Lab accepting new cases ·  Mon–Fri, 9am–5:30pm Urgent? Call 01273 964902
BDR Brighton Data Recovery 01273 964902 Start a case
BDR / How it failed / BitLocker & encrypted drives

How it failed · BitLocker & encrypted

The blue screen isn’t the problem. The missing key is.

BitLocker recovery mode is the machine doing its job: something about the hardware or firmware changed, so it demands proof it's still yours — a 48-digit key. Most 'BitLocker disasters' are key-management problems wearing a scary screen. Find the key, and the rest is engineering.

No fix, no fee on most jobs Free diagnosis & written quote Post-in from anywhere in Sussex

Talk it through with an engineer
01273 964902

What you're seeing, decoded.

Something else? Run the triage →
What you seeWhat it meansFirst move
BitLocker recovery — Enter the recovery key for this driveThe pre-boot recovery screen: the TPM won't release the key automaticallyFind the key, don't guess
Use the number keys or function keys F1–F10 (use F10 for 0).Input instruction for the 48-digit keyIt wants digits, not your password
Recovery key ID (to identify your key):An 8-character label that identifies WHICH key — it is not the key itselfMatch the ID to the right key
For more information go to: aka.ms/recoverykeyfaqMicrosoft's default hint URLThe real key lives in your account
BitLocker waiting for activationEncryption enabled but protection suspendedNot locked — but not protected
Drive both encrypted AND failingHardware fault underneath the encryptionImage first, decrypt second
Getting it to us: post your device tracked and fully insured to our secure intake lab — free return postage — or start by phone and we'll walk you through packing it. Sending details are on the contact page.

Where your 48-digit key lives.

Personal Microsoft accountSign in at aka.ms/myrecoverykey from any device — keys back up there automatically on most consumer machines.
Work or school accountaka.ms/aadrecoverykey, signed in with your work identity — Entra ID escrows keys for managed devices.
Your company's ITActive Directory and Intune both escrow keys on managed fleets — the Recovery Key ID on your screen is exactly what IT needs to find it.
Paper, USB or a fileThe printout or BitLockerRecoveryKey…TXT you were prompted to save at setup. It exists more often than people remember.

How we recover it, stage by stage.

See recent recoveries →
01

Booked in, diagnosed free Free

Your device is logged with its own case reference the moment it arrives. An engineer assesses the fault, confirms what's actually recoverable, and you get a fixed price in writing — no diagnosis fee, no obligation, and no paid work until you say go.

Free diagnosisFixed written quoteNo obligation
02

Find the key first

The Recovery Key ID on screen is matched to the actual 48-digit key — via your Microsoft or work account, IT's escrow, or that printout. No key means no data, for anyone, by design; so this comes before all engineering.

ID matched to keyEvery escrow checked
03

Stabilise and image

Where the drive is also failing, it's imaged in full first — encrypted sectors and all — so the decryption never has to run against dying hardware.

Encrypted image takenHardware risk removed
04

Decrypt and repair on the copy

With the key, the volume is unlocked on the image; where BitLocker's own metadata is damaged, Microsoft's repair-bde pathway rebuilds it onto fresh media.

repair-bde on the copyRecovered to new media
05

Verified, returned, signed off

Before you pay the recovery fee you approve a full listing of what came back. Your data returns on new media with free return postage, and the case only closes once you've confirmed everything opens on your side.

File listing approvalNew media includedFree return postage

What the lab checks first

  • The ID is not the key — the 8-character Recovery Key ID only identifies which 48-digit key you need. Reading it out to IT is exactly how they find yours.
  • July 2024 proved the point twice — a Windows update tipped machines into recovery mode, and days later the CrowdStrike outage (8.5 million devices, per Microsoft) forced organisations everywhere to type recovery keys they'd never escrowed.
  • repair-bde exists for the ugly cases — when BitLocker's own metadata corrupts, Microsoft's repair tool can rebuild the volume onto another disk, provided the key is known.
  • Encrypted + failing = image first — decryption is heavy sustained reading, the worst possible workload for a dying drive.

The uncomfortable, useful truth: BitLocker without its 48-digit key is unrecoverable by design — Microsoft's documentation says so and so do we. Which turns the real task into a key hunt: personal account, work account, IT escrow, paper. In our cases, when the key exists anywhere, the data comes back; when it truly doesn't, no honest lab can help — and we'll tell you that for free rather than charge you to discover it.

From the casebook.

EX · BDR-2026-0642VERIFIED ✓

A Hove architect's workstation, locked by its own BIOS update

A firmware update changed the TPM's measurements overnight and the machine demanded a key nobody had written down. The Recovery Key ID led to the practice's Entra ID escrow; damaged BitLocker metadata was rebuilt with repair-bde onto a new drive, and every project file survived.

100% recovered3 days in lab

Before it reaches us.

Do

  • Note the Recovery Key ID exactly as shown
  • Check aka.ms/myrecoverykey and aka.ms/aadrecoverykey
  • Ask IT — AD and Intune escrow keys on managed machines
  • Hunt the printout or saved .TXT from setup

Don't

  • Guess repeatedly at 48 digits
  • Reinstall Windows to 'clear' the screen — that destroys the data
  • Confuse the 8-character key ID with the key itself
  • Format the drive because it's 'locked anyway'

Asked on this bench, answered honestly.

How do I find my BitLocker recovery key?

Check your Microsoft account at aka.ms/myrecoverykey, your work or school account at aka.ms/aadrecoverykey, your IT team's Active Directory or Intune escrow, or the printout or text file you saved at setup — and match it by the Recovery Key ID on screen.

Can BitLocker data be recovered without the key?

No — not by us, not by Microsoft, not by anyone. That's the product working as designed. The recoverable cases are the ones where the key exists somewhere and the drive or metadata is the problem.

Why did my PC suddenly ask for the key?

Something the TPM measures changed: a BIOS or firmware update, a Secure Boot change, a motherboard repair, moving the drive to another machine — or a Windows update, as happened at scale in July 2024.

My encrypted drive is also failing — what order do things happen in?

Image first, decrypt second. The full encrypted drive is imaged so the unlock runs against a healthy copy — a dying drive should never be asked to decrypt itself.

Whatever's failed, don't power it on again.

Every restart of a damaged device costs data. Open a case first — the diagnosis is free either way.

01273 964902