BitLocker
What BitLocker actually protects against, why a machine suddenly asks for a recovery key when nothing was changed, and where that key should have been stored before it was needed. Covers TPM and the measured-boot triggers, the escrow options and how to verify one worked, suspending before firmware work, and what recovery looks like when the drive is pulled.
Doing it
What to do before the key is needed, and what recovery looks like when it already is.
- Administrative access to the machine
- Access to wherever keys are escrowed
- 01
Know what it does and does not protect
BitLocker protects data at rest — a drive removed from the machine, or a laptop taken while powered off. It does nothing about a running machine an attacker is already logged into, and nothing about ransomware, which encrypts files the user can legitimately reach. It is theft and disposal protection, and treating it as general security is a mistake.
- 02
Understand why the prompt appears
With a TPM, the key is released only when the boot measurements match what they were when encryption was enabled. Change the measured environment — firmware update, secure boot toggled, boot order changed, drive moved to another machine, sometimes a dock or hardware change — and the TPM withholds the key. The recovery prompt is the system working correctly, not a fault.
- 03
Escrow the key before you need it, and verify it landed
Entra ID, Active Directory, or an MDM, depending on how the estate is managed. The critical step is verification: check the key is actually visible in the directory for that specific device rather than assuming policy applied. A key that was never escrowed is indistinguishable from an escrowed one until the day it matters.
CautionVerify per device, not per policy. A machine that was encrypted before it was enrolled frequently has no key stored anywhere.
- 04
Suspend before firmware and boot changes
Suspending protection lets the machine boot once without the key, updates the measurements, and resumes automatically. It takes seconds and it prevents the entire class of unexpected recovery prompts after a BIOS update. Any process that flashes firmware across a fleet should suspend first.
- 05
Find the key by its identifier
The recovery screen shows a key ID. Match that ID against the escrowed keys rather than searching by machine name — a device that was rebuilt or renamed can have several keys, and entering the wrong one repeatedly is how people conclude the key is missing when it is not.
- 06
Recover a drive that has left its machine
A drive pulled and attached to another machine can be unlocked with the recovery key and the right tooling, provided you have the key. Without it there is no recovery path, by design — no support call, no vendor bypass. That is the point of the product, and it is the reason escrow verification is the step that actually matters.
CautionDo not attempt repairs on the original drive. Unlock, image the volume, and work on the image.
- Why is BitLocker suddenly asking for a recovery key?
- Because the measured boot environment changed. The usual causes are a firmware or BIOS update, secure boot being toggled, a change in boot order, the drive being moved to another machine, or occasionally a hardware or dock change. The TPM releases the key only when measurements match, so a changed environment means it withholds it and falls back to recovery.
- Where is the recovery key stored?
- Wherever it was escrowed when encryption was enabled — Entra ID, Active Directory, an MDM, a Microsoft account for consumer devices, or a printed or saved copy. If none of those was configured at the time, it may exist nowhere. That is why verifying escrow per device, rather than trusting that a policy applied, is the part worth doing.
- Can data be recovered without the key?
- No. There is no vendor bypass and no support path, and that is the design rather than an omission — a recoverable-without-key encryption product would not be an encryption product. This is exactly why escrow verification is the only meaningful protection against data loss here.
- Should I suspend BitLocker before a BIOS update?
- Yes, always. It takes seconds, lets the machine boot once without the key, updates the measurements and resumes on its own. Skipping it is the single most common cause of a fleet-wide wave of recovery prompts the morning after a firmware rollout.
- Does BitLocker protect against ransomware?
- No. Ransomware runs as a user who can already read the files, so the volume is already unlocked from its point of view. BitLocker protects data at rest against someone who has the hardware but not the credentials. Backups protect against ransomware; encryption protects against theft and improper disposal.
- TPM-only or TPM with a PIN?
- TPM-only unlocks transparently, which is convenient and means a stolen powered-off laptop is protected only up to the login. Adding a PIN requires something the thief does not have before the volume unlocks at all, which materially raises the bar against attacks on a machine in someone else's hands. For laptops that leave the building it is usually worth the friction.
The rest of the section
- 01RJ45 Wiring: T568A and T568BBoth colour codes, pin by pin, side by side.
- 02RJ11 Wiring and Phone PinoutsSix positions, three lines, two colour systems.
- 03Keystone Jack TerminationStrip, seat, punch, snap — without failing the certification.
- 0466 Block WiringFifty rows, four columns, and where the bridging clips go.
- 05110 Block WiringLay the pairs in, press the connecting block on.
- 06Cat5e vs Cat6 vs Cat6a vs Cat8Speed, distance, and power decide it — not the bigger number.
- 07Fibre Types, Connectors and PolishRead the jacket, read the connector, don't mate blue to green.
- 08Subnetting, ExplainedWhere the numbers come from, and the meaning behind them.
- 09PoE Standards and Why It Won't PowerThe switch reserves the class, not the draw.
- 10Camera Lens, Field of View and Pixel DensityCovering the room is not the same as identifying a face in it.
- 11Patch Panels and Labelling to TIA-606A label that survives is worth more than a tidy rack.
- 12Rack Planning: Units, Depth, Weight and HeatIt fits vertically. That was never the hard part.
- 13Writing a Switch ConfigurationFrom factory default to a switch you would hand over.
- 14Networking and Cabling GlossaryThe terms, and what they mean on a job.
- 15POTS to VoIP: What BreaksThe lines nobody remembers until they stop working.
- 16Testing an Analogue Phone LineTip, ring, and the four numbers that tell you whose fault it is.
- 17Toning and Tracing a CableFinding one pair in a bundle of two hundred.
- 18Reading a Cable Certifier ReportWhat PASS* actually means, and which number to look at first.
- 19Which Cable Tester Do You Need?Three tiers, and the one most people actually need.
- 20Running an Office Floor RestackEveryone sits down Monday and their machine works.
- 21Cable Management for Desks and RacksTidy is a by-product. Serviceable is the point.
- 22Asset Tagging and CMDB AuditsThe scan is easy. Scanning it into the right record is the job.
- 23Cabling an Office Fit-OutHow many drops, run where, and what it takes to add one later.
- 24Parcel Locker Site SurveysWhether the unit fits, powers, connects — and gets in the door.
- 25VLANs and TrunkingAccess, trunk, tagged, native — and which one is the security hole.
- 26Spanning Tree and Switching LoopsWhy one patch cord can take a whole floor down in seconds.
- 27Reading a TracerouteWhich loss is real, and whose network it is in.
- 28DHCP, DNS and Helper AddressesWhy the new VLAN gets no addresses, and why it is always DNS.
- 29Wi-Fi Channel Planning and AP PlacementMore access points at lower power, not fewer at maximum.
- 30SMART Attributes That Predict FailureA drive can report PASSED while it is visibly dying.
- 31Grounding and Bonding a Telecom RoomOne ground, one path, and no loops between rooms.
- 32UPS Sizing: VA, Watts and RuntimeThe number on the box is not the number you need.
- 33Mounting Displays on Any WallFind the structure. Everything else is a repair bill.
- 34Mounting IP CamerasHeight, angle, and the surfaces that ruin the picture at night.
We do this work
as well as document it
Anyone facing a recovery prompt on a machine that was working yesterday, or rolling out encryption and wanting the keys to exist afterwards.