Field guide · Endpoints & data
BitLocker: Keys, Recovery and Escrow
What BitLocker actually protects against, why a machine suddenly asks for a recovery key when nothing was changed, and where that key should have been stored before it was needed. Covers TPM and the measured-boot triggers, the escrow options and how to verify one worked, suspending before firmware work, and what recovery looks like when the drive is pulled.
Procedure
Doing it
What to do before the key is needed, and what recovery looks like when it already is.
- Administrative access to the machine
- Access to wherever keys are escrowed
Know what it does and does not protect
BitLocker protects data at rest — a drive removed from the machine, or a laptop taken while powered off. It does nothing about a running machine an attacker is already logged into, and nothing about ransomware, which encrypts files the user can legitimately reach. It is theft and disposal protection, and treating it as general security is a mistake.
Understand why the prompt appears
With a TPM, the key is released only when the boot measurements match what they were when encryption was enabled. Change the measured environment — firmware update, secure boot toggled, boot order changed, drive moved to another machine, sometimes a dock or hardware change — and the TPM withholds the key. The recovery prompt is the system doing exactly what it was designed to do.
Escrow the key before you need it, and verify it landed
Entra ID, Active Directory, or an MDM, depending on how the estate is managed. The critical step is verification: check the key is actually visible in the directory for that specific device rather than assuming policy applied. A key that was never escrowed is indistinguishable from an escrowed one until the day it matters.
CautionVerify per device, not per policy. A machine that was encrypted before it was enrolled frequently has no key stored anywhere.
Suspend before firmware and boot changes
Suspending protection lets the machine boot once without the key, updates the measurements, and resumes automatically. It takes seconds and it prevents the entire class of unexpected recovery prompts after a BIOS update. Any process that flashes firmware across a fleet should suspend first.
Find the key by its identifier
The recovery screen shows a key ID. Match that ID against the escrowed keys rather than searching by machine name — a device that was rebuilt or renamed can have several keys, and entering the wrong one repeatedly is how people conclude the key is missing when it is not.
Recover a drive that has left its machine
A drive pulled and attached to another machine can be unlocked with the recovery key and the right tooling, provided you have the key. Without it there is no recovery path, by design — no support call, no vendor bypass. That is the point of the product, and it is the reason escrow verification is the step that actually matters.
CautionDo not attempt repairs on the original drive. Unlock, image the volume, and work on the image.
Questions
Questions people actually ask
- Why is BitLocker suddenly asking for a recovery key?
- Because the measured boot environment changed. The usual causes are a firmware or BIOS update, secure boot being toggled, a change in boot order, the drive being moved to another machine, or occasionally a hardware or dock change. The TPM releases the key only when measurements match, so a changed environment means it withholds it and falls back to recovery.
- Where is the recovery key stored?
- Wherever it was escrowed when encryption was enabled — Entra ID, Active Directory, an MDM, a Microsoft account for consumer devices, or a printed or saved copy. If none of those was configured at the time, it may exist nowhere. That is why verifying escrow per device, rather than trusting that a policy applied, is the part worth doing.
- Can data be recovered without the key?
- No. There is no vendor bypass and no support path, and that is the design rather than an omission — a recoverable-without-key encryption product would not be an encryption product. This is exactly why escrow verification is the only meaningful protection against data loss here.
- Should I suspend BitLocker before a BIOS update?
- Yes, always. It takes seconds, lets the machine boot once without the key, updates the measurements and resumes on its own. Skipping it is the single most common cause of a fleet-wide wave of recovery prompts the morning after a firmware rollout.
- Does BitLocker protect against ransomware?
- No. Ransomware runs as a user who can already read the files, so the volume is already unlocked from its point of view. BitLocker protects data at rest against someone who has the hardware but not the credentials. Backups protect against ransomware; encryption protects against theft and improper disposal.
- TPM-only or TPM with a PIN?
- TPM-only unlocks transparently, which is convenient and means a stolen powered-off laptop is protected only up to the login. Adding a PIN requires something the thief does not have before the volume unlocks at all, which materially raises the bar against attacks on a machine in someone else's hands. For laptops that leave the building it is usually worth the friction.
Other guides
Related guides
- 01
SMART Attributes That Predict Failure
A drive can report PASSED while it is visibly dying. - 02
RJ45 Wiring: T568A and T568B
Both colour codes, pin by pin, side by side. - 03
RJ11 Wiring and Phone Pinouts
Six positions, three lines, two colour systems. - 04
Keystone Jack Termination
Strip, seat, punch, snap — without failing the certification. - 05
66 Block Wiring
Fifty rows, four columns, and where the bridging clips go. - 06
110 Block Wiring
Lay the pairs in, press the connecting block on.
Book the work
We do this work
as well as document it
Anyone facing a recovery prompt on a machine that was working yesterday, or rolling out encryption and wanting the keys to exist afterwards.
- Free guides
- No sign-up
- Nothing tracked
- Written on the job