Skip to content
Dispatching · New York Metro
(347) 262-9435
Field guide · Endpoints & data

BitLocker

What BitLocker actually protects against, why a machine suddenly asks for a recovery key when nothing was changed, and where that key should have been stored before it was needed. Covers TPM and the measured-boot triggers, the escrow options and how to verify one worked, suspending before firmware work, and what recovery looks like when the drive is pulled.

Plate 01Procedure

Doing it

What to do before the key is needed, and what recovery looks like when it already is.

Tools
  • Administrative access to the machine
  • Access to wherever keys are escrowed
  1. 01

    Know what it does and does not protect

    BitLocker protects data at rest — a drive removed from the machine, or a laptop taken while powered off. It does nothing about a running machine an attacker is already logged into, and nothing about ransomware, which encrypts files the user can legitimately reach. It is theft and disposal protection, and treating it as general security is a mistake.

  2. 02

    Understand why the prompt appears

    With a TPM, the key is released only when the boot measurements match what they were when encryption was enabled. Change the measured environment — firmware update, secure boot toggled, boot order changed, drive moved to another machine, sometimes a dock or hardware change — and the TPM withholds the key. The recovery prompt is the system working correctly, not a fault.

  3. 03

    Escrow the key before you need it, and verify it landed

    Entra ID, Active Directory, or an MDM, depending on how the estate is managed. The critical step is verification: check the key is actually visible in the directory for that specific device rather than assuming policy applied. A key that was never escrowed is indistinguishable from an escrowed one until the day it matters.

    CautionVerify per device, not per policy. A machine that was encrypted before it was enrolled frequently has no key stored anywhere.

  4. 04

    Suspend before firmware and boot changes

    Suspending protection lets the machine boot once without the key, updates the measurements, and resumes automatically. It takes seconds and it prevents the entire class of unexpected recovery prompts after a BIOS update. Any process that flashes firmware across a fleet should suspend first.

  5. 05

    Find the key by its identifier

    The recovery screen shows a key ID. Match that ID against the escrowed keys rather than searching by machine name — a device that was rebuilt or renamed can have several keys, and entering the wrong one repeatedly is how people conclude the key is missing when it is not.

  6. 06

    Recover a drive that has left its machine

    A drive pulled and attached to another machine can be unlocked with the recovery key and the right tooling, provided you have the key. Without it there is no recovery path, by design — no support call, no vendor bypass. That is the point of the product, and it is the reason escrow verification is the step that actually matters.

    CautionDo not attempt repairs on the original drive. Unlock, image the volume, and work on the image.

Plate 02Questions
Questions people actually ask
Why is BitLocker suddenly asking for a recovery key?
Because the measured boot environment changed. The usual causes are a firmware or BIOS update, secure boot being toggled, a change in boot order, the drive being moved to another machine, or occasionally a hardware or dock change. The TPM releases the key only when measurements match, so a changed environment means it withholds it and falls back to recovery.
Where is the recovery key stored?
Wherever it was escrowed when encryption was enabled — Entra ID, Active Directory, an MDM, a Microsoft account for consumer devices, or a printed or saved copy. If none of those was configured at the time, it may exist nowhere. That is why verifying escrow per device, rather than trusting that a policy applied, is the part worth doing.
Can data be recovered without the key?
No. There is no vendor bypass and no support path, and that is the design rather than an omission — a recoverable-without-key encryption product would not be an encryption product. This is exactly why escrow verification is the only meaningful protection against data loss here.
Should I suspend BitLocker before a BIOS update?
Yes, always. It takes seconds, lets the machine boot once without the key, updates the measurements and resumes on its own. Skipping it is the single most common cause of a fleet-wide wave of recovery prompts the morning after a firmware rollout.
Does BitLocker protect against ransomware?
No. Ransomware runs as a user who can already read the files, so the volume is already unlocked from its point of view. BitLocker protects data at rest against someone who has the hardware but not the credentials. Backups protect against ransomware; encryption protects against theft and improper disposal.
TPM-only or TPM with a PIN?
TPM-only unlocks transparently, which is convenient and means a stolen powered-off laptop is protected only up to the login. Adding a PIN requires something the thief does not have before the volume unlocks at all, which materially raises the bar against attacks on a machine in someone else's hands. For laptops that leave the building it is usually worth the friction.
Plate Other guides

The rest of the section

Free guidesNo sign-upNothing trackedWritten on the job
Rather it was just done

We do this work
as well as document it

Anyone facing a recovery prompt on a machine that was working yesterday, or rolling out encryption and wanting the keys to exist afterwards.

Or call and speak to someone who does the work(347) 262-9435inquiries@jcitsystems.com