Find your BitLocker recovery key

A BitLocker recovery screen is asking for a disk-encryption key, not the usual Windows password or PIN. Its recovery key is a 48-digit number. The key ID displayed on screen identifies which saved key you need; it is not itself the secret that unlocks the drive.

Use these steps for a device or drive you own or are authorized to manage. For an ordinary Windows sign-in prompt, use Windows account recovery. A local password reset disk cannot replace a BitLocker recovery key.

1. Record the key ID and identify who set up the device

Microsoft's BitLocker recovery article explains matching the displayed key ID to the correct saved record. Note the ID and the device involved. You can give an organization that identifier without posting the actual recovery key in a public support discussion.

Consider who originally configured the computer or enabled encryption. The key may be associated with that person's Microsoft account, an employer's systems, or a saved offline record. The Microsoft account you use most often today is not necessarily where this particular key was stored.

If the screen appeared after a hardware or startup change, record what changed before taking further action. Do not assume every blue recovery screen means the password was forgotten or that the drive is damaged. The important first task is locating the matching key.

2. Check the relevant Microsoft account

Follow the account link in Microsoft's official recovery-key instructions from another trusted device. Sign in to the account associated with the encrypted computer and compare the saved key IDs. Multiple entries can exist for different devices or encryption events.

Use the matching 48-digit recovery key on the BitLocker screen. Read groups carefully and do not confuse the account's separate recovery code with the disk key. A Microsoft password reset only helps you reach the account where a key might be stored; it does not create a missing BitLocker key.

If another person set up a device you now legitimately own, ask them to check the relevant saved record through their own account. Do not request their Microsoft password. They can follow the appropriate ownership and support process without giving you unrelated account access.

3. Ask the organization or inspect offline records

Microsoft's article lists work or school accounts, printed copies, and USB storage among possible key locations. For a managed computer, contact the IT administrator and provide the device and key ID it requests. The organization may have escrowed the recovery information.

For your personal device, check the secure place where you saved or printed the key. Match the ID before assuming the first 48-digit number you find belongs to the current screen. A drive re-encrypted later can have a different record from an older installation.

Treat a saved text file or printout as a credential that can unlock data. Keep it out of shared photo albums and public chat messages. If support needs the key itself for an authorized operation, use the organization's approved secure process rather than a convenient public channel.

4. Decide what to do if no matching key exists

Microsoft's recovery guidance says support cannot retrieve, provide, or recreate a lost key. Search the legitimate locations carefully before selecting a reset. A record for another device, an account password, or a purchase receipt does not decrypt this drive.

If the required key cannot be found and the condition triggering recovery cannot be resolved through supported guidance, resetting the device can be the remaining route to a usable system. Read the data-loss warning and check independent backups first. An erase does not recover the files from the encrypted drive.

Without the key, the encrypted data may be permanently inaccessible.

BitLocker is designed to protect the drive when normal access cannot be trusted. A third-party promise to bypass it cannot guarantee recovery. Do not overwrite the only copy of important data while merely testing a suggested fix.

After the drive unlocks

Back up important files and confirm where the current recovery key is safely stored. Keep a copy accessible without the encrypted computer itself. For a managed device, let the administrator handle any required key rotation or configuration review using Microsoft's organizational BitLocker recovery guidance. It explains retrieving stored recovery information through Microsoft Entra or Intune and reviewing why recovery was triggered.

Investigate the event that caused recovery before repeatedly changing hardware or startup settings. A successful unlock is an opportunity to verify the recovery record, not a reason to disable encryption reflexively. Label the key with its device and ID so the next request can be matched quickly without exposing the secret itself.

If you are subsequently stopped at the Windows login screen, return to the Windows guide. Unlocking the drive and signing into a user account are separate stages, and each needs the credential designed for that layer.

Instructions checked against vendor guidance on 25 September 2026.