RESOURCES · SECURITY & EMAIL

BitLocker is asking
for a recovery key?

You turn on the PC and a blue screen wants a 48-digit BitLocker recovery key before it will start. It looks alarming — but your data is safe, and you almost certainly have the key. Here's what BitLocker is, why it's asking, and exactly where to find it.

Applies to: Windows BitLocker Read: ~6 minutes Level: Everyone should read this
Quick answer

Don't reset or wipe the PC — your data is safe behind the key. Note the Recovery Key ID shown on screen, then get your 48-digit key from your Microsoft account (account.microsoft.com/devices/recoverykey), your IT team (work devices), or wherever it was saved at setup (USB or printout). Enter it to unlock.

WHY IT HAPPENS

It's a security check, not a fault.

BitLocker encrypts your drive so that if the device is lost or stolen, nobody can read your data. It asks for the recovery key when it detects a change it doesn't trust — a BIOS or firmware update, a hardware change, a Secure Boot or TPM change, or repeated failed sign-ins — as a way of checking it's really you starting the machine. Enter the key and you're straight back in; nothing has been lost.

WHERE TO FIND YOUR KEY

Work through these in order.

  1. Don't panic, and don't reset or wipeThe blue screen is scary but the data is intact behind the key. Wiping or reinstalling to "make it go away" is the one move that actually loses your files. Take a breath and find the key instead.
  2. Note the Recovery Key ID on screenThe BitLocker screen shows a short Recovery Key ID (a code). Write it down — you'll use it to match the right key, since a PC or account can have more than one.
  3. Personal / Microsoft-account device: check your accountOn your phone or another PC, go to account.microsoft.com/devices/recoverykey and sign in with the same Microsoft account. Match the Key ID and copy the matching 48-digit key.
  4. Work or school device: contact your IT teamThe key is stored in your organisation's Microsoft Entra ID / Intune. Your IT team can look it up by the Key ID and read it to you — this is the normal, correct process for a managed device.
  5. Check any USB stick or printout from setupWhen BitLocker was first turned on, the key may have been saved to a USB stick or printed out. Dig out that setup paperwork or drive if you have it.
  6. Type the 48-digit key to unlockEnter the recovery key on the BitLocker screen exactly as shown. Windows unlocks the drive and boots normally — everything is where you left it.
  7. Find out what triggered it — and prevent a repeatOnce back in, work out what set it off (a firmware update is the usual culprit). In future, suspend BitLocker before BIOS/firmware updates via the BitLocker control panel → Suspend protection, then resume after.
Never hand your recovery key to anyone who contacts you first. No legitimate support will ever cold-call or email you asking for your BitLocker recovery key — and that key unlocks all of your data. If someone rings claiming you "need" to read it out, hang up. On a managed work device your IT provider already holds the key; that is the safe, correct source to get it from.
ENCRYPTION DONE RIGHT

Encryption should protect you — not lock you out.

BitLocker is a genuinely good thing: lose a laptop and the data stays unreadable. But it only works if the keys are stored centrally and someone can retrieve them fast. Our free IT Health Check reviews how your devices are encrypted and where the keys live, so a recovery prompt is a two-minute fix — not a lost day or a lost drive.

KEEP READING

Related resources