Taking work now — the first look is freeDrives posted in from anywhere in the UK, or handed in at ten drop-off pointsQuicker still, give us a ring:0800 6890668
BLKBitLocker Data Recovery 0800 6890668 Price my job
BLK / Makes and drives

The laptops that prompt for the key, and the drives inside them

BitLocker by make, and by drive. The make decides what sends it to the recovery screen. The key decides how you get back in.

The make of a laptop does not change how BitLocker works, but it does change what sends a machine to the recovery screen, because the thing that most often does it is a firmware update, and every maker pushes those differently. Dell, Lenovo and HP all send firmware updates through Windows Update, so a BitLocker machine can land at the recovery screen after an update the owner never consciously ran. A Microsoft Surface is the tightest-integrated of all, Microsoft's own hardware running Microsoft's encryption. The drive inside matters too: most modern SSDs encrypt with BitLocker's software encryption, but some are self-encrypting hardware drives, and a few years ago Microsoft changed how it trusts those, which is worth understanding. The pages below take the common makes and the common drives in turn. The message is the same for all of them, though: a firmware update or a hardware change sends the machine to the recovery screen, the data is intact, and the 48-digit recovery key is what opens it. Every recovery here is done for the drive's owner, behind proof of ownership.

Owner-only, proof requiredFree first look£800 + VAT, one diskThe honest answer either way

Rather talk it through? An engineer answers the bench line
0800 6890668

Stop before you reinstall or reformat anything. If the machine is at the BitLocker recovery screen, the data is intact behind the key; reinstalling Windows, reformatting the drive or clearing the TPM again will not get you in and can overwrite what is there. Do not keep typing the wrong key until a device locks you out. If the machine is still running and unlocked, do not shut it down before you have read the lost-password pages. Find your recovery key first, and send nothing until you have.

What the make changes, and what it does not.

Firmware updates are the common triggerDell, Lenovo, HP and the rest deliver firmware updates through Windows Update, and firmware is part of the boot chain the TPM measures. So an update the owner barely noticed can send a BitLocker machine to the recovery screen. The data is intact; the key opens it; suspending BitLocker before a known firmware update avoids it.
Surface is Microsoft end to endA Microsoft Surface runs Microsoft's encryption on Microsoft's hardware with Microsoft's firmware, the most integrated case. Device Encryption is usually on, the key is usually in the owner's Microsoft account, and a Surface lockout is usually a find-the-key-in-the-account job.
The drive inside decides software or hardware encryptionMost SSDs are encrypted by BitLocker's own software encryption. Some drives are self-encrypting hardware drives, and Microsoft changed in 2019 how far it trusts hardware encryption after weaknesses were found in some drives, defaulting to software encryption instead. It is worth knowing which your drive used, and the self-encrypting page explains why.
The fix does not vary by makeWhatever the badge, a BitLocker machine at the recovery screen holds intact data behind a key, and the 48-digit recovery key opens it. A failed drive of any make is imaged and decrypted with the key. The make tells us what to expect; it does not change the route back in.

Every make and drive, with a page.

Find your recovery key → →

Where the key is, by kind of machine.

A personal laptop, of any make, running Windows Home with Device Encryption, almost always has its key in the Microsoft account the owner signed in with, at account.microsoft.com/devices/recoverykey. A personal machine with full BitLocker turned on deliberately may have the key in a Microsoft account, a saved file, or a printout. The finder page covers both.

A work or school laptop, again of any make, almost always has its key escrowed in the organisation's directory, Active Directory, Microsoft Entra ID, Intune or MBAM, where IT can read it out. The make of the laptop is irrelevant to this; what matters is that it is managed, and managed machines escrow their keys by design. The escrow page explains how.

So the make helps us anticipate the trigger, a Dell firmware push, a Surface update, an AMD fTPM reset on a particular laptop, but the key is found by the kind of account, not the badge. Identify whether the machine is personal or managed, find the key in the matching place, and almost any make's recovery screen is solved. We are for the cases where the key is lost or the drive has failed, whatever the make.

The questions that come up first.

Does the make of my laptop change whether BitLocker can be recovered?

No. The make changes what sends a machine to the recovery screen, usually a firmware update, but not how recovery works. A BitLocker drive of any make is opened by the 48-digit recovery key, and a failed one of any make is imaged and decrypted with the key. The route back in is the same for all of them.

Why does my Dell, Lenovo or HP ask for a key after an update?

Because these makers deliver firmware updates through Windows Update, and firmware is part of the boot chain the TPM measures. An update you barely noticed changed those measurements, so the TPM withheld its key and BitLocker asked for the recovery key. The data is intact; the key opens it.

Where is the key for my particular make of laptop?

It depends on whether the machine is personal or managed, not on the make. A personal Windows Home laptop usually has its key in the owner's Microsoft account; a work laptop of any make usually has it escrowed in the organisation's directory. The finder page lists both.

Is a Surface different from other laptops for BitLocker?

Only in being the most integrated: Microsoft hardware, firmware and encryption together. In practice that usually means Device Encryption is on and the key is in the owner's Microsoft account, so a Surface lockout is typically a find-the-key job. The recovery route is the same as any other make.

Find the key by the account, whatever the badge.

Work out whether the machine is personal or managed, find the key in the matching place, and almost any make's recovery screen is solved. If the key is lost or the drive has failed, tell us the make and model and send proof it is yours, and the first look will tell you honestly what can be done.

0800 6890668