Microsoft account · Entra ID · Active Directory · Intune · MBAM · saved file · printout · USB key
How to find your BitLocker recovery key. It was almost certainly saved somewhere when BitLocker was switched on. Here is everywhere to look.
If your computer is asking for a 48-digit BitLocker recovery key, the key almost certainly exists, because BitLocker escrows it somewhere when it is switched on, and entering it will open the drive with your data intact. This page is the complete list of where it could be, in the order most people find it. Work through it before you consider anything drastic, because reinstalling Windows or reformatting the drive, which some people try in desperation, writes over the data the key would recover. The recovery screen also shows a key ID, the first eight characters of the identifier for the key that drive wants, which tells you which key to use if you have more than one. Start at the top: for a home laptop the key is usually in your Microsoft account, and for a work laptop it is usually held by your IT department.
Rather talk it through? An engineer answers the bench line
0800 6890668
Every place your recovery key could be.
1. Your personal Microsoft account (the most common place). If this is a home laptop, and especially a Windows Home machine, Windows most likely turned on Device Encryption automatically and escrowed the key to the Microsoft account you signed in with. From any device, go to account.microsoft.com/devices/recoverykey (or the short link aka.ms/myrecoverykey), sign in, and you will see the recovery keys stored against your devices. Match the key ID on your recovery screen to the one shown online. The single most common reason people do not find it here is that they try the wrong Microsoft account, so try every account you or your household might have used to set the machine up, including an old email address.
2. Your work or school account, in Microsoft Entra ID. If the machine belongs to an employer or a school, the key is almost certainly escrowed in the organisation's Microsoft Entra ID (formerly Azure AD). You can look at aka.ms/aadrecoverykey, signing in with your work or school account, and view the BitLocker keys stored against your device; or, more usually, your IT department or administrator reads it out for you. This is the quickest route for a company laptop.
3. On-premises Active Directory (for a traditional company domain). Many organisations store the key in on-premises Active Directory, against the computer object, as the msFVE-RecoveryPassword attribute. Your IT department reads it with the BitLocker Recovery Password Viewer in Active Directory Users and Computers, or with PowerShell, matching the key ID on your screen to the record. You will not do this yourself; ask IT.
4. Intune or MBAM (for managed devices). If your device is managed with Microsoft Intune, the recovery key is visible to administrators in the device's properties in the Intune admin centre. Older managed estates use MBAM, Microsoft BitLocker Administration and Monitoring, which stores keys centrally and issues single-use keys, so a key that worked before will have expired and your administrator retrieves the current one. Again, this is a job for IT.
5. A printout, a saved text file, or a USB key file. When BitLocker is turned on manually, it offers to print the key, save it to a text file, or save it to a USB stick as a small key file. So check: any printout filed with your important papers; a file named something like BitLocker Recovery Key.txt on a USB stick, another drive, or in your cloud storage; and a .BEK file on a USB stick. People who deliberately enabled BitLocker often saved it this way and forgot.
How the key ID helps.
The blue recovery screen shows a key ID, the first eight characters of the identifier for the key that particular drive needs. If you have several encrypted devices, or several keys in your Microsoft account, this is how you tell which key is the right one: find the stored key whose ID begins with those same eight characters. A key whose ID does not match will be refused no matter how carefully you type it, so always check the ID first.
What if it is not in any of these places?
Then it may never have been escrowed, which happens most often when a machine was signed in with a local account rather than a Microsoft account when it encrypted, or when the Microsoft account it used has since been deleted. Microsoft is explicit that it cannot access or reset a lost BitLocker recovery key; there is no master key and no backdoor. At that point, whether your data can be recovered depends on what else is true about the drive, a weak password that can be attacked, or a memory capture if the machine is still running, and for a modern AES-256 drive with none of those, the honest answer is that it cannot be recovered. The lost-key page and the when-it-cannot-be-recovered page explain this honestly, and we assess it free.
The two quickest routes, by machine.
The questions that come up first.
What is the fastest way to find my BitLocker recovery key?
For a home laptop, go straight to account.microsoft.com/devices/recoverykey and sign in with the Microsoft account the machine was set up with. For a work laptop, ask your IT department to read it from the organisation's directory. Those two routes solve the great majority of lockouts in minutes.
I have tried my Microsoft account and the key is not there. What now?
Try every other Microsoft account you or your household might have used, as the key is under whichever account was signed in when the drive encrypted, which is not always the obvious one. If it is genuinely in no account, no directory and no saved copy, it may never have been escrowed, and Microsoft cannot recreate it; the lost-key page explains what is still possible.
What does the key ID on the recovery screen mean?
It is the first eight characters of the identifier for the specific key that drive wants. If you have several keys, match those eight characters to the key ID shown beside each stored key, and use the one that matches. It stops you trying a key from a different device.
Can you find my recovery key for me?
The key is in your own account or your organisation's records, so you or your IT department retrieve it, not us, and that is free. We are for when the key is genuinely lost and the data matters, or when the drive has failed, and we assess those honestly at the free look.
Is my data safe while I look for the key?
Yes, as long as you do not reinstall Windows or reformat the drive. At the recovery screen the data is intact behind the key; those two actions are the only genuinely destructive mistakes, because they write over the data the key would recover. Take your time finding the key.
Find the key, and the drive opens.
Work through the places above, starting with your Microsoft account for a home machine or your IT department for a work one. If the key is genuinely nowhere, or the drive has also failed, tell us what happened and we will tell you honestly what can be done.