Startup key · .BEK external key · USB stick · no-TPM boot · recovery key
BitLocker startup-key recovery. A key that lives on a USB stick, and a drive that will not start without it.
A startup key puts part of the unlock on a USB stick: at every boot the stick must be present, and BitLocker reads a .BEK external key file from it to release the drive. It is used on machines with no TPM, or where an administrator wanted the key physically separated from the computer. The weakness is obvious in hindsight: lose the stick, or let it fail, and the machine will not boot. As always, the 48-digit recovery key opens the drive without the stick, so a lost startup key is a find-the-recovery-key job first. Where the stick itself still exists but is failing or will not read, the .BEK file can often be recovered from it like any other small file. Where both the stick and the recovery key are gone, a startup-key drive is in the same hard place as any other BitLocker drive with no openable protector. The data is intact throughout; the question, as ever, is whether a key can be found. These drives are recovered only for their owners, behind proof of ownership.
Rather talk it through? An engineer answers the bench line
0800 6890668
The recovery key, or the file on the stick.
Two things can open a startup-key drive: the 48-digit recovery key, and the .BEK startup-key file itself. Look for the recovery key first, in the usual places, your Microsoft account, your organisation's Entra ID or Active Directory, Intune or MBAM, or a saved copy, all covered on the finder page. With the recovery key you do not need the stick at all.
If you still have the USB stick but it will not read or has failed, that is a flash-recovery problem: the .BEK file is small, and recovering it from a failing or formatted stick is the same kind of work as recovering any file from flash. Once the .BEK is back, it unlocks the drive as it always did. Send the stick with the drive and tell us what happened to it.
If both the stick and the recovery key are gone, a startup-key drive has no protector left that can be opened, and on a modern AES-256 drive that is the hard limit: not recoverable by anyone. The honest answer comes at the free look. As with every protector, the lesson is that the recovery key is the thing to keep safe, because it opens the drive when the special hardware, here a USB stick, is lost.
A key on a stick, and what happens when it is gone.
What you see, and what is behind it.
Describe yours to us →| What you see | What is usually behind it | Where that leaves you |
|---|---|---|
| Lost the USB startup-key stick | A missing protector, not lost data | Open with the 48-digit recovery key |
| Stick exists but will not read | A failing or formatted flash stick | The .BEK file is usually recoverable from it |
| Machine will not boot, stick in hand but corrupt | The .BEK file is damaged | Recovered from the stick, or use the recovery key |
| No stick and no recovery key, modern drive | No openable protector left | Not recoverable; we say so at the free look |
| Drive also failed, recovery key held | A physical job with the key in hand | Imaged, then decrypted from the clone |
From the drive arriving to your files going back.
Work we have closed →Logged the day it lands, and the first look costs nothing Free
A number goes on the parcel and the drive the day it is opened, matched to your enquiry by the booking sheet inside. Before anything is read we check the proof of ownership you sent. The drive is then connected through a write blocker, read-only, and examined: whether it is a healthy drive behind a lost key, or a failing drive behind a known key, is settled here, and so is whether what you want is possible. That first look is free, and you may stop at it owing nothing.
Imaged at the sector level, before anything else
A drive that answers at all is imaged in full on a hardware imager, behind a write blocker, weak areas last, with a map kept of what could not be read. The image is a copy of the encrypted sectors, so it is useless to anyone without your key, which is a privacy gain in itself. Every later step is done on the image. The original drive is never decrypted, never written to, and never worked on directly.
The physical fault repaired on the clone, when there is one
A drive that has failed, that reads slowly or that drops out is stabilised and imaged in passes; a mechanically failed disk is repaired and read on the bench, a dead SSD controller read at the chip level, before any decryption is attempted. The aim at this stage is one clean image of the encrypted volume to decrypt from. Where the drive is healthy and the problem is only the key, this stage is skipped.
The image decrypted with your key or password
With your recovery key, recovery password or the drive's password, the image is unlocked: the protector releases the Volume Master Key, the VMK releases the Full Volume Encryption Key, and the volume is decrypted from the clone. Where the metadata or header is damaged, repair-bde and the key package rebuild it at the block level onto a separate target. Where the key is lost but a memory image or hibernation file is available, the Volume Master Key is extracted from it with Passware. Without a key, a password to attack, or a memory capture, the volume cannot be opened, and you are told so at the free look.
The file system rebuilt, and the list before the bill
Once the volume is open it is an ordinary NTFS or exFAT file system, and any damage in it is repaired on the image and the files recovered. What was recovered is listed for you first, and only then does a bill exist. The files go home on fresh media. The original drive is returned, or securely destroyed at your request; we never send the key and the data by the same route.
From the bench
- Look for the recovery key before worrying about the stick. It opens the drive without the stick and skips the flash-recovery step entirely.
- If the stick still exists, send it with the drive. The .BEK file is small and often recoverable even from a failing stick.
- Keep the recovery key separate from the startup stick. Storing both together means one loss takes out both routes in.
What helps, and what harms.
Do this much first
- Find the recovery key first; it replaces the lost stick
- Send the USB stick with the drive if it still exists
- Tell us what happened to the stick
- Send proof the drive is yours
What sets us back
- Assuming a lost stick means lost data; the recovery key opens it
- Reformatting the USB stick, which overwrites the .BEK file
- Storing the recovery key on the same stick as the startup key
- Reinstalling Windows while the recovery key is still findable
Questions answered before you commit.
I lost the USB stick my computer needs to start. Is the data gone?
No. The stick holds a startup-key file, and the 48-digit recovery key opens the drive without it. Find the recovery key in your account or a saved copy, boot, and you are in. The data was never in question.
Can you recover the startup-key file from a failing USB stick?
Usually, yes. The .BEK file is small, and recovering it from a failing or accidentally formatted stick is ordinary flash recovery. Send the stick with the drive and tell us what happened to it; once the file is back it unlocks the drive as before.
What if I have lost both the stick and the recovery key?
Then a startup-key drive has no protector left that can be opened, and on a modern AES-256 drive the data cannot be recovered by anyone. We tell you that honestly at the free look rather than take work that cannot succeed.
Why does my computer need a USB stick to boot at all?
Because it was set up with a startup-key protector, common on machines without a TPM or where the key was deliberately kept off the computer. The stick carries part of the unlock. The recovery key is the fallback for when the stick is unavailable.
What does it cost?
If the recovery key is to hand, it opens the drive at no cost beyond the free look. Recovering the .BEK from a failing stick, or decrypting a failed drive, falls under single-disk recovery at £800 + VAT, 50% non-refundable on acceptance and 50% no fix, no fee.
Begin here if yours is doing the same thing.
The data is behind the key, not gone.
Looking at it is free, and it begins with the one question that decides everything: do you have the recovery key or password, or can you retrieve it. Tell us what the recovery screen says and what the drive has done, send the proof that it is yours, and back comes a straight account of what is possible and the one price to do it. Until then, reinstall nothing and reformat nothing.