Data Recovery

Drive Asking for a BitLocker Recovery Key: Where to Find It

Your computer boots to a blue screen asking for a 48-digit BitLocker recovery key. Or you plug in an external drive and Windows asks to unlock it. Or a drive that used to work now shows as RAW on a different machine.

Let me be direct about the hard part first, because it changes what you should do with your time and money:

If the recovery key is genuinely gone, the data is genuinely gone. Not “difficult.” Not “expensive.” Gone. No data recovery lab can help — not me, not the biggest lab in the country. That’s not an equipment limitation, it’s arithmetic. AES-256 is what governments use precisely because it can’t be brute-forced.

So this article isn’t about recovery techniques. It’s about finding the key, because it’s usually somewhere you haven’t looked.

Where the key actually is

Work through all of these before concluding anything.

Your Microsoft account. The most likely place by a wide margin. If the machine was ever signed into a Microsoft account, Windows very likely uploaded the key automatically. Go to account.microsoft.com/devices/recoverykey from any device and sign in with the account that was used on that computer. Check every Microsoft account you’ve ever had — old Hotmail, Outlook, Xbox, whatever.

Your work or school account. On a company machine, the key is stored in Active Directory or Intune. Your IT department can retrieve it in about a minute. This includes machines you kept after leaving a job — which is a real conversation to have with your old employer, but a much shorter one than you’d fear.

A saved file. BitLocker offers to save the key as a .txt file during setup. Search your other computers, cloud storage, and old USB sticks for BitLocker Recovery Key — the file name includes the identifier shown on the prompt screen.

A printout. BitLocker offers to print it too, and plenty of people did. Check the filing cabinet, the desk drawer, the folder with the router password in it.

A USB stick. Some configurations store the key on removable media.

A password manager. Worth searching if one was in use.

When it’s not really BitLocker

A couple of situations look like a lockout but aren’t.

The TPM lost its state. If BIOS was updated, secure boot settings changed, or hardware was swapped, the TPM stops releasing the key automatically and falls back to asking for the recovery key. The encryption is fine and so is your data — you just need the key once to get back in, and reverting the firmware change sometimes clears it without one.

A shucked external drive. If you pulled a drive out of a WD or Seagate enclosure, what you’re seeing may not be BitLocker at all — many external models encrypt in the bridge board itself. Put the drive back in its original enclosure and it may simply work. Detail here.

A drive that’s failing, not locked. If BitLocker metadata sectors are damaged, Windows may prompt for a key on a drive whose real problem is bad sectors. If the drive has also been slow, noisy, or throwing I/O errors, that’s a different conversation — and one where imaging first matters, because further degradation of the encryption header is unrecoverable in a way ordinary file damage isn’t.

Start a Recovery Case

Free evaluation. No data, no charge.

What not to waste effort on

Don’t try to guess. The recovery key is 48 digits. There’s nothing to guess.

Don’t pay anyone claiming they can crack it. If someone offers to break BitLocker without the key for a fee, that’s a scam, full stop. Same family as the other pricing red flags in this industry.

Don’t reinstall Windows hoping to keep the data. It won’t decrypt anything, and it will write over the volume.

Don’t format when Windows offers. If you later find the key in an old email, a formatted volume is a much worse starting point.

If you do find the key

Unlock the drive first, then deal with any other problems. A drive with bad sectors that’s also encrypted has to be unlocked before its contents mean anything — an image of an encrypted volume is an image of noise until the key is applied.

If the drive is failing and you have the key, tell whoever works on it upfront. It changes the order of operations.

The bottom line

BitLocker without the key is a wall, and any honest lab will tell you that on day one instead of taking your money. But most people who think the key is lost haven’t checked account.microsoft.com yet. Start there, then work through your old Microsoft accounts and your IT department before giving up on the drive.


Found the key but the drive still won’t cooperate? Start a case — that usually means a hardware problem underneath the encryption, and it’s worth looking at.

Dealing with this right now?

Describe what's happening and I'll let you know if I can help. No charge to find out.

Start a Recovery Case