Taking work now — the first look is freeDrives posted in from anywhere in the UK, or handed in at ten drop-off pointsQuicker still, give us a ring:0800 6890668
BLKBitLocker Data Recovery 0800 6890668 Price my job

TPM-only · no PIN · PCR measurements · cleared TPM · motherboard · BIOS · fTPM · PTT

TPM-only BitLocker recovery. The drive that never asked for anything, until the chip changed and it asked for everything.

A TPM-only drive is the quiet one: no PIN, no password, no USB stick. At every boot the Trusted Platform Module on the motherboard measures the early startup state, and if the measurements match what they were when BitLocker was switched on, the chip releases the key and Windows starts with no prompt at all. The owner can go years without seeing a recovery screen. Then something changes what the chip measures, the chip refuses to release the key, and BitLocker falls back to the one protector that does not depend on the hardware: the 48-digit recovery key. The data is completely intact; the drive has simply stopped trusting the machine around it. The triggers are everyday events: clearing or resetting the TPM, replacing the motherboard or CPU, a BIOS or UEFI firmware update, turning Secure Boot on or off, or moving the drive to another computer. On AMD systems a BIOS update or a CPU change can reinitialise the firmware TPM on its own, and a TPM-only machine will not boot afterwards without the recovery key. The fix is almost never recovery in the data sense; it is finding the key. These drives are recovered for their owners, behind proof of ownership.

Owner-only, proof requiredFree first look£800 + VAT, one diskNo fix, no fee on the balance

Rather talk it through? An engineer answers the bench line
0800 6890668

Stop before you reinstall or reformat anything. If the machine is at the BitLocker recovery screen, the data is intact behind the key; reinstalling Windows, reformatting the drive or clearing the TPM again will not get you in and can overwrite what is there. Do not keep typing the wrong key until a device locks you out. If the machine is still running and unlocked, do not shut it down before you have read the lost-password pages. Find your recovery key first, and send nothing until you have.

Where the key is, when the chip will not give it up.

A TPM-only machine at the recovery screen is asking for the 48-digit recovery key, and the recovery screen shows the first eight characters of that key's ID so you can tell which one you need. It is in one of a small number of places, and the finder page walks through each: a personal Microsoft account at account.microsoft.com/devices/recoverykey, if Device Encryption or BitLocker was set up under that account; a work or school account in Microsoft Entra ID at aka.ms/aadrecoverykey; on-premises Active Directory, where a company stores it as the msFVE-RecoveryPassword attribute and IT reads it with the recovery password viewer; Intune or MBAM for managed devices; or a printed copy, a saved text file, or a .BEK file on a USB stick from when BitLocker was turned on.

If you find the key, you often do not need us at all: enter it at the recovery screen and Windows starts; then, if you like, suspend and resume BitLocker so it re-reads the current TPM state and stops prompting. We are for the cases where the key cannot be found and the data matters, where the drive has also failed, or where a business needs the recovery done under proof of authority with a clean chain of custody.

Microsoft is explicit that it cannot access or reset a lost BitLocker recovery key. If the key is in none of the places above, and the drive is a modern AES-256-XTS TPM-only drive, the honest position is that the data cannot be recovered, and we will tell you that at the free look rather than take work that cannot succeed.

What a TPM-only lockout is, and is not.

It is not data lossNothing on the drive has changed. The volume is intact and will mount the instant the correct key is entered. The problem is entirely that the chip will not hand over its copy of the key, and another copy, the recovery key, exists for exactly this.
The TPM clear is the common causeClearing the TPM, in the BIOS or through Windows security settings, destroys the chip's stored key copy. People do it to fix an unrelated problem, or a firmware update does it for them. After a clear, a TPM-only drive can only be opened with the recovery key, so find the key before clearing a TPM, never after.
Firmware and board changes do it tooA BIOS or UEFI update changes the measured early-boot state; a new motherboard has a different TPM entirely; a CPU swap on AMD can reinitialise the firmware TPM. Each leaves the data intact and the drive asking for the recovery key. None of them is a reason to reinstall Windows, which would overwrite the data you are trying to reach.
TPM-only is the least recoverable without the keyBecause there is no PIN or password to attack, a TPM-only drive with a genuinely lost key and no escrow copy offers nothing to work with except a memory or hibernation capture, if the machine is still running. Once it is powered off at the recovery screen, even that route is gone. This is the configuration where finding the key matters most.

What you see, and what is behind it.

Describe yours to us →
What you see What is usually behind it Where that leaves you
Recovery screen after a BIOS or firmware updateThe measured boot state changedEnter the recovery key; the data is intact
Recovery screen after clearing the TPMThe chip's key copy was destroyedOnly the recovery key opens it now
Recovery screen after a new motherboardA different TPM, different measurementsThe recovery key, or move the old drive back
Will not boot after an AMD BIOS or CPU changeThe firmware TPM reinitialised itselfThe recovery key; nothing is wrong with the data
Key cannot be found, modern AES-256 driveNo protector left that can be openedHonestly, not recoverable; we say so free

From the drive arriving to your files going back.

Work we have closed →
01

Logged the day it lands, and the first look costs nothing Free

A number goes on the parcel and the drive the day it is opened, matched to your enquiry by the booking sheet inside. Before anything is read we check the proof of ownership you sent. The drive is then connected through a write blocker, read-only, and examined: whether it is a healthy drive behind a lost key, or a failing drive behind a known key, is settled here, and so is whether what you want is possible. That first look is free, and you may stop at it owing nothing.

Nothing to pay for lookingProof of ownership checked firstRead-only, nothing written to the drive
02

Imaged at the sector level, before anything else

A drive that answers at all is imaged in full on a hardware imager, behind a write blocker, weak areas last, with a map kept of what could not be read. The image is a copy of the encrypted sectors, so it is useless to anyone without your key, which is a privacy gain in itself. Every later step is done on the image. The original drive is never decrypted, never written to, and never worked on directly.

Sector by sector, behind a write blockerNothing written to the original
03

The physical fault repaired on the clone, when there is one

A drive that has failed, that reads slowly or that drops out is stabilised and imaged in passes; a mechanically failed disk is repaired and read on the bench, a dead SSD controller read at the chip level, before any decryption is attempted. The aim at this stage is one clean image of the encrypted volume to decrypt from. Where the drive is healthy and the problem is only the key, this stage is skipped.

Mechanical and chip-level work where neededOne clean encrypted image to work from
04

The image decrypted with your key or password

With your recovery key, recovery password or the drive's password, the image is unlocked: the protector releases the Volume Master Key, the VMK releases the Full Volume Encryption Key, and the volume is decrypted from the clone. Where the metadata or header is damaged, repair-bde and the key package rebuild it at the block level onto a separate target. Where the key is lost but a memory image or hibernation file is available, the Volume Master Key is extracted from it with Passware. Without a key, a password to attack, or a memory capture, the volume cannot be opened, and you are told so at the free look.

Protector → VMK → FVEK → volumeDecrypted from the clone, never the original
05

The file system rebuilt, and the list before the bill

Once the volume is open it is an ordinary NTFS or exFAT file system, and any damage in it is repaired on the image and the files recovered. What was recovered is listed for you first, and only then does a bill exist. The files go home on fresh media. The original drive is returned, or securely destroyed at your request; we never send the key and the data by the same route.

Files listed before any invoiceFresh media, supplied with the job3–7 days at the bench

From the bench

  • Find the key before you clear a TPM, not after. A clear is irreversible for the chip's key copy, and a TPM-only drive has nothing else short of the recovery key.
  • The eight characters on the recovery screen are a key ID, not the key. Send them to us and we can tell you which stored key matches.
  • If the machine is still running and unlocked, do not shut it down until you have read the lost-key pages; the key may be liftable from memory while it runs.

Most TPM-only lockouts we see are solved by finding the key in the owner's Microsoft account, not by recovery work.

One job, followed all the way through.

UK · BLK-2026-0701JOB LOGGED ✓

A Dell OptiPlex that went to the BitLocker recovery screen after a scheduled firmware update, TPM-only, with a sole trader's accounts on it and no key to hand

The drive was healthy; only the key was needed. The owner had set the machine up with a personal Microsoft account and did not realise Device Encryption had escrowed the key there. We confirmed ownership, guided them to account.microsoft.com/devices/recoverykey where the 48-digit key sat against the device, and the machine started on the first try. No recovery work was needed and no fee was charged beyond the free look.

100% intact; key found, not brokenSame day once the account was checked
Illustrative example — replace with a genuine case

What helps, and what harms.

Do this much first

  • Find the 48-digit recovery key before anything else
  • Check the Microsoft account you signed in with
  • Send us the key ID from the recovery screen if you are stuck
  • Send proof the drive is yours if it needs lab work

What sets us back

  • Reinstalling Windows, which overwrites the data
  • Clearing the TPM again to try to fix it
  • Reformatting the drive at the recovery screen
  • Shutting down a still-running machine before reading the lost-key pages
We recover BitLocker drives for the people who own them. Before any work begins we ask for proof that the drive is yours or that you are authorised to have it recovered: a purchase receipt, the device serial, a letter on company letterhead for a work machine, or written authorisation from the owner, together with photo ID and a signed authorisation. It is a condition of the work, not a formality, and it is what keeps the service on the right side of the Computer Misuse Act. A drive with no proof of ownership is returned unread.

Questions answered before you commit.

Why did my computer suddenly ask for a BitLocker key after an update?

The update changed what the TPM measures at boot, so the chip would not release its key, and BitLocker fell back to the recovery key. Nothing is wrong with your data; enter the 48-digit recovery key and it starts. The finder page lists where that key is.

I cleared my TPM and now I am locked out. Can you get in?

Only with the recovery key. Clearing the TPM destroyed the chip's copy of the key, and a TPM-only drive has no PIN or password to fall back on. If the recovery key is in your Microsoft account, Entra ID or Active Directory, you are fine; if it is nowhere, honestly the data cannot be recovered.

My motherboard died. Is the data on the encrypted drive gone?

No. The data is intact on the drive; a new board has a different TPM, so the drive will ask for the recovery key. Enter it, or send us the drive with the key and proof of ownership and we will recover it. The board failing does not touch the encrypted data.

Can you recover a TPM-only drive if I have lost the key?

Only if the machine is still running and the key can be lifted from memory, or a hibernation file survives. A powered-off TPM-only drive with a lost key and no escrow copy, on a modern AES-256 system, cannot be opened by anyone, and we will tell you that at the free look.

What does it cost?

Single-disk BitLocker decryption is £800 + VAT, with 50% taken on acceptance and not refunded and 50% on a no-fix-no-fee basis. If finding the key in your account solves it, as it often does for a healthy TPM-only drive, there is nothing to pay beyond the free look.

The data is behind the key, not gone.

Looking at it is free, and it begins with the one question that decides everything: do you have the recovery key or password, or can you retrieve it. Tell us what the recovery screen says and what the drive has done, send the proof that it is yours, and back comes a straight account of what is possible and the one price to do it. Until then, reinstall nothing and reformat nothing.

0800 6890668