TPM · PIN · password · recovery key · startup key · escrow · To Go · Device Encryption
How the drive was locked, and where the key lives. The protector decides what happens when it goes wrong, and where to look first.
BitLocker locks a drive the same way underneath whatever you chose at setup: one key encrypts every sector, a second key encrypts that one, and a protector holds a copy of the second key. The protector is the part you interact with, and it decides what happens when something goes wrong. A TPM-only drive unlocks itself from a chip on the board, so you never see a prompt until the chip's measurements change and it drops to the recovery screen. A PIN or a password is something you type, so it can be forgotten, and a weak one can sometimes be recovered while a strong one cannot. A startup key lives on a USB stick that can be lost. And above all of them sits the 48-digit recovery key, which unlocks the drive when every other protector fails, and which is the first thing to look for. The pages below take each protector in turn: where its key is kept, how to retrieve it, and what it means for getting your data back. Every one of them is recovered only for the drive's owner, behind proof that it is yours.
Rather talk it through? An engineer answers the bench line
0800 6890668
The one idea that makes sense of all of them.
Every protector, and where its key is kept.
Find your recovery key → →How the drive was locked
TPM-onlyNo PIN, no password: the key comes from the chip. A cleared TPM, a dead motherboard, or a BIOS or firmware update changes the chip's measurements and sends the drive to the recovery screen. The recovery key is what you need→TPM and PINA PIN at every boot, held with the chip. A short numeric PIN may be recoverable from a memory image; the chip locks after repeated wrong tries. The recovery key still opens it→PasswordA password protector, common on data drives and BitLocker To Go. A human-memorable password may be recoverable by a dictionary or mask attack; a strong random one is not, and there is no backdoor→Recovery key, or 48-digit passwordThe 48-digit number that unlocks the drive when all else fails. With it the data comes back even from a failed drive. Find it in your Microsoft account, Entra ID, AD or a saved copy before anything else→Startup key on USB (.BEK)Part of the key is a .BEK file on a USB stick, needed at every boot. Lose the stick with no recovery key escrowed and the drive stays sealed→Escrow: AD, Entra ID, Intune, MBAMA work or school machine keeps a copy of the key: Active Directory, Microsoft Entra ID, Intune, or MBAM. Your IT department can read it out; this is the commonest happy ending for a business laptop→Where the key lives
BitLocker To Go, USB and external drivesAn encrypted USB stick or external drive, unlocked by a password or recovery key. Auto-unlock keeps the key on one PC, so the drive needs its password once it is moved→Device Encryption on Windows HomeWindows turned it on by itself and escrowed the key to the Microsoft account you signed in with. The commonest consumer lockout, and usually the easiest to solve once you find that account→Which of these can be recovered, in one place.
Almost always recoverable: any drive whose owner has, or can retrieve, the 48-digit recovery key or the drive's password. That includes every machine sent to the recovery screen by a Windows update, a firmware update, a cleared TPM or a motherboard change, because the data is intact and only the key is needed; and it includes a drive that has physically failed, which is imaged and then decrypted from the clone. A work or school machine whose key is escrowed in Active Directory, Entra ID, Intune or MBAM is in this group, and so is a Windows Home machine whose Device Encryption key is in a Microsoft account.
Sometimes recoverable: a drive locked with a human-chosen password or a short numeric PIN, where the password is weak enough for a dictionary or mask attack, or where the machine is still running or a hibernation file survives so the key can be lifted from memory. The weaker the password and the more that is known about it, the better the odds; a strong random password is not in this group.
Not recoverable by anyone: a modern drive encrypted with AES-256-XTS, protected by TPM only or TPM and a strong PIN, with no recovery key escrowed anywhere, no password protector to attack, and no memory or hibernation capture. There is no backdoor and no feasible way to brute-force the key. We say so at the free look rather than take the work, and we would rather you heard it from us than paid someone who implies otherwise.
The questions that come up first.
What is the difference between the recovery key and the recovery password?
In everyday use, none: both mean the 48-digit number shown on the recovery screen and stored in your Microsoft account, Entra ID or Active Directory. Strictly, Microsoft calls the 48-digit number the recovery password and uses recovery key for a .BEK key file on a USB stick, but when people say recovery key they almost always mean the 48 digits.
I do not know which protector I had. Does it matter?
Not for finding the key. Whatever the protector, the 48-digit recovery key opens the drive, and that is what to look for first. The recovery screen shows the first eight characters of the key's ID, which tells us which stored key matches if you have more than one.
Can you recover any of these without the key?
Only the sometimes-recoverable group above, and only in the conditions described: a weak password, or a memory or hibernation capture. On a modern TPM-sealed AES-256 drive with none of those, no, and no legitimate service can. The honest pages here say which is which.
Do you need the whole computer?
No. Take the drive out and send the drive on its own. Whole laptops and desktops are not accepted. If you cannot remove the drive, the sending-in guide explains what to do.
Start with the key, whatever the protector.
Find your 48-digit recovery key before anything else; the finder page lists every place it could be. If the drive has also failed, or the key is truly lost, tell us what happened and send proof the drive is yours, and the first look will tell you honestly what can be done.