USB stick. Check wherever the paperwork from the machine's purchase lives, and any old USB sticks in that drawer. You are looking for a small text file named BitLocker Recovery Key followed by a long ID.

4. Your OneDrive

Sign in to OneDrive in a browser and search for BitLocker. Keys sometimes sit in a saved recovery file there rather than showing on the devices page. While you are at it, search your email for BitLocker too, plenty of people have mailed the key to themselves and forgotten.

5. Active Directory, for a machine on a company domain

An older office machine joined to a Windows domain stores its key in Active Directory itself, attached to that computer's record rather than to any person. IT reads it from the BitLocker Recovery tab on the computer object. Worth knowing if you are the one looking: Active Directory keeps the history of every key that machine has ever had, and old keys are not tidied away unless the computer record is deleted. So even a machine that has been re-encrypted since is usually still covered.

6. Whoever supplied or manages the machine

If a reseller, managed IT provider or a hire company set the laptop up, they may hold the key in their own management system, so ask them before you give up. Be clear about what the manufacturer can and cannot do, though. Dell, HP, Lenovo and the rest cannot look up your recovery key from a serial number. The key is generated on your machine and escrowed to your account, never to theirs, which is why their support pages send you back to your Microsoft account. Ringing the manufacturer is the most common wasted hour in this process.

What you are looking for

A BitLocker recovery key is 48 digits in eight groups of six, numbers only: 123456-123456-123456 and so on. It is not your password, not your PIN, and there are no letters in it. The recovery screen also shows a recovery key ID, a short code identifying which key the machine wants. If you find more than one saved key, match the ID on the screen to the ID stored next to each key. If the IDs do not match, it is the wrong key.

If the key is in an account you cannot get into

This is the situation the standard advice skips, and it is the one we are called about most. The key exists, you know roughly where it is, and you cannot reach the account holding it. The branch you are on decides whether it is recoverable.

An old employer. Ask them anyway, and ask specifically for the BitLocker recovery key for the device, not for access to your account. Their IT team can read it out of Entra ID or Active Directory without touching your old mailbox, because the key is stored against the machine. If the laptop was genuinely yours, say so plainly and be ready to show the purchase. Most IT teams will help, this is a routine request.

A school or university. Same path, through the IT service desk, and the same fact applies after you have graduated. Student accounts are often closed long before the machine is retired, so lead with the device serial number rather than your student number.

A Microsoft account you cannot sign in to. Work the account recovery first, because there is no way to extract a key without getting into the account. If two-factor is the blocker and you still have the recovery codes or a signed-in phone, use those before anything else. Do not create a new account with the same name hoping the key follows, it will not, keys are tied to the account that received them.

A relative who has died. Handled through the account provider's deceased-estate process with the death certificate and proof you are the executor, not through a repair shop. Expect it to take weeks. If the machine is needed sooner, take the drive out of the equation and work from whatever backups, cloud accounts or printed records exist.

A business that no longer exists. This is the hard one. If the company wound up and its Microsoft tenant was deleted, the escrowed key went with it. Try the former IT provider, who may still hold records, and any director who managed the account. If that comes back empty, treat it as gone and read the next section.

If the key is genuinely gone

Straight answer: without the key, the data on that drive is unreachable. Not hidden, not tricky, cryptographically unreachable. That is the entire point of BitLocker. If a stolen laptop could be cracked open at a repair bench, the encryption would be worthless. There is no back door, and nobody is brute-forcing modern AES encryption, not a repair shop, not a data recovery lab, not anyone.

We would rather say that plainly than leave you hoping, because the hope is what gets people's money taken. There is no service to buy here. If every location above is a dead end, the files are gone, and the sooner you accept that the sooner you can get on with replacing what you can.

So be very wary of anyone who says they can crack BitLocker for a fee. They cannot. They will either reinstall Windows and hand you back an empty machine, or take your money and stall. The tells are consistent, and any one of them should end the conversation:

  • Any claim to "crack", "bypass", "decrypt" or "brute force" BitLocker without the key.
  • A quoted price and a success rate for something that is mathematically impossible.
  • Software downloads promising to remove BitLocker from a locked drive.
  • Payment up front, in crypto or by bank transfer, before anything is examined.
  • Pressure to act now, or a warning that the data expires. Encrypted data does not decay.

What a reinstall does get you is the machine. Wipe the drive, reinstall Windows, and the hardware is back in service today. Your files come back only if a copy exists somewhere else, a backup drive, OneDrive, email attachments, a work server. Before you accept that, check every location above one more time. In eighteen years of doing this we have found the key far more often than not, usually in a Microsoft account the owner forgot existed.

On a Mac, it is FileVault, and the rules are the same

Macs encrypt the disk too, using a feature called FileVault, and people get locked out of one by the same route. If you are hunting a FileVault recovery key rather than a BitLocker one, the shape of the problem does not change, only the places to look.

When FileVault is switched on, macOS makes you pick one of two ways to get back in if you ever forget your password. Either your iCloud account unlocks the disk, which is the option most people take because there is nothing to keep track of, or macOS generates a recovery key, a string of letters and numbers, and you keep a copy yourself. A workplace or school can also hold its own key for a Mac it manages, so if the machine came from an employer, ask them first.

That gives you the same checklist: try the iCloud account tied to the Mac, including any older Apple Account the original owner used, then look for a printed or photographed recovery key wherever the machine's paperwork lives, then ask the organisation if it is a work or school Mac.

The hard truth carries across too. Apple's own warning is about as blunt as vendor documentation gets: forget the login password and the recovery key, and your files and settings are lost forever. No lab or fee changes that. Apple cannot unlock it either, which surprises people who assume the manufacturer keeps a spare.

Do this today, while your machine still boots

Reading this before a lockout? Five minutes now makes the whole problem disappear.

Confirm your key exists

From any browser, sign in at account.microsoft.com/devices/recoverykey and check a key is listed for your machine. Listed means covered, firmware updates, board swaps, the lot.

Save a second copy

On the machine, search Manage BitLocker in the Start menu and choose Back up your recovery key. Print it and file it with the passports. Paper does not get hacked, and does not get lost in a dead account.

Running a business? Escrow it

More than a couple of machines means keys belong in a management system that captures them automatically, not in a drawer. Then a lockout is a two-minute lookup, not a lost day.

One locked laptop is a warning shot

If a single BitLocker prompt cost you this morning, picture a firmware update rolling out to every machine in the office overnight. Fleets need key escrow: every drive's recovery key captured automatically the moment it is encrypted, readable by IT the moment it is needed. Sticky notes and spreadsheets do not survive contact with a real lockout. Same Day IT is the emergency arm of Alien IT Solutions, 18 years in Sydney business IT. We get you back in today where the key exists, we are straight with you where it does not, and then we set up escrow and real backups so it never bites again.

Questions people ask

Why is my laptop suddenly asking for a BitLocker recovery key?

Because the machine looks different to the security chip (the TPM) that normally unlocks the drive. BIOS and firmware updates, some Windows updates, a replaced motherboard, or a change to boot hardware can all trigger it. It is a security feature doing its job, not a fault, and your data is still intact behind it.

Where is my BitLocker recovery key?

Check in this order: your Microsoft account at account.microsoft.com/devices/recoverykey, your work or school account (ask IT), a printout or USB stick from when the machine was set up, your OneDrive, and for business machines the company's management system. On most home machines it is in the Microsoft account.

What does a BitLocker recovery key look like?

48 digits in eight groups of six, numbers only, like 123456-123456 and so on. It is not your password or PIN. The recovery screen also shows a key ID. If you have several saved keys, match the ID on the screen to the ID next to the saved key, otherwise the key will not work.

Can a repair shop unlock BitLocker without the recovery key?

No. BitLocker is full disk encryption with no back door, and without the key the data is mathematically out of reach. Anyone who claims they can crack it for a fee is selling snake oil. A shop can reinstall Windows and give you back a working machine, but that wipes the drive.

Will reinstalling Windows get my files back?

No. A reinstall wipes the encrypted drive and gives you back a working computer, not the data. Your files only come back if a copy exists somewhere else, like a backup drive, OneDrive, email, or a work server. That is why it is worth exhausting every key location first.

How do I stop this happening again?

Find your key today, while the machine still boots. Confirm it is listed in your Microsoft account, then keep a second copy: search Manage BitLocker in the Start menu and use Back up your recovery key. Businesses should escrow every machine's key automatically in their management system, not on sticky notes.

Did Windows 11 turn on BitLocker without telling me?

Quite possibly. Windows device encryption switches BitLocker on by itself on qualifying machines, and from Windows 11 version 24H2 Microsoft removed the hardware prerequisites that used to limit which machines qualified, so far more new and freshly installed PCs are encrypted from day one. The key is saved automatically to whichever account was signed in, a personal Microsoft account, or a work or school account. Nobody clicked anything, which is exactly why the recovery screen comes as a shock.

Which Microsoft account is my recovery key in?

From Windows 11 version 24H2 the recovery screen itself shows a hint of the Microsoft account the key belongs to, so read the screen before you start guessing. Then sign in to that account at aka.ms/myrecoverykey. On older versions there is no hint, so check every Microsoft account you have used on that machine, including the account of whoever set it up.

The key is in an old work or school account I cannot access. What now?

Ask the organisation, even if you have left. Their IT team can usually still read the key out of Microsoft Entra ID or Active Directory, because it is stored against the device, not against your login, and Active Directory keeps the history of old keys too. Be ready to prove the machine is yours. If the business has closed and the tenant is gone, or the computer record was deleted, the key may be genuinely unrecoverable.

Does my laptop's manufacturer have a copy of my BitLocker key?

No. Dell, HP, Lenovo and the rest cannot look up a recovery key from a serial number, because the key is generated on your machine and saved to your account, not to theirs. Their support pages exist to send you back to your own Microsoft account. The exception is a business machine supplied and managed by an IT provider or reseller, who may hold it in their management system.

What is the Mac equivalent, and does the same apply?

FileVault, and yes. When FileVault is switched on you choose either to unlock the disk with your iCloud account or to keep a recovery key yourself, and a workplace can hold its own key. Apple's warning is blunt: forget the login password and the recovery key and your files and settings are lost forever. Neither platform has a back door.

Locked out and the day is stopping?

Get a real technician working through every key location with you, remotely, in minutes. If the key exists we will find it. If it does not, we will tell you straight and get the machine back in service.