Security Guides
Asked for a BitLocker recovery key? How to find the 48-digit key, and what you can do if you can't
Windows is asking for a BitLocker recovery key (48 digits) at startup. How to find it, based on Microsoft's official guidance: the Microsoft account page, work or school PCs, printouts and USB drives, matching the key ID on screen, options if you can't find it, and backing it up now.
For: anyone whose Windows PC started up to a blue "BitLocker recovery" screen asking for a 48-digit recovery key, and anyone who wants to check where their key is before that happens. This article is based on Microsoft's official guidance (Microsoft Support and Microsoft Learn).
If the recovery screen is in front of you now
Write down the first 8 digits of the recovery key ID shown on the screen, then use your phone or another computer to check the places listed under "Where to look" below. Your PC isn't broken: once you enter the key, it starts normally.
Why Windows is asking for the recovery key
BitLocker works with the TPM (Trusted Platform Module, a chip that stores encryption keys securely) to check, at every startup, that it is the same PC going through the same startup sequence as before. If something differs, the drive may have been stolen and be opened somewhere else, so BitLocker won't unlock it automatically and asks for the recovery key instead. This is the protection working, not a fault.
Microsoft Learn lists common events that put a device into BitLocker recovery, including these:
| Trigger | Examples |
|---|---|
| Firmware updates | Updating the BIOS or UEFI (the low-level software that starts the PC) |
| TPM changes | Turning off or clearing the TPM, a TPM self-test failure |
| Hardware changes | Replacing the motherboard, moving the drive to another computer |
| Boot configuration changes | Changing the boot order, booting from USB or CD/DVD, changes to the boot manager |
| Docking | Docking or undocking a laptop |
| Failed entry | Entering the startup PIN wrongly too many times |
Suspending protection prevents this before a planned BIOS update
Microsoft Learn says that for planned work such as hardware or firmware upgrades, you can avoid recovery by suspending BitLocker protection temporarily. The drive stays fully encrypted while protection is suspended, and protection resumes automatically when the PC restarts.
Where to look for the recovery key
The recovery key is not stored on the PC itself (if it were, a thief would have it too). Where to look depends on the kind of account the PC used.
| Your PC | Look here first |
|---|---|
| Home PC signed in with a Microsoft account | https://aka.ms/myrecoverykey, with the same account |
| PC first set up by a family member or a shop | That person's Microsoft account |
| PC from your employer or school | https://aka.ms/aadrecoverykey, or the IT department |
| PC joined to a company network (Active Directory) | The IT department (admins can look it up on the company's servers) |
| PC where you turned on BitLocker yourself | A printout, or the USB flash drive or file you saved |
Write down the recovery key ID
Microsoft Support says to note the first 8 digits of the recovery key ID when you're asked for a key. If several keys are stored, these 8 digits tell you which one belongs to this drive.
Personal PC: open your Microsoft account page
On a phone or another computer, open https://aka.ms/myrecoverykey and sign in with the Microsoft account you used on the PC. The saved recovery keys are listed with their key IDs. Starting with Windows 11, version 24H2, the recovery screen also shows a hint of the Microsoft account the key is associated with.
Work or school PC: your work account or IT
Sign in at https://aka.ms/aadrecoverykey with your work or school account, select Devices, expand the PC and choose View BitLocker Keys. If nothing shows up, or the PC is managed on a company network, contact your IT department or help desk. The key is stored in Microsoft Entra ID (the organization's account system) or Active Directory, where administrators can retrieve it.
Check printouts and USB drives
If you printed the key when you turned BitLocker on, it may be with your important papers. If you saved it to a USB flash drive, plug that into the locked PC and follow the instructions. You can also open the drive on another computer and read the key from the text file.
Match the key ID on screen to the right key
Recovery screen on the PC
Box to enter the recovery key (48 digits)
Recovery key ID: 1A2B3C4D-xxxx-…
Recovery keys in your Microsoft account
Key ID: 9F8E7D6C… / another PC's key
Key ID: 1A2B3C4D… / enter this one
The recovery key is a 48-digit number. It's common to see several keys in one account — from a previous PC, or from keys that were recreated over time. Choose by the first 8 digits of the key ID, not by date or device name.
If you can't find the recovery key
To be clear up front: Microsoft says its support cannot retrieve, provide or recreate a lost BitLocker recovery key. Without the key, there is no way to read the encrypted drive. That is exactly how it protects a stolen PC.
Check every account you might have used
Try your other Microsoft accounts, the account of the family member who first set up the PC, and any work account. If the PC belongs to your employer or school, stop and contact the IT department.
Try undoing the last change
Microsoft Support says a reset is needed if you can't find the key and can't undo the change that required it. So if you can undo the change, try that first: unplug a USB device you just connected, reconnect a dock you removed, or put back BIOS/UEFI boot order or TPM settings you changed yourself.
Last resort: reset the PC
If the drive still won't unlock, reset the PC using Windows recovery options. This removes all files on the drive. Files that had already synced to OneDrive or another cloud service are still in the cloud. After the reset, use the steps below to confirm where your new recovery key is stored.
Don't rely on tools or services that 'unlock BitLocker without the key'
Searching turns up software and paid services claiming to unlock BitLocker without a recovery key. Since Microsoft itself says it can't recreate a recovery key, anything promising to open a properly encrypted drive without the key is not credible. You may pay and still not get in, and you add the risk of installing dubious software or handing your drive to strangers. If you consult a professional data recovery company, confirm the cost and terms first, on the understanding that the data can't be read without the key.
Back up your recovery key now
Now, while no recovery screen is showing, is the easiest time to check. The steps depend on whether you have Device encryption on Windows Home or BitLocker on Pro and above. The differences between the two are covered in BitLocker vs Device encryption.
| Edition | How to check and back up the key |
|---|---|
| Windows 11/10 Home (Device encryption) | Go to Settings > Privacy & security > Device encryption to see whether it's on. If it was turned on when you signed in with a Microsoft account, the recovery key is attached to that account automatically, so check that it actually appears at https://aka.ms/myrecoverykey. With a local account (signing in without a Microsoft account), Device encryption is not turned on automatically |
| Windows 11/10 Pro, Enterprise, Education (BitLocker) | Type BitLocker in Start and open Manage BitLocker. Select Back up your recovery key next to the drive, then choose Save to your Microsoft account, Save to a USB flash drive, Save to a file, or Print the recovery key |
| Command line (administrator) | In a terminal opened as administrator, run manage-bde -protectors -get C: to list the key protectors on drive C with their IDs, including the 48-digit recovery password |
Microsoft gives these cautions when saving the key:
- Don't keep the USB flash drive or printout with the key alongside the PC (a thief who takes both can get past the encryption)
- You can't save the key file to a drive that is itself encrypted with BitLocker
- If you save it as a file, keep it in OneDrive Personal Vault (an area that needs extra identity verification), so you can reach it from any device
This site's view: most people didn't know their PC was encrypted
Most people stuck at the recovery screen didn't know their PC was encrypted at all. Recent versions of Windows turn on Device encryption automatically on supported PCs when you sign in with a Microsoft account. The encryption itself is valuable — it protects your data if the PC is lost — and there's no need to turn it off.
What's missing is checking, once, where the key is. Open https://aka.ms/myrecoverykey and see whether the PC you use now is listed with a key. That turns the recovery screen from a crisis into a few minutes of typing. It's also worth checking family PCs: is the key in the account of whoever set them up?
Calls or messages asking for your recovery key are scams
How the scam works
- Someone claiming to be "Microsoft support" asks for your recovery key by phone or message
- They offer to "reissue" the key or "unlock it for you", then ask for payment or remote access
- A screen tells you to call a phone number
What Microsoft actually does
- Doesn't make unsolicited calls or send unsolicited emails to fix your computer
- Never puts phone numbers in its error or warning messages
- Has no way to retrieve or recreate a lost recovery key
The recovery key is the last key to everything on the drive. Anyone who has it and your PC can read your data. You type the key in yourself; you never need to say it out loud or send it to anyone. Even when checking with IT about a work PC, contact the official internal help desk yourself. Fake warning screens with phone numbers are covered in how to close a "your PC is infected" fake warning.
Sources
- Microsoft Support: Find your BitLocker recovery key — support.microsoft.com
- Microsoft Support: Back up your BitLocker recovery key — support.microsoft.com
- Microsoft Support: Device encryption in Windows — support.microsoft.com
- Microsoft Learn: BitLocker recovery overview (common recovery triggers, recovery options, suspending protection) — learn.microsoft.com
- Microsoft Learn: manage-bde protectors — learn.microsoft.com
- Microsoft Support: Protect yourself from tech support scams — support.microsoft.com
Read next
- Term: What is BitLocker? (disk encryption)
- The difference: BitLocker vs Device encryption
- Preparation: Backup essentials (the 3-2-1 rule) / Securing a laptop you carry around
- Scams: "Your PC is infected" fake warnings (tech support scams)
FAQ
QWhere can I find my BitLocker recovery key?
If the PC is personal and you use a Microsoft account, open https://aka.ms/myrecoverykey on another phone or PC and sign in with the same Microsoft account to see the saved recovery keys. For a work or school PC, sign in at https://aka.ms/aadrecoverykey with your work or school account, select Devices, expand the PC and choose View BitLocker Keys, or ask your IT department. The key may also be on a printout or a USB flash drive you saved when BitLocker was turned on.
QI have several recovery keys. Which one do I enter?
Write down the first 8 digits of the recovery key ID shown on the recovery screen, then compare them with the key IDs listed on your Microsoft account page or wherever the keys are stored. The 48-digit number on the row whose ID matches is the key for that drive.
QMy Microsoft account page doesn't show a recovery key.
If someone else first set up the PC — a family member or a shop, for example — the key may be in their Microsoft account. Starting with Windows 11, version 24H2, the recovery screen shows a hint of the Microsoft account the key is associated with. If the PC came from your employer or school, check with the IT department.
QIf I can't find the recovery key, can I get my data back?
Microsoft says its support cannot retrieve, provide or recreate a lost BitLocker recovery key. If you can't find the key and can't undo the change that triggered recovery (such as a device you removed or a setting you changed), the remaining option is to reset the device with Windows recovery options, which removes all files. Don't rely on tools or services that claim to unlock BitLocker without the key.
QHow do I back up my recovery key?
With BitLocker on Windows Pro and above, type BitLocker in Start, open Manage BitLocker, choose Back up your recovery key next to the drive, and pick Save to your Microsoft account, Save to a USB flash drive, Save to a file or Print the recovery key. With Device encryption on Windows Home, the key is attached to your Microsoft account automatically when encryption was turned on by signing in with that account, so check that it actually appears at https://aka.ms/myrecoverykey.
QSomeone claiming to be Microsoft support asked me for my recovery key.
Don't give it. Microsoft says it does not make unsolicited phone calls or send unsolicited emails to request personal information or to offer to fix your computer. Anyone who has your recovery key and your PC can read the drive. You type the key in yourself; you never need to tell it to anyone.