How to Fix the BitLocker Recovery Screen After a Windows Update

14 min read

Help Desk Geek is reader-supported. We may earn a commission when you buy through links on our site. Learn more.

The ā€œBitLocker recoveryā€ screen appears after a Windows update and asks for a 48-digit recovery key. Enter the matching key first, then use the fixes below if the prompt comes back.

Quick Fixes to Try First

Get back into Windows first. Figure out why later.

Important: Nothing gets you past this screen without the key. A recovery drive, Windows Recovery Environment, Safe Mode, or Microsoft Support can’t unlock the drive or recreate a lost key. If you can’t find the key and can’t undo the change that triggered it, Microsoft’s only remaining option is to reset the PC, which removes all your files.

  • Enter your recovery key: Type the 48-digit key exactly as shown, including the dashes. Press Enter.
  • Check the ID matches: The recovery screen shows a ā€œKey ID.ā€ Make sure it matches the ID on the key you’re entering, especially if you’ve saved keys from multiple devices.
  • Try a different keyboard input: If the number keys don’t register, the pre-boot recovery screen also accepts the function keys (F1–F9 type 1–9, F10 types 0). You can also plug in a basic wired USB keyboard.
  • Install pending updates once you’re in: After Windows boots, go to Settings > Windows Update and install everything available. Microsoft has fixed at least one documented update-related recovery prompt in a later cumulative update.

Symptoms and Fixes

SymptomLikely CauseQuick Fix
Blue recovery screen right after a cumulative update installsUpdate changed a measured boot componentEnter recovery key, then install the next cumulative update
Recovery key requested on every restartTPM disabled, Secure Boot off, or boot mode changedSuspend and resume BitLocker after fixing firmware settings
Recovery triggered after a BIOS/firmware updateFirmware update wasn’t preceded by a BitLocker suspendSuspend BitLocker before future firmware updates
Recovery key typed but rejectedWrong key entered, or Key ID mismatchMatch the Key ID shown on-screen to the correct saved key
Can’t find any recovery keyKey was never backed up outside the deviceCheck your Microsoft account’s device recovery page

Common Issues and Solutions

Fix #1: Enter the key, then install follow-up updates

Symptoms:

  • The recovery screen appears immediately after a restart following a Windows Update install
  • You never touched BIOS settings or opened the case
  • The PC worked fine before that specific update

Why it happens: BitLocker checks boot measurements on every start, and an update that changes a boot component can trip that check on PCs with a specific configuration. It isn’t a blanket bug across every Windows 11 PC. Microsoft’s documented example: after the April 14, 2026 update KB5083769 (Windows 11 24H2/25H2), some devices asked for the recovery key once on the first restart. Microsoft describes the affected PCs as ā€œdevices with an unrecommended BitLocker Group Policy configuration,ā€ and addressed the issue in the May 12, 2026 update KB5089549. Before you blame a specific KB, check its known-issues section on Microsoft’s support site.

Fix:

  • Enter the recovery key to get past the blue screen.
  • Once Windows loads, open Settings > Windows Update and select Check for updates.
  • Install any additional cumulative or ā€œout-of-bandā€ updates offered. When Microsoft confirms an update-triggered recovery issue, the fix ships in one of these.
  • Restart normally and confirm you’re not prompted for the recovery key again.
Windows 11 Settings > Windows Update page showing the Check for updates button and recent update history

Tip: Search Microsoft’s official BitLocker documentation and the Microsoft Q&A thread on sudden recovery-key prompts for the latest confirmed KB numbers before you spend time chasing a fix that’s already shipped.

Fix #2: Check TPM and Secure Boot if the prompt repeats

Symptoms:

  • The recovery prompt reappears every time you reboot, including after the update
  • It started right after an update but never stopped

Why it happens: A one-time update glitch is annoying but self-resolving once you’re past it. A recurring prompt means something changed permanently. Maybe the TPM got disabled or cleared. Maybe Secure Boot got turned off, or the boot mode flipped from UEFI to Legacy/CSM. Or Group Policy is demanding authentication your hardware can’t satisfy automatically. Less obvious measured-boot changes, such as a changed boot manager or a modified TPM validation profile, can also keep tripping the check.

Warning: Don’t select Clear TPM in tpm.msc or in firmware while troubleshooting. Clearing the TPM removes the keys BitLocker uses to unlock automatically, so you’ll need the recovery key to get back in, and you can lose access to your data if you don’t have it.

Fix:

Have your recovery key on hand before you change any firmware setting. Windows may ask for it on the next boot.

  • Press Windows key + R, type tpm.msc, and press Enter.
  • Confirm the status reads ā€œThe TPM is ready for use.ā€ If it says disabled or not found, you’ll need to re-enable it in firmware (steps 4–5 below).
TPM Management console showing TPM status message such as 'The TPM is ready for use'
  • Before you touch any firmware setting, open Control Panel, go to System and Security > BitLocker Drive Encryption, and select Suspend protection next to your system drive. Suspending keeps the drive encrypted but stops the firmware changes from triggering another recovery prompt.
Windows 11 Control Panel BitLocker Drive Encryption page for drive C: with Suspend protection highlighted and Back up your recovery key visible
  • Restart the PC and enter the firmware/BIOS setup (usually F2, F10, Del, or Esc at boot; check your PC’s manual).
  • Confirm TPM, fTPM, or PTT is enabled and Secure Boot is on. If boot mode now reads Legacy/CSM and it was UEFI before, switch it back to UEFI. Change only the setting that’s actually wrong.
  • Save changes and boot into Windows. If the recovery screen appears anyway, enter your key.
  • Return to BitLocker Drive Encryption and check the status. Depending on how protection was suspended, it either resumes on its own after the restart or stays suspended until you resume it. If it still shows as suspended, select Resume protection. Resuming reseals BitLocker’s key to the corrected settings.

If the prompt still returns after these settings are correct, don’t keep changing firmware options. Go to the escalation section below.

Verification: As a quick check, restart the PC two or three times. If every restart goes straight into Windows, the fix held. If any restart asks for the key again, enter it and go to the escalation section rather than changing more firmware settings.

Fix #3: Re-baseline BitLocker after a firmware update

Symptoms:

  • The recovery screen appears specifically after a firmware/BIOS version change, not a regular cumulative update
  • Can happen whether the firmware arrived through Windows Update or your PC maker’s update tool

Why it happens: OEM firmware updates change low-level security measurements that BitLocker checks at boot. If BitLocker wasn’t suspended first, it sees those changes as a possible tampering attempt and locks the drive. Microsoft lists BIOS/UEFI firmware upgrades among the standard BitLocker recovery triggers.

Fix:

  • Enter the recovery key to boot into Windows.
  • Open Control Panel > System and Security > BitLocker Drive Encryption.
  • Select Suspend protection, restart once, then check the status and select Resume protection if it still shows as suspended. Suspending and resuming reseals BitLocker’s key to the new firmware measurements, so the next boot shouldn’t need the recovery key.
  • Before your next firmware update, suspend BitLocker manually first using the same menu, apply the update, restart, then resume protection.

Tip: Firmware and TPM updates can restart the PC more than once, so a one-restart suspend can resume protection too early. Before a firmware update, open PowerShell as administrator and run Suspend-BitLocker -MountPoint "C:" -RebootCount 0, which keeps protection suspended until you resume it. When the update has fully finished, run Resume-BitLocker -MountPoint "C:" in the same elevated window. Use either PowerShell or the Control Panel steps, not both.

Fix #4: Use the function keys if typing doesn’t register

Symptoms:

  • You’re at the blue recovery screen, but typing the key does nothing
  • Numbers don’t register, or the field won’t accept input at all

Why it happens: Some update-related bugs affect USB keyboard input inside the Windows Recovery Environment (WinRE). WinRE is the stripped-down environment that hosts the recovery screen.

Fix:

  • Try a different USB port, preferably a USB-A port instead of USB-C if your laptop has both.
  • If your device has a touchscreen, check for an on-screen keyboard option.
  • If the digit keys don’t register, use the function keys instead: F1–F9 enter 1–9 and F10 enters 0.
  • If input still fails and you have another Windows PC plus a USB drive, create a recovery drive on that PC (search Start for Create a recovery drive) and boot from it to reach repair options. A recovery drive can’t unlock the encrypted drive or replace the recovery key; you’ll still need to enter the key there.

Less common: The EFI System Partition is nearly full

Symptoms:

  • Feature updates fail repeatedly, and you’ve already ruled out the fixes above
  • This is an uncommon edge case, not a typical cause of the recovery screen

Why it happens: The EFI System Partition (ESP) is a small, hidden partition that stores boot files. If it’s nearly full, a large update may not be able to write its new boot files.

Fix:

  • Right-click Start and select Disk Management.
  • Find the small partition labeled ā€œEFI System Partition,ā€ usually 100–500 MB. Disk Management shows its total size, but Windows hides its contents and doesn’t show usable free space.
Windows 11 Disk Management window with the small EFI System Partition highlighted next to the Windows (C:) partition on Disk 0
  • If feature updates keep failing and you suspect this partition, contact your PC’s manufacturer or Microsoft support for a supported procedure. Don’t delete files from the ESP or resize it with third-party partition tools; a mistake here can break booting entirely.

Fix #5: Find your recovery key online

Symptoms:

  • You’re at the recovery screen with no printed key, no USB drive, and no memory of saving one
  • The PC belongs to work or school

Why it happens: The key was generated automatically when BitLocker or Device Encryption turned on. It was never backed up anywhere you can currently access.

Fix:

  • On any other device (phone, tablet, another PC), open a browser and go to https://aka.ms/myrecoverykey. This is Microsoft’s short link to the recovery key page (https://account.microsoft.com/devices/recoverykey).
  • Sign in with the same Microsoft account used to set up the locked PC.
  • Find the key whose Key ID matches the one shown on the recovery screen (the first eight characters are enough to tell keys apart), then copy that recovery key. Device names alone can be misleading if you’ve reinstalled Windows or own several PCs.
Signed-in Microsoft account devices page listing BitLocker recovery keys associated with the user's devices
  • If the PC is managed by a workplace or school, contact IT instead. Recovery keys for managed devices live in Microsoft Entra ID/Intune or Active Directory, not your personal Microsoft account. If your organization allows self-service, sign in at https://aka.ms/aadrecoverykey with your work or school account, select Devices, expand the locked PC, and select View BitLocker Keys. Match the Key ID the same way.
  • Type the recovered key into the recovery screen.

Error Messages Table

Message / Screen TextWhat It Means
ā€œBitLocker recoveryā€ (blue screen with Key ID)Boot measurements changed since last successful boot; enter the matching recovery key
ā€œThe TPM is ready for useā€ (tpm.msc)TPM is healthy and functioning normally
ā€œCompatible TPM cannot be foundā€ (tpm.msc)TPM is disabled in firmware, not present, or not recognized by Windows
ā€œThis device can’t use a Trusted Platform Moduleā€TPM missing, disabled, or firmware set to Legacy/CSM instead of UEFI
ā€œBitLocker Drive Encryption is suspendedā€ (Control Panel)Protection is temporarily paused; normal during maintenance, but re-enable it afterward

Settings to Check

  • TPM status: Run tpm.msc; confirm it reads ā€œThe TPM is ready for use.ā€
  • Secure Boot: Check in firmware/UEFI setup, or via Confirm-SecureBootUEFI in an elevated PowerShell prompt (returns True if enabled).
  • BitLocker Group Policy: Go to Local Group Policy Editor (gpedit.msc) > Computer Configuration > Administrative Templates > Windows Components > BitLocker Drive Encryption > Operating System Drives and review ā€œConfigure TPM platform validation profileā€ and ā€œRequire additional authentication at startup.ā€
Local Group Policy Editor open to Administrative Templates > Windows Components > BitLocker Drive Encryption > Operating System Drives with the Require additional authentication at startup and Configure TPM platform validation profile policies listed
  • Recovery key backups: Confirm at least one copy exists at account.microsoft.com/devices/recoverykey, printed, or saved to a USB drive.

How to check and reset the TPM platform validation profile

The platform validation profile determines which boot components BitLocker measures before deciding the boot is trustworthy. These components are called PCRs, or Platform Configuration Registers. Microsoft’s April 2026 known issue involved this policy in an unrecommended configuration, so it’s worth checking on a personal PC.

Important: If your PC is managed by work or school, don’t change this policy yourself. It’s usually part of your organization’s security baseline, so contact IT instead.

  • Open gpedit.msc.
  • Navigate to Computer Configuration > Administrative Templates > Windows Components > BitLocker Drive Encryption > Operating System Drives.
  • Open Configure TPM platform validation profile (for native UEFI firmware configurations).
  • If it’s set to Enabled with custom PCR values on a personal PC, switch it to Not Configured. This returns BitLocker to the Windows default profile.
  • Select Apply, then OK.
  • Restart the PC, then suspend and resume BitLocker protection once to re-baseline against the new profile.

Verification: Install a routine cumulative update afterward and confirm the PC boots normally without a recovery prompt.

When to Escalate

The steps above cover software and configuration causes. Suspect a hardware or firmware problem instead of an update bug when:

  • The recovery prompt appears with no update, firmware change, or Group Policy change involved
  • tpm.msc reports TPM errors that persist after re-enabling it in firmware and reflashing to the latest firmware version
  • The recovery screen appears intermittently with no consistent trigger, especially alongside random shutdowns or POST beep codes
  • Your PC manufacturer has published an advisory for your model’s BIOS/firmware version describing this exact symptom

How to get help:

  • Check your PC manufacturer’s support site for a documented BIOS/TPM advisory matching your model
  • Review event logs via Event Viewer > Applications and Services Logs > Microsoft > Windows > BitLocker-API for the specific error code
  • Post the exact recovery Key ID and error details on Microsoft Q&A
  • For work/school PCs, contact your IT department, as they can pull recovery keys and BitLocker status directly from Microsoft Entra ID or Intune

Prevention Tips

  • Back up the recovery key before major updates: Open Control Panel > BitLocker Drive Encryption, select Back up your recovery key, and save it to your Microsoft account and a printed or offline copy.
  • Suspend BitLocker before firmware updates: Manually suspend protection before installing non-Microsoft BIOS/UEFI firmware or TPM firmware updates that change boot components, then resume afterward. Routine Windows quality updates don’t need this.
  • Leave the PCR policy at its default: On personal PCs, keep the TPM platform validation profile Group Policy at ā€œNot Configured.ā€ On managed PCs, leave it to IT.
  • Keep Windows current: Install cumulative updates promptly. Confirmed BitLocker/update conflicts are fixed in later cumulative updates, as with KB5089549.
Help & Answers

Frequently Asked Questions

3 questions

Does turning off BitLocker before installing updates help?

It can prevent the recovery prompt. But it also leaves your drive unencrypted during that window, which defeats the point of having BitLocker on. Suspending protection is the safer middle ground.

It pauses the boot verification check without decrypting the drive. Depending on how you suspend it, protection resumes after a restart, after the number of restarts you set with PowerShell’s -RebootCount, or only when you resume it manually (-RebootCount 0).

Is this Microsoft’s fault?

Sometimes, yes. Microsoft confirmed that the April 2026 update KB5083769 triggered a one-time recovery prompt on devices with a specific BitLocker policy setup, and fixed it in KB5089549.

Other cases trace back to OEM firmware updates or PC-specific settings, not Windows Update itself. Check the update’s known-issues notes and your PC manufacturer’s support site before you pin the blame on either side.

Will this happen again on my next update?

It’s uncommon, but not impossible. BitLocker’s whole job is to notice boot changes.

Any future firmware or update change that alters those measurements could trigger it again. Backing up your recovery key and keeping the TPM validation profile at default settings lowers your odds by a lot.

Last updated: 2026-10-05 | Applies to BitLocker Drive Encryption on Windows 11, and on Windows 10 version 22H2 PCs enrolled in Extended Security Updates