The āBitLocker recoveryā screen appears after a Windows update and asks for a 48-digit recovery key. Enter the matching key first, then use the fixes below if the prompt comes back.
Quick Fixes to Try First
Get back into Windows first. Figure out why later.
Important: Nothing gets you past this screen without the key. A recovery drive, Windows Recovery Environment, Safe Mode, or Microsoft Support canāt unlock the drive or recreate a lost key. If you canāt find the key and canāt undo the change that triggered it, Microsoftās only remaining option is to reset the PC, which removes all your files.
- Enter your recovery key: Type the 48-digit key exactly as shown, including the dashes. Press
Enter. - Check the ID matches: The recovery screen shows a āKey ID.ā Make sure it matches the ID on the key youāre entering, especially if youāve saved keys from multiple devices.
- Try a different keyboard input: If the number keys donāt register, the pre-boot recovery screen also accepts the function keys (
F1āF9type 1ā9,F10types 0). You can also plug in a basic wired USB keyboard. - Install pending updates once youāre in: After Windows boots, go to Settings > Windows Update and install everything available. Microsoft has fixed at least one documented update-related recovery prompt in a later cumulative update.
Symptoms and Fixes
| Symptom | Likely Cause | Quick Fix |
|---|---|---|
| Blue recovery screen right after a cumulative update installs | Update changed a measured boot component | Enter recovery key, then install the next cumulative update |
| Recovery key requested on every restart | TPM disabled, Secure Boot off, or boot mode changed | Suspend and resume BitLocker after fixing firmware settings |
| Recovery triggered after a BIOS/firmware update | Firmware update wasnāt preceded by a BitLocker suspend | Suspend BitLocker before future firmware updates |
| Recovery key typed but rejected | Wrong key entered, or Key ID mismatch | Match the Key ID shown on-screen to the correct saved key |
| Canāt find any recovery key | Key was never backed up outside the device | Check your Microsoft accountās device recovery page |
Common Issues and Solutions
Fix #1: Enter the key, then install follow-up updates
Symptoms:
- The recovery screen appears immediately after a restart following a Windows Update install
- You never touched BIOS settings or opened the case
- The PC worked fine before that specific update
Why it happens: BitLocker checks boot measurements on every start, and an update that changes a boot component can trip that check on PCs with a specific configuration. It isnāt a blanket bug across every Windows 11 PC. Microsoftās documented example: after the April 14, 2026 update KB5083769 (Windows 11 24H2/25H2), some devices asked for the recovery key once on the first restart. Microsoft describes the affected PCs as ādevices with an unrecommended BitLocker Group Policy configuration,ā and addressed the issue in the May 12, 2026 update KB5089549. Before you blame a specific KB, check its known-issues section on Microsoftās support site.
Fix:
- Enter the recovery key to get past the blue screen.
- Once Windows loads, open Settings > Windows Update and select Check for updates.
- Install any additional cumulative or āout-of-bandā updates offered. When Microsoft confirms an update-triggered recovery issue, the fix ships in one of these.
- Restart normally and confirm youāre not prompted for the recovery key again.
Tip: Search Microsoftās official BitLocker documentation and the Microsoft Q&A thread on sudden recovery-key prompts for the latest confirmed KB numbers before you spend time chasing a fix thatās already shipped.
Fix #2: Check TPM and Secure Boot if the prompt repeats
Symptoms:
- The recovery prompt reappears every time you reboot, including after the update
- It started right after an update but never stopped
Why it happens: A one-time update glitch is annoying but self-resolving once youāre past it. A recurring prompt means something changed permanently. Maybe the TPM got disabled or cleared. Maybe Secure Boot got turned off, or the boot mode flipped from UEFI to Legacy/CSM. Or Group Policy is demanding authentication your hardware canāt satisfy automatically. Less obvious measured-boot changes, such as a changed boot manager or a modified TPM validation profile, can also keep tripping the check.
Warning: Donāt select Clear TPM in
tpm.mscor in firmware while troubleshooting. Clearing the TPM removes the keys BitLocker uses to unlock automatically, so youāll need the recovery key to get back in, and you can lose access to your data if you donāt have it.
Fix:
Have your recovery key on hand before you change any firmware setting. Windows may ask for it on the next boot.
- Press
Windows key + R, typetpm.msc, and pressEnter. - Confirm the status reads āThe TPM is ready for use.ā If it says disabled or not found, youāll need to re-enable it in firmware (steps 4ā5 below).
- Before you touch any firmware setting, open Control Panel, go to System and Security > BitLocker Drive Encryption, and select Suspend protection next to your system drive. Suspending keeps the drive encrypted but stops the firmware changes from triggering another recovery prompt.
- Restart the PC and enter the firmware/BIOS setup (usually
F2,F10,Del, orEscat boot; check your PCās manual). - Confirm TPM, fTPM, or PTT is enabled and Secure Boot is on. If boot mode now reads Legacy/CSM and it was UEFI before, switch it back to UEFI. Change only the setting thatās actually wrong.
- Save changes and boot into Windows. If the recovery screen appears anyway, enter your key.
- Return to BitLocker Drive Encryption and check the status. Depending on how protection was suspended, it either resumes on its own after the restart or stays suspended until you resume it. If it still shows as suspended, select Resume protection. Resuming reseals BitLockerās key to the corrected settings.
If the prompt still returns after these settings are correct, donāt keep changing firmware options. Go to the escalation section below.
Verification: As a quick check, restart the PC two or three times. If every restart goes straight into Windows, the fix held. If any restart asks for the key again, enter it and go to the escalation section rather than changing more firmware settings.
Fix #3: Re-baseline BitLocker after a firmware update
Symptoms:
- The recovery screen appears specifically after a firmware/BIOS version change, not a regular cumulative update
- Can happen whether the firmware arrived through Windows Update or your PC makerās update tool
Why it happens: OEM firmware updates change low-level security measurements that BitLocker checks at boot. If BitLocker wasnāt suspended first, it sees those changes as a possible tampering attempt and locks the drive. Microsoft lists BIOS/UEFI firmware upgrades among the standard BitLocker recovery triggers.
Fix:
- Enter the recovery key to boot into Windows.
- Open Control Panel > System and Security > BitLocker Drive Encryption.
- Select Suspend protection, restart once, then check the status and select Resume protection if it still shows as suspended. Suspending and resuming reseals BitLockerās key to the new firmware measurements, so the next boot shouldnāt need the recovery key.
- Before your next firmware update, suspend BitLocker manually first using the same menu, apply the update, restart, then resume protection.
Tip: Firmware and TPM updates can restart the PC more than once, so a one-restart suspend can resume protection too early. Before a firmware update, open PowerShell as administrator and run
Suspend-BitLocker -MountPoint "C:" -RebootCount 0, which keeps protection suspended until you resume it. When the update has fully finished, runResume-BitLocker -MountPoint "C:"in the same elevated window. Use either PowerShell or the Control Panel steps, not both.
Fix #4: Use the function keys if typing doesnāt register
Symptoms:
- Youāre at the blue recovery screen, but typing the key does nothing
- Numbers donāt register, or the field wonāt accept input at all
Why it happens: Some update-related bugs affect USB keyboard input inside the Windows Recovery Environment (WinRE). WinRE is the stripped-down environment that hosts the recovery screen.
Fix:
- Try a different USB port, preferably a USB-A port instead of USB-C if your laptop has both.
- If your device has a touchscreen, check for an on-screen keyboard option.
- If the digit keys donāt register, use the function keys instead:
F1āF9enter 1ā9 andF10enters 0. - If input still fails and you have another Windows PC plus a USB drive, create a recovery drive on that PC (search Start for Create a recovery drive) and boot from it to reach repair options. A recovery drive canāt unlock the encrypted drive or replace the recovery key; youāll still need to enter the key there.
Less common: The EFI System Partition is nearly full
Symptoms:
- Feature updates fail repeatedly, and youāve already ruled out the fixes above
- This is an uncommon edge case, not a typical cause of the recovery screen
Why it happens: The EFI System Partition (ESP) is a small, hidden partition that stores boot files. If itās nearly full, a large update may not be able to write its new boot files.
Fix:
- Right-click Start and select Disk Management.
- Find the small partition labeled āEFI System Partition,ā usually 100ā500 MB. Disk Management shows its total size, but Windows hides its contents and doesnāt show usable free space.
- If feature updates keep failing and you suspect this partition, contact your PCās manufacturer or Microsoft support for a supported procedure. Donāt delete files from the ESP or resize it with third-party partition tools; a mistake here can break booting entirely.
Fix #5: Find your recovery key online
Symptoms:
- Youāre at the recovery screen with no printed key, no USB drive, and no memory of saving one
- The PC belongs to work or school
Why it happens: The key was generated automatically when BitLocker or Device Encryption turned on. It was never backed up anywhere you can currently access.
Fix:
- On any other device (phone, tablet, another PC), open a browser and go to
https://aka.ms/myrecoverykey. This is Microsoftās short link to the recovery key page (https://account.microsoft.com/devices/recoverykey). - Sign in with the same Microsoft account used to set up the locked PC.
- Find the key whose Key ID matches the one shown on the recovery screen (the first eight characters are enough to tell keys apart), then copy that recovery key. Device names alone can be misleading if youāve reinstalled Windows or own several PCs.
- If the PC is managed by a workplace or school, contact IT instead. Recovery keys for managed devices live in Microsoft Entra ID/Intune or Active Directory, not your personal Microsoft account. If your organization allows self-service, sign in at
https://aka.ms/aadrecoverykeywith your work or school account, select Devices, expand the locked PC, and select View BitLocker Keys. Match the Key ID the same way. - Type the recovered key into the recovery screen.
Error Messages Table
| Message / Screen Text | What It Means |
|---|---|
| āBitLocker recoveryā (blue screen with Key ID) | Boot measurements changed since last successful boot; enter the matching recovery key |
| āThe TPM is ready for useā (tpm.msc) | TPM is healthy and functioning normally |
| āCompatible TPM cannot be foundā (tpm.msc) | TPM is disabled in firmware, not present, or not recognized by Windows |
| āThis device canāt use a Trusted Platform Moduleā | TPM missing, disabled, or firmware set to Legacy/CSM instead of UEFI |
| āBitLocker Drive Encryption is suspendedā (Control Panel) | Protection is temporarily paused; normal during maintenance, but re-enable it afterward |
Settings to Check
- TPM status: Run
tpm.msc; confirm it reads āThe TPM is ready for use.ā - Secure Boot: Check in firmware/UEFI setup, or via
Confirm-SecureBootUEFIin an elevated PowerShell prompt (returnsTrueif enabled). - BitLocker Group Policy: Go to Local Group Policy Editor (
gpedit.msc) > Computer Configuration > Administrative Templates > Windows Components > BitLocker Drive Encryption > Operating System Drives and review āConfigure TPM platform validation profileā and āRequire additional authentication at startup.ā
- Recovery key backups: Confirm at least one copy exists at account.microsoft.com/devices/recoverykey, printed, or saved to a USB drive.
How to check and reset the TPM platform validation profile
The platform validation profile determines which boot components BitLocker measures before deciding the boot is trustworthy. These components are called PCRs, or Platform Configuration Registers. Microsoftās April 2026 known issue involved this policy in an unrecommended configuration, so itās worth checking on a personal PC.
Important: If your PC is managed by work or school, donāt change this policy yourself. Itās usually part of your organizationās security baseline, so contact IT instead.
- Open
gpedit.msc. - Navigate to Computer Configuration > Administrative Templates > Windows Components > BitLocker Drive Encryption > Operating System Drives.
- Open Configure TPM platform validation profile (for native UEFI firmware configurations).
- If itās set to Enabled with custom PCR values on a personal PC, switch it to Not Configured. This returns BitLocker to the Windows default profile.
- Select Apply, then OK.
- Restart the PC, then suspend and resume BitLocker protection once to re-baseline against the new profile.
Verification: Install a routine cumulative update afterward and confirm the PC boots normally without a recovery prompt.
When to Escalate
The steps above cover software and configuration causes. Suspect a hardware or firmware problem instead of an update bug when:
- The recovery prompt appears with no update, firmware change, or Group Policy change involved
tpm.mscreports TPM errors that persist after re-enabling it in firmware and reflashing to the latest firmware version- The recovery screen appears intermittently with no consistent trigger, especially alongside random shutdowns or POST beep codes
- Your PC manufacturer has published an advisory for your modelās BIOS/firmware version describing this exact symptom
How to get help:
- Check your PC manufacturerās support site for a documented BIOS/TPM advisory matching your model
- Review event logs via Event Viewer > Applications and Services Logs > Microsoft > Windows > BitLocker-API for the specific error code
- Post the exact recovery Key ID and error details on Microsoft Q&A
- For work/school PCs, contact your IT department, as they can pull recovery keys and BitLocker status directly from Microsoft Entra ID or Intune
Prevention Tips
- Back up the recovery key before major updates: Open Control Panel > BitLocker Drive Encryption, select Back up your recovery key, and save it to your Microsoft account and a printed or offline copy.
- Suspend BitLocker before firmware updates: Manually suspend protection before installing non-Microsoft BIOS/UEFI firmware or TPM firmware updates that change boot components, then resume afterward. Routine Windows quality updates donāt need this.
- Leave the PCR policy at its default: On personal PCs, keep the TPM platform validation profile Group Policy at āNot Configured.ā On managed PCs, leave it to IT.
- Keep Windows current: Install cumulative updates promptly. Confirmed BitLocker/update conflicts are fixed in later cumulative updates, as with KB5089549.
Frequently Asked Questions
Does turning off BitLocker before installing updates help?
It can prevent the recovery prompt. But it also leaves your drive unencrypted during that window, which defeats the point of having BitLocker on. Suspending protection is the safer middle ground.
It pauses the boot verification check without decrypting the drive. Depending on how you suspend it, protection resumes after a restart, after the number of restarts you set with PowerShellās -RebootCount, or only when you resume it manually (-RebootCount 0).
Is this Microsoftās fault?
Sometimes, yes. Microsoft confirmed that the April 2026 update KB5083769 triggered a one-time recovery prompt on devices with a specific BitLocker policy setup, and fixed it in KB5089549.
Other cases trace back to OEM firmware updates or PC-specific settings, not Windows Update itself. Check the updateās known-issues notes and your PC manufacturerās support site before you pin the blame on either side.
Will this happen again on my next update?
Itās uncommon, but not impossible. BitLockerās whole job is to notice boot changes.
Any future firmware or update change that alters those measurements could trigger it again. Backing up your recovery key and keeping the TPM validation profile at default settings lowers your odds by a lot.
Last updated: 2026-10-05 | Applies to BitLocker Drive Encryption on Windows 11, and on Windows 10 version 22H2 PCs enrolled in Extended Security Updates