Taking work now — the first look is freeDrives posted in from anywhere in the UK, or handed in at ten drop-off pointsQuicker still, give us a ring:0800 6890668
BLKBitLocker Data Recovery 0800 6890668 Price my job
BLK / How the drive was locked / Device Encryption on Windows Home

Device Encryption · Windows Home · automatic · Microsoft account · account.microsoft.com · 24H2

Windows Home Device Encryption recovery. The encryption you never knew was on, until the blue recovery screen you never set up.

Most people who hit a BitLocker recovery screen on a home laptop never turned BitLocker on, and are adamant they did not, because they did not: Windows did it for them. On Windows Home, a feature called Device Encryption switches encryption on automatically on supported hardware the moment you sign in with a Microsoft account, and escrows the recovery key to that account. It is the same encryption engine as full BitLocker, just automatic and stripped of the controls. You never see it until something, a feature update, a firmware update, a change to the hardware, drops the machine to the recovery screen and asks for a 48-digit key you did not know existed. The good news is that the key almost certainly exists, in the Microsoft account you signed in with, and finding it usually ends the problem in minutes. On newer machines this is more common than ever, because Windows 11 has been enabling Device Encryption by default on clean installs, so a great many ordinary home laptops are now silently encrypted. These drives are recovered only for their owners, and for a home machine that proof is simple; but most owners never need us, because the key is in their account.

Owner-only, proof requiredFree first look£800 + VAT, one diskNo fix, no fee on the balance

Rather talk it through? An engineer answers the bench line
0800 6890668

Stop before you reinstall or reformat anything. If the machine is at the BitLocker recovery screen, the data is intact behind the key; reinstalling Windows, reformatting the drive or clearing the TPM again will not get you in and can overwrite what is there. Do not keep typing the wrong key until a device locks you out. If the machine is still running and unlocked, do not shut it down before you have read the lost-password pages. Find your recovery key first, and send nothing until you have.

The key is in the Microsoft account you signed in with.

Device Encryption escrows its recovery key to the Microsoft account that was signed in when encryption turned on. So the first and usually the only step is to go, from any device, to account.microsoft.com/devices/recoverykey (or aka.ms/myrecoverykey), sign in with that account, and read the 48-digit key shown against the device. Match the key ID on your recovery screen to the one shown online if several devices are listed. Enter the key, and Windows starts.

The usual complication is simply which account. People have more than one Microsoft account, or a family member set the machine up, or it was signed in with an email they have half-forgotten. The key is under whichever account was active when Windows encrypted the drive, so if the obvious account does not show it, try the others, and any account a family member might have used. The finder page has the full list of where else to look if it is genuinely not in any account.

If the drive has also failed, which is when people come to us rather than solving it themselves, the account still holds the key: we image the failed drive and decrypt the image with the key from the account. And if the machine was signed in with a local account rather than a Microsoft account when it encrypted, or the Microsoft account has been deleted, the key may never have been escrowed, and then the usual hard limit applies, which the free look will tell you honestly.

Why a home laptop locks out people who never set up BitLocker.

Windows turned it on automaticallyDevice Encryption is BitLocker without the switch: on supported Home hardware, signing in with a Microsoft account turns encryption on by itself and tells almost no one. That is why the recovery screen feels like it came from nowhere, and why people insist they never enabled BitLocker. They did not; Windows did.
The key went to a Microsoft accountThe same automatic process escrows the recovery key to the Microsoft account you used. It is almost certainly sitting at account.microsoft.com/devices/recoverykey right now, which is why most Device Encryption lockouts are solved in minutes without any recovery work at all.
Windows 11 made it far more commonRecent Windows 11 versions enable Device Encryption by default on clean installs, having relaxed the old hardware requirements. The practical result is that a large and growing share of ordinary home laptops are silently encrypted, so these lockouts, and the shock that goes with them, are rising fast.
A local account is the gapThe one case where the key may not exist is a machine that was signed in with a local account, not a Microsoft account, when it encrypted, or whose Microsoft account has since been deleted. Then nothing was escrowed, and a modern encrypted drive with no key is the hard limit. It is the exception, but it is a real one.

What you see, and what is behind it.

Describe yours to us →
What you see What is usually behind it Where that leaves you
Recovery screen on a home laptop I never encryptedDevice Encryption turned on automaticallyThe key is in your Microsoft account; read it out
Not sure which Microsoft accountThe key is under the one active at encryptionTry each account you or family may have used
Key not in the obvious accountA different or family member's account was usedCheck the others; the finder page lists more places
Home drive failed, key in the accountA hardware job with the key availableImaged, then decrypted with the account's key
Machine used a local account, no key anywhereNothing was ever escrowedNot recoverable; we say so at the free look

From the drive arriving to your files going back.

Work we have closed →
01

Logged the day it lands, and the first look costs nothing Free

A number goes on the parcel and the drive the day it is opened, matched to your enquiry by the booking sheet inside. Before anything is read we check the proof of ownership you sent. The drive is then connected through a write blocker, read-only, and examined: whether it is a healthy drive behind a lost key, or a failing drive behind a known key, is settled here, and so is whether what you want is possible. That first look is free, and you may stop at it owing nothing.

Nothing to pay for lookingProof of ownership checked firstRead-only, nothing written to the drive
02

Imaged at the sector level, before anything else

A drive that answers at all is imaged in full on a hardware imager, behind a write blocker, weak areas last, with a map kept of what could not be read. The image is a copy of the encrypted sectors, so it is useless to anyone without your key, which is a privacy gain in itself. Every later step is done on the image. The original drive is never decrypted, never written to, and never worked on directly.

Sector by sector, behind a write blockerNothing written to the original
03

The physical fault repaired on the clone, when there is one

A drive that has failed, that reads slowly or that drops out is stabilised and imaged in passes; a mechanically failed disk is repaired and read on the bench, a dead SSD controller read at the chip level, before any decryption is attempted. The aim at this stage is one clean image of the encrypted volume to decrypt from. Where the drive is healthy and the problem is only the key, this stage is skipped.

Mechanical and chip-level work where neededOne clean encrypted image to work from
04

The image decrypted with your key or password

With your recovery key, recovery password or the drive's password, the image is unlocked: the protector releases the Volume Master Key, the VMK releases the Full Volume Encryption Key, and the volume is decrypted from the clone. Where the metadata or header is damaged, repair-bde and the key package rebuild it at the block level onto a separate target. Where the key is lost but a memory image or hibernation file is available, the Volume Master Key is extracted from it with Passware. Without a key, a password to attack, or a memory capture, the volume cannot be opened, and you are told so at the free look.

Protector → VMK → FVEK → volumeDecrypted from the clone, never the original
05

The file system rebuilt, and the list before the bill

Once the volume is open it is an ordinary NTFS or exFAT file system, and any damage in it is repaired on the image and the files recovered. What was recovered is listed for you first, and only then does a bill exist. The files go home on fresh media. The original drive is returned, or securely destroyed at your request; we never send the key and the data by the same route.

Files listed before any invoiceFresh media, supplied with the job3–7 days at the bench

From the bench

  • Go to account.microsoft.com/devices/recoverykey first. For a Home laptop lockout the key is almost always there, and it ends the problem in minutes.
  • Try every Microsoft account you or your family might have used. The key is under whichever was signed in when Windows encrypted the drive, which is not always the obvious one.
  • You probably do not need us. We are for failed drives and genuine local-account gaps; most Device Encryption lockouts are solved by finding the account.

Clean installs of Windows 11 now enable Device Encryption by default, so far more home laptops are silently encrypted than their owners realise.

One job, followed all the way through.

UK · BLK-2026-0707JOB LOGGED ✓

A home laptop that dropped to the BitLocker recovery screen after a Windows update, whose retired owner was certain they had never used BitLocker, with years of photographs on it

They were right that they never set it up; Device Encryption had. The drive was healthy, so this needed no recovery work at all. We established which Microsoft account the laptop had been set up with, had the owner sign in to account.microsoft.com/devices/recoverykey on a tablet, and the 48-digit key was there against the device. It started on the first try. We charged nothing beyond the free look and told them where to keep the key for next time.

100% intact; key found in the accountSame day once the account was identified
Illustrative example — replace with a genuine case

What helps, and what harms.

Do this much first

  • Go to account.microsoft.com/devices/recoverykey first
  • Try every Microsoft account you or family may have used
  • Match the key ID on the screen to the one shown online
  • Come to us for a failed drive, or if no account has the key

What sets us back

  • Insisting BitLocker is not on; on Home, Windows turns it on itself
  • Reinstalling Windows, which overwrites the photographs
  • Reformatting at the recovery screen
  • Assuming the key is lost before checking every account
We recover BitLocker drives for the people who own them. Before any work begins we ask for proof that the drive is yours or that you are authorised to have it recovered: a purchase receipt, the device serial, a letter on company letterhead for a work machine, or written authorisation from the owner, together with photo ID and a signed authorisation. It is a condition of the work, not a formality, and it is what keeps the service on the right side of the Computer Misuse Act. A drive with no proof of ownership is returned unread.

Questions answered before you commit.

I never turned on BitLocker. Why is my home laptop asking for a key?

Because Windows turned it on for you. On Windows Home, Device Encryption encrypts the drive automatically when you sign in with a Microsoft account, and escrows the key to that account. Go to account.microsoft.com/devices/recoverykey, sign in, and the 48-digit key is almost certainly there.

Where is my Device Encryption recovery key?

In the Microsoft account that was signed in when the drive encrypted, at account.microsoft.com/devices/recoverykey or aka.ms/myrecoverykey. If the obvious account does not show it, try any other account you or a family member might have used to set the machine up.

Why is this happening on new laptops so much?

Recent Windows 11 versions enable Device Encryption by default on clean installs, so far more home laptops are silently encrypted than before. The encryption is fine; people simply do not know it is on until an update sends them to the recovery screen, and then they need the key from their account.

What if the laptop used a local account and there is no key?

Then the key may never have been escrowed, and on a modern encrypted drive with no key the data cannot be recovered by anyone. It is the exception rather than the rule, and we tell you honestly at the free look whether that is your situation.

What does it cost?

If the key is in your account and the drive is healthy, finding it costs nothing from us, and you may not need us at all. A failed home drive falls under single-disk recovery at £800 + VAT, 50% non-refundable on acceptance and 50% no fix, no fee.

The data is behind the key, not gone.

Looking at it is free, and it begins with the one question that decides everything: do you have the recovery key or password, or can you retrieve it. Tell us what the recovery screen says and what the drive has done, send the proof that it is yours, and back comes a straight account of what is possible and the one price to do it. Until then, reinstall nothing and reformat nothing.

0800 6890668