Taking work now — the first look is freeDrives posted in from anywhere in the UK, or handed in at ten drop-off pointsQuicker still, give us a ring:0800 6890668
BLKBitLocker Data Recovery 0800 6890668 Price my job
BLK / Makes and drives / Microsoft Surface

Microsoft Surface · Surface Pro · Surface Laptop · Device Encryption · soldered SSD · Microsoft account

Microsoft Surface BitLocker recovery. Microsoft's hardware, Microsoft's encryption, and usually Microsoft's account holding the key.

A Microsoft Surface is the most integrated BitLocker case there is: Microsoft's own hardware, running Microsoft's firmware and Microsoft's encryption. Device Encryption is usually on by default, turned on automatically when the owner signed in with a Microsoft account, and the recovery key is usually escrowed to that same account. So a Surface Pro or Surface Laptop that lands at the BitLocker recovery screen, after a Windows update or a firmware update, is almost always a find-the-key-in-the-account job: the data is intact, and the 48-digit key is sitting at account.microsoft.com/devices/recoverykey under the Microsoft account the Surface was set up with. The one complication particular to Surface is hardware: the SSD is soldered to the board on many models, so if the Surface itself has failed, recovering the drive is a board-level job rather than a matter of removing a drive. With the key, though, even that is recoverable. These are recovered only for their owners, which for a personal Surface is straightforward.

Owner-only, proof requiredFree first look£800 + VAT, one diskThe honest answer either way

Rather talk it through? An engineer answers the bench line
0800 6890668

Stop before you reinstall or reformat anything. If the machine is at the BitLocker recovery screen, the data is intact behind the key; reinstalling Windows, reformatting the drive or clearing the TPM again will not get you in and can overwrite what is there. Do not keep typing the wrong key until a device locks you out. If the machine is still running and unlocked, do not shut it down before you have read the lost-password pages. Find your recovery key first, and send nothing until you have.

Why a Surface lockout is usually a find-the-key job.

On a Surface, Device Encryption is typically enabled automatically the moment the owner signs in with a Microsoft account, and the recovery key is escrowed to that account at the same time. So when a Surface reaches the recovery screen, after a Windows feature update or a Surface firmware update changes the boot measurements, the key is almost certainly already stored where the owner can reach it: account.microsoft.com/devices/recoverykey, under the Microsoft account the Surface uses.

The data is intact; this is the easy kind of lockout. Sign in to the account from any device, read the 48-digit key against the Surface, enter it, and the machine starts. The usual snag is simply which Microsoft account the Surface was set up with, so if the obvious one does not show the key, try the others the owner or household might have used. The finder page has the full list.

The Surface-specific issue is hardware. On many Surface models the SSD is soldered to the mainboard, not a removable drive, so if the Surface itself has failed, recovering the data is a board-level operation, reading the soldered storage directly, rather than pulling a drive and imaging it. It is more involved, but with the recovery key the encrypted data is still recoverable once the storage is read. Tell us the exact Surface model, because what is possible physically varies across the range.

What to know about Surface and BitLocker.

Device Encryption is usually onA Surface almost always has Device Encryption enabled automatically, so it is encrypted whether or not the owner realised. That is why a Surface recovery screen surprises people, and why the key is almost always already in their Microsoft account.
The key is in the Microsoft accountThe recovery key is escrowed to the Microsoft account the Surface was set up with, at account.microsoft.com/devices/recoverykey. For a Surface lockout, that is the first and usually the only place to look, and it ends the problem in minutes.
The SSD is often solderedMany Surface models solder the SSD to the board, so a failed Surface is a board-level recovery rather than a drive you can remove and send. With the recovery key the encrypted data is still recoverable, but the physical work is more involved and varies by model.
Tell us the exact modelWhat is physically possible on a failed Surface depends closely on the model and generation, from fully soldered storage to a removable SSD on some later models. The exact model tells us what the hardware allows before anything else.

What you see, and what is behind it.

Describe yours to us →
What you see The usual reason Where that leaves you
Surface recovery screen after a Windows updateThe update changed the boot measurementsThe key is in your Microsoft account; enter it
Not sure which Microsoft account set it upThe key is under that specific accountTry each account you or household used
Surface itself has failed, SSD solderedA board-level recovery, not a removable driveThe soldered storage is read; then decrypted with the key
Later Surface with a removable SSD, failedA removable drive after allRemoved, imaged, then decrypted with the key
Key not in any account, modern SurfaceNothing was escrowed, or the account is lostHonestly assessed free; may not be recoverable

From the drive arriving to your files going back.

Work we have closed →
01

Logged the day it lands, and the first look costs nothing Free

A number goes on the parcel and the drive the day it is opened, matched to your enquiry by the booking sheet inside. Before anything is read we check the proof of ownership you sent. The drive is then connected through a write blocker, read-only, and examined: whether it is a healthy drive behind a lost key, or a failing drive behind a known key, is settled here, and so is whether what you want is possible. That first look is free, and you may stop at it owing nothing.

Nothing to pay for lookingProof of ownership checked firstRead-only, nothing written to the drive
02

Imaged at the sector level, before anything else

A drive that answers at all is imaged in full on a hardware imager, behind a write blocker, weak areas last, with a map kept of what could not be read. The image is a copy of the encrypted sectors, so it is useless to anyone without your key, which is a privacy gain in itself. Every later step is done on the image. The original drive is never decrypted, never written to, and never worked on directly.

Sector by sector, behind a write blockerNothing written to the original
03

The physical fault repaired on the clone, when there is one

A drive that has failed, that reads slowly or that drops out is stabilised and imaged in passes; a mechanically failed disk is repaired and read on the bench, a dead SSD controller read at the chip level, before any decryption is attempted. The aim at this stage is one clean image of the encrypted volume to decrypt from. Where the drive is healthy and the problem is only the key, this stage is skipped.

Mechanical and chip-level work where neededOne clean encrypted image to work from
04

The image decrypted with your key or password

With your recovery key, recovery password or the drive's password, the image is unlocked: the protector releases the Volume Master Key, the VMK releases the Full Volume Encryption Key, and the volume is decrypted from the clone. Where the metadata or header is damaged, repair-bde and the key package rebuild it at the block level onto a separate target. Where the key is lost but a memory image or hibernation file is available, the Volume Master Key is extracted from it with Passware. Without a key, a password to attack, or a memory capture, the volume cannot be opened, and you are told so at the free look.

Protector → VMK → FVEK → volumeDecrypted from the clone, never the original
05

The file system rebuilt, and the list before the bill

Once the volume is open it is an ordinary NTFS or exFAT file system, and any damage in it is repaired on the image and the files recovered. What was recovered is listed for you first, and only then does a bill exist. The files go home on fresh media. The original drive is returned, or securely destroyed at your request; we never send the key and the data by the same route.

Files listed before any invoiceFresh media, supplied with the job3–7 days at the bench

From the bench

  • Check account.microsoft.com/devices/recoverykey first. A Surface's key is almost always there, under the Microsoft account it was set up with.
  • Tell us the exact Surface model. Whether the SSD is soldered or removable, and so what a failed-Surface recovery involves, depends on it.
  • A soldered-SSD Surface is still recoverable with the key, but it is board-level work, not a drive you can remove and post.

Device Encryption is on by default on a Surface, so the key is almost always already in the owner's Microsoft account.

What helps, and what harms.

Do this much first

  • Check account.microsoft.com/devices/recoverykey first
  • Try every Microsoft account the Surface might have used
  • Tell us the exact Surface model for a failed unit
  • Send proof the Surface is yours if it needs lab work

What sets us back

  • Assuming a Surface is not encrypted; Device Encryption usually is on
  • Reinstalling Windows over intact data
  • Trying to prise a soldered SSD off yourself
  • Reformatting at the recovery screen
We recover BitLocker drives for the people who own them. Before any work begins we ask for proof that the drive is yours or that you are authorised to have it recovered: a purchase receipt, the device serial, a letter on company letterhead for a work machine, or written authorisation from the owner, together with photo ID and a signed authorisation. It is a condition of the work, not a formality, and it is what keeps the service on the right side of the Computer Misuse Act. A drive with no proof of ownership is returned unread.

Questions answered before you commit.

Why is my Surface asking for a BitLocker key?

Because Surfaces almost always have Device Encryption enabled automatically, and a Windows or firmware update changed the boot measurements the TPM checks, so it asked for the recovery key. Your data is intact, and the key is almost certainly in the Microsoft account your Surface was set up with, at account.microsoft.com/devices/recoverykey.

Where is my Surface's recovery key?

In the Microsoft account the Surface was set up with, at account.microsoft.com/devices/recoverykey or aka.ms/myrecoverykey. If the obvious account does not show it, try any other account you or your household might have used to sign in to the Surface.

My Surface has died. Can you recover the data if the SSD is soldered?

Yes, with the recovery key, though it is more involved. On models where the SSD is soldered to the board, we read the soldered storage at the board level rather than removing a drive, then decrypt the recovered data with your key. Tell us the exact model, as the hardware varies across the range.

Do I need to send the whole Surface if it has failed?

For a soldered-SSD model, yes, because the storage cannot be separated from the board; this is the exception to our drive-only rule, and we will tell you so when you give us the model. For a later model with a removable SSD, the drive alone is enough.

What does it cost?

If the key is in your account and the Surface works, finding it costs nothing from us. A failed Surface, including board-level work on a soldered SSD, is a single disk at £800 + VAT, 50% non-refundable on acceptance and 50% no fix, no fee, the same as any other drive.

The data is behind the key, not gone.

Looking at it is free, and it starts with whether you have the recovery key or can retrieve it. Tell us the make and model, what the recovery screen says, and what happened just before it, and send proof the drive is yours. Back comes a straight account of what is possible and the one price to do it. Until then, reinstall nothing and reformat nothing.

0800 6890668