After an update · after firmware · after a board change · key not accepted · CrowdStrike · lost key · failed drive
Why you are seeing the recovery screen. It looks like the end of your data. It almost never is.
A BitLocker recovery screen is frightening because it looks like the end of your data, and it almost never is. In the great majority of cases the drive is perfectly intact and simply will not release its key, because something changed that BitLocker is built to be suspicious of: a Windows update, a firmware update, a hardware change, a cleared TPM. The fix is to enter the 48-digit recovery key, and the whole job is finding it. A smaller set of cases is genuinely harder: a key that cannot be found at all, a forgotten password on a drive with no escrow copy, or a drive that has physically failed while encrypted. The pages below take each situation in turn, tell you honestly whether it is the easy kind or the hard kind, and say what can and cannot be done. Start with the one that matches what you saw, and in every case the honest answer comes before any price.
Rather talk it through? An engineer answers the bench line
0800 6890668
The easy kind and the hard kind, told apart.
Start from what you saw.
Find your recovery key → →At the recovery screen
Asking for the recovery key after a Windows updateA feature update changed the boot state and the TPM would not release the key. The data is intact; enter the 48-digit key. Usually the easy kind→Recovery key after a BIOS or UEFI updateA firmware update changed what the TPM measures. Nothing is wrong with the drive; the recovery key opens it, and you can stop it recurring→Recovery screen after a motherboard, CPU or TPM changeA new board means a different TPM; an AMD CPU change can reset the firmware TPM. The data is intact behind the recovery key→The recovery key is not acceptedAlmost always the wrong key for this drive, or a key ID mismatch. The right 48 digits do work; here is how to find which key the drive wants→The CrowdStrike recovery loopThe July 2024 outage sent millions of machines to the recovery screen. The data was never at risk; the key is what each machine needed. What happened and what to do→Lost key, or a failed drive
Forgot the BitLocker passwordThe recovery key opens the drive without the password. If that is lost too, a weak password may be recoverable and a strong one not. The honest position→Lost the recovery key, no copy anywhereThe hardest case, told straight: when a weak password or a memory capture can still save it, and when a modern drive with no key genuinely cannot be opened→The drive failed or corrupted while BitLocker was onA hardware failure, not an encryption problem. With your key we image the failed drive and decrypt the image. The best outcome of the hard cases→The drive shows RAW, or BitLocker finds no valid metadataThe volume header is damaged. With the key, repair-bde rebuilds it at the block level onto a clone. Often recoverable→Stuck or interrupted part way through encryptingEncryption or decryption stopped half done, leaving a partly-encrypted drive. A delicate case; with the key, often still recoverable→The one thing to do before anything else.
Whatever sent your machine to the recovery screen, the first move is the same: find your 48-digit recovery key, because it opens the drive in almost every case and makes even a failed drive recoverable. The finder page lists every place it could be, a Microsoft account, a work or school account, Active Directory, Intune, a saved or printed copy. Do that before you consider reinstalling Windows, reformatting, clearing the TPM again, or sending anything anywhere.
Reinstalling or reformatting is the one genuinely destructive mistake available here. At the recovery screen your data is intact behind the key; a reinstall or reformat writes over it, turning a find-the-key problem into real data loss. If you cannot find the key and the data matters, that is the point to stop and talk to us, not to try to repair your way in.
If the drive has also failed, or the key is genuinely lost, send us what you have, the key ID from the recovery screen, an account of what happened, and proof the drive is yours, and the free look will tell you honestly which kind of case it is and what it would cost. We recover BitLocker drives only for their owners.
The questions that come up first.
Is my data gone if I am at the BitLocker recovery screen?
Almost certainly not. In most cases the drive is intact and simply will not release its key after a change BitLocker did not trust, an update, new hardware, a cleared TPM. Enter the 48-digit recovery key and it opens. Only a genuinely lost key, or a physically failed drive, is a hard case.
What is the single most important thing to do?
Find your recovery key before anything else, and do not reinstall or reformat. The key opens almost any lockout, and reinstalling over an intact encrypted volume is the one mistake that turns a solvable problem into real data loss.
When do I actually need a recovery lab?
When the key is genuinely lost and the data matters, when the drive has physically failed, or when a business needs the recovery done under proof of authority with a clean chain of custody. Most update-triggered lockouts are solved by finding the key and never need us.
Will you tell me honestly if it cannot be recovered?
Yes, at the free look, before you spend anything. A modern AES-256 drive with a lost key and no openable protector cannot be recovered by anyone, and we say so rather than take the work. We would rather lose the job than mislead you.
Find the key first; talk to us if it is lost or the drive has failed.
The finder page lists everywhere the key could be. If it is nowhere, or the drive has failed, tell us what happened and send proof it is yours, and the first look will tell you honestly what can be done.