“Enter the recovery key to get going again” can appear before Windows starts. It’s an alarming screen when your files are locked behind it.
You need the matching 48-digit BitLocker recovery key to continue. You can find it now or back it up before an update, firmware change, or TPM reset triggers the screen again.
What Is a BitLocker Recovery Key?
BitLocker encrypts a Windows drive so no one can read its files without permission. Full BitLocker comes with Windows 11 and 10 Pro, Enterprise, and Education. Many Home-edition PCs offer a simpler tool called Device Encryption.
Windows usually unlocks the drive after the Trusted Platform Module (TPM) checks that startup is safe. The TPM is a security chip that protects encryption data. If something changes during startup, BitLocker may ask for its unique 48-digit recovery key.
The recovery screen also shows a Key ID. This is not the recovery key. It helps you find the saved 48-digit key for the locked drive among the entries in your account. That difference matters when your account lists several keys.
Prerequisites
Make sure you have:
- A Windows 11 or Windows 10 PC that supports BitLocker or Device Encryption
- Administrator access if you plan to enable encryption or create a new backup
- Your Microsoft account email address and password
- A second device if the Windows PC is already locked
- A USB drive, printer, or secure offline location for a second backup
- A backup of important personal files before enabling encryption
- The computer connected to AC power during initial encryption
Warning: You cannot bypass or rebuild a BitLocker recovery key. If the drive is locked and no valid key exists, resetting the PC erases the encrypted files.
Step-by-Step Guide
Fix #1: Check Whether Encryption Is Already Enabled
First, check the current encryption status. You don’t need to change anything until you know what Windows already protects.
- Press
Windows + Ito open Settings.
- Open System > About. Check the Windows specifications section to find your Windows edition.
- Open Start, type the following search phrase, and select Manage BitLocker if it appears:
BitLocker

- In the BitLocker Drive Encryption window, find Operating system drive. Check the status beside drive
C:.

- On Windows 11 Home, open Settings > Privacy & security > Device encryption instead. On Windows 10 Home, open Settings > Update & Security > Device encryption.

Expected result: The page says BitLocker or Device Encryption is on, off, or unavailable. If it is on, don’t turn it off. Go to Fix #3 and back up the current key.
Fix #2: Turn On BitLocker and Create a Recovery Key
Skip this fix if encryption is already on. Turning BitLocker off and on adds work and may create a new recovery key.
- Sign in to Windows with an administrator account.
- Connect the computer to power and close all open apps.
- Open Start, type Manage BitLocker, and select the matching Control Panel result.
- Select Turn on BitLocker beside drive
C:.
- Wait while Windows checks if the computer supports BitLocker.
- Choose Save to your Microsoft account when asked how to back up the recovery key.
- Select Print the recovery key or Save to a file to create a second copy.
Warning: Do not save the only copy on the encrypted
C:drive. Use another drive, a USB device, or a printed page stored in a safe place.
- Choose Encrypt used disk space only for a new PC or drive. Choose Encrypt entire drive for a PC that has already stored personal files.
- Select New encryption mode for a fixed drive used only with current Windows versions. Select Compatible mode for a removable drive that must work with older Windows versions.
- Leave Run BitLocker system check selected.
- Select Continue, then restart the computer when asked.
- Sign in after the restart. Keep the PC connected to power while encryption runs.
- Open Control Panel > System and Security > BitLocker Drive Encryption. Confirm that drive
C:says BitLocker on or shows encryption in progress.
Expected result: Windows encrypts the system drive and creates at least one recovery-password protector. You can use the PC while encryption finishes. Disk-heavy tasks may run a little slower.
Note: On Windows Home, signing in with a Microsoft account may turn on Device Encryption and upload the key. Check the upload instead of assuming it worked.
Fix #3: Back Up an Existing Key Through Windows
This is usually the easiest way to protect an existing BitLocker key. Make two copies now. That way, a lost USB drive or account problem won’t become a crisis.
- Open Start, type Manage BitLocker, and open the result.
- Expand drive
C:if its actions are hidden.
- Select Back up your recovery key.

- Select Save to your Microsoft account for an online copy linked to your Windows sign-in.
- Run Back up your recovery key again. Choose Save to a file or Print the recovery key for a separate copy.
- If you save a file, choose a USB drive or another unencrypted storage location.
- Open the saved text file. Confirm that it contains a BitLocker Recovery Key identifier and a 48-digit BitLocker Recovery Key.
Expected result: You have at least two usable copies. Keep one in your Microsoft account and another offline if possible.
Fix #4: Verify the Key in Your Microsoft Account
Saving a key is only half the job. Take a minute to check that the online entry matches your protected drive.
- Open Microsoft’s recovery-key page in a browser.
- Sign in with the Microsoft account used on the Windows PC.
- Review the device name, Key ID, drive, and recovery-key entries.

- Compare the listed Key ID with the ID in your saved or printed copy.
- Store the offline copy away from the computer.
Expected result: The page shows the current recovery key and a Key ID that matches the protected drive. If the IDs differ, don’t rely on the device name. Check the other entries.
Retrieve the Key on macOS
A Mac can serve as the second device when your Windows PC won’t start.
- Open Safari or another browser on your Mac.
- Sign in with the Microsoft account linked to the Windows PC.

- Match the Key ID. Then read the 48-digit key to the person at the locked PC.
BitLocker does not run on macOS. FileVault is Apple’s own disk-encryption system. A FileVault recovery key cannot unlock a BitLocker drive.
Retrieve the Key on iOS
An iPhone or iPad may be the fastest option when the locked PC is your only computer.
- Open Safari on the iPhone or iPad.
- Sign in with the Microsoft account used on the Windows computer.

- Rotate the device or zoom the page if needed to read the full Key ID.
- Keep the page open while you enter the matching 48-digit key on the Windows recovery screen.
The iPhone or iPad only retrieves the saved key. iOS cannot manage BitLocker.
Fix #5: Verify and Export the Key with manage-bde
Use the built-in manage-bde command if the Control Panel link is missing. You can also use it to check the recovery protector directly. The output looks technical, but you only need two parts: the Numerical Password ID and the 48-digit password.
- Connect a USB drive and note its drive letter in File Explorer. The example below uses
E:.
- Open Start, type Command Prompt, and select Run as administrator.
- Approve the User Account Control prompt.
- Check BitLocker’s status:
manage-bde -status C:
- Confirm that Protection Status says Protection On. Also note the encryption percentage.
- Display the protectors linked to the system drive:
manage-bde -protectors -get C:

- Find the Numerical Password section. Its ID marks the recovery protector. The eight groups of six digits form the recovery key.
- Export the output to the USB drive:
manage-bde -protectors -get C: > E:\BitLocker-Recovery-Key.txt
- Open
E:\BitLocker-Recovery-Key.txt. Confirm that it contains the Numerical Password entry.
- Eject the USB drive and store it in a safe place.
Expected result: The command reports a Numerical Password protector. The USB drive also contains a readable backup. That’s what you want. A TPM entry alone is not the 48-digit recovery password.
Warning: Anyone with this file can unlock the encrypted drive. Don’t email it without protection, put it in a public cloud folder, or leave the USB drive beside the PC.
Fix #6: Unlock a PC at the Recovery Screen
The long number on this screen leaves no room for error, but you don’t need to guess. Match the Key ID first. Then enter the key linked to it.
- On another device, open the Microsoft recovery-key page. You can also use the printed or saved copy made when BitLocker was enabled.
- Write down the Key ID shown on the blue recovery screen.
- Find the saved entry with the exact same Key ID.
- Enter its 48-digit recovery key. You can skip the hyphens if the recovery screen adds them for you.
- Check each six-digit group before you continue.
- Press
Enteror select Continue.
Expected result: BitLocker accepts the key, and Windows continues to start. After you sign in, back up the current key again and install any pending Windows updates. Make that extra copy while the right key is still in front of you.
Fix #7: Ask Work or School IT for the Stored Key
If your employer or school owns the PC, its key may be in the organization’s system. It may not be in your personal Microsoft account.
- Check if the recovery screen names your employer, school, or organization.
- Record the device name and full Key ID shown on the screen.
- Contact the organization’s help desk through a trusted phone number or support portal.
- Tell IT that the device is at the BitLocker recovery screen. Give them the Key ID.
- Enter the 48-digit key only after IT matches it to the device in Microsoft Entra ID, Intune, or another approved system.
Expected result: IT gives you the recovery key for that managed device. A work or school key may not appear in your personal Microsoft account. Checking the same personal account again won’t help.
Configuration
Choose where to store the recovery key based on who owns the PC:
| Setting | Recommended choice | Applies to |
|---|---|---|
| Primary key backup | Microsoft account | Personal PC |
| Secondary key backup | Printed copy or secured USB drive | Personal PC |
| Organizational storage | Microsoft Entra ID or Intune, managed by IT | Work or school PC |
| Key matching | Compare the recovery screen’s Key ID exactly | All encrypted PCs |
| Protection check | manage-bde -status C: | Windows Pro, Enterprise, or Education |
Keep the recovery key away from the encrypted PC. During a lockout, a printed copy in a locked drawer is more useful than a file stored only on that PC.
Check the backup before BIOS updates, TPM work, motherboard replacement, or major Windows upgrades. Back up your important files before those changes as well.
Tips and Troubleshooting
Why Is Windows Suddenly Asking for the Key?
A recovery prompt does not always mean the drive has failed. It often means BitLocker noticed a startup change and would not unlock the drive on its own.
BitLocker may enter recovery mode after:
- A Windows, BIOS, UEFI, or device-firmware update
- A change to Secure Boot or the boot order
- Clearing or resetting the TPM
- Replacing the motherboard or storage hardware
- Moving an encrypted drive to another computer
- Changes to startup files that BitLocker cannot validate
Don’t clear the TPM to escape the recovery screen. Doing so can remove keys that the TPM uses during startup and make the problem worse.
What Changed in April and May 2026?
Microsoft confirmed that an April 2026 Windows update caused surprise BitLocker recovery prompts on some devices. The May 2026 update fixed that known trigger.
After you regain access, open Settings > Windows Update and select Check for updates. Install the May 2026 update or any newer cumulative update, then restart.

If Windows Update fails, fix that error before you change firmware or TPM settings. Current updates reduce the risk of the April issue. They do not replace a recovery-key backup.
Multiple Keys Appear in the Microsoft Account
A list of similar entries can be confusing. This is common if you reset Windows or use the same account on several PCs. Don’t rely on the device name because Windows may keep old entries.
Match the Key ID on the recovery screen with the online or printed Key ID. Only its linked 48-digit key will unlock the drive.
The Key Is Not in the Microsoft Account
Check each Microsoft account that may have been used to set up the PC. Then search USB drives, printed records, and backup folders for a file named like BitLocker Recovery Key*.txt.
For a work or school PC, stop checking personal accounts and contact IT. The organization may have the only copy.
No Recovery Key Exists Anywhere
This is the outcome no one wants, but the limit is firm. Microsoft Support cannot find, rebuild, or bypass a missing BitLocker recovery key. If no personal or work copy exists, you must reset or reinstall Windows. This erases the encrypted drive.
Don’t pay anyone who claims they can calculate the key. A valid 48-digit recovery password cannot be guessed in practice. Such offers may also expose you to fraud or malware.
Wrapping Up
Back up the key through Manage BitLocker and check it on Microsoft’s recovery-key page. Keep a printed or secured USB copy somewhere else. You’ll then have a clear way back in if an update, account issue, or hardware change triggers recovery mode.
If prompts continue after the May 2026 update, check for storage failure, firmware trouble, unsafe boot changes, or malware. Do the same if prompts appear without any hardware changes.
For more information about BitLocker, you can visit Microsoft’s official support page or check out our guide on Windows 11 privacy and security settings. Additionally, you can learn more about fixing TPM device not detected issues in Windows 11 or resolving Windows 11 boot loops after updates.
