Taking work now — the first look is freeDrives posted in from anywhere in the UK, or handed in at ten drop-off pointsQuicker still, give us a ring:0800 6890668
BLKBitLocker Data Recovery 0800 6890668 Price my job
BLK / Why you are seeing the recovery screen / Recovery screen after a motherboard, CPU or TPM change

New motherboard · CPU change · cleared TPM · AMD fTPM reset · recovery key

BitLocker recovery after a motherboard, CPU or TPM change. You changed the hardware the key was tied to, and the drive noticed.

BitLocker on a TPM machine ties its key to that specific TPM and the boot state around it, so changing the hardware the key was bound to sends the drive to the recovery screen, by design. Replace the motherboard and you have a different TPM entirely, which knows nothing of the old key. Clear or reset the TPM and you destroy its stored key copy. Change the CPU on an AMD system and the firmware TPM can reinitialise itself, so the machine will not boot afterwards without the recovery key. In every one of these the data on the drive is completely intact; the drive is simply bound to hardware that is no longer there, and it falls back to the 48-digit recovery key, which does not depend on the TPM at all. The fix is to find and enter the key. The one thing to get right in advance, if a hardware change is planned, is to have the recovery key in hand first, because a TPM-only drive has nothing else to fall back on. We are for when the key is lost, or the drive has also failed.

Owner-only, proof requiredFree first look£800 + VAT, one diskThe honest answer either way

Rather talk it through? An engineer answers the bench line
0800 6890668

Have the recovery key before you change hardware, not after. A TPM-only drive bound to a replaced board or a cleared TPM has nothing but the recovery key to fall back on. Do not clear the TPM again, reinstall Windows, or reformat; the data is intact behind the key. Find the 48-digit key first.

Why hardware changes send the drive to recovery, every time.

A TPM is a specific chip, and BitLocker seals its key to that chip and to the boot state it measures. Replace the motherboard and the new board's TPM is a different chip that never held the key; the drive cannot get its key from it and asks for the recovery key. Clear or reset the TPM, in the BIOS or through Windows, and you deliberately wipe the chip's stored key copy, with the same result. These are not faults; they are BitLocker behaving exactly as intended when the hardware it trusts changes.

Changing the CPU on an AMD system has a particular twist: the firmware TPM is provided by the processor, and a CPU change, or sometimes a BIOS update, can cause the firmware TPM to reinitialise. Once it does, a machine with BitLocker enabled will not boot without the recovery key, because the reinitialised TPM no longer holds the old key. Intel's firmware TPM behaves comparably when the platform it is tied to changes.

In all of these the fix is the recovery key, which is a protector that does not depend on any TPM, so it opens the drive regardless of what happened to the hardware. Enter it and the machine starts. The practical lesson is the one every technician learns once: retrieve and keep the recovery key before any planned hardware change or TPM clear, because a TPM-only drive has no other way back in once the change is made.

What you see, and what it means.

Describe yours to us →
What you see The usual reason Where that leaves you
Recovery screen after fitting a new motherboardA different TPM that never held the keyEnter the recovery key; or refit the old board
Will not boot after an AMD CPU changeThe firmware TPM reinitialised itselfThe recovery key; the data is intact
Locked out after clearing the TPMThe chip's key copy was destroyedOnly the recovery key opens it now
Planned a board swap, no key savedA TPM-only drive with nothing to fall back onRetrieve the key first, if you still can
Drive also failed during the hardware workA coincident hardware faultImaged, then decrypted with the key

From the drive arriving to your files going back.

Work we have closed →
01

Logged the day it lands, and the first look costs nothing Free

A number goes on the parcel and the drive the day it is opened, matched to your enquiry by the booking sheet inside. Before anything is read we check the proof of ownership you sent. The drive is then connected through a write blocker, read-only, and examined: whether it is a healthy drive behind a lost key, or a failing drive behind a known key, is settled here, and so is whether what you want is possible. That first look is free, and you may stop at it owing nothing.

Nothing to pay for lookingProof of ownership checked firstRead-only, nothing written to the drive
02

Imaged at the sector level, before anything else

A drive that answers at all is imaged in full on a hardware imager, behind a write blocker, weak areas last, with a map kept of what could not be read. The image is a copy of the encrypted sectors, so it is useless to anyone without your key, which is a privacy gain in itself. Every later step is done on the image. The original drive is never decrypted, never written to, and never worked on directly.

Sector by sector, behind a write blockerNothing written to the original
03

The physical fault repaired on the clone, when there is one

A drive that has failed, that reads slowly or that drops out is stabilised and imaged in passes; a mechanically failed disk is repaired and read on the bench, a dead SSD controller read at the chip level, before any decryption is attempted. The aim at this stage is one clean image of the encrypted volume to decrypt from. Where the drive is healthy and the problem is only the key, this stage is skipped.

Mechanical and chip-level work where neededOne clean encrypted image to work from
04

The image decrypted with your key or password

With your recovery key, recovery password or the drive's password, the image is unlocked: the protector releases the Volume Master Key, the VMK releases the Full Volume Encryption Key, and the volume is decrypted from the clone. Where the metadata or header is damaged, repair-bde and the key package rebuild it at the block level onto a separate target. Where the key is lost but a memory image or hibernation file is available, the Volume Master Key is extracted from it with Passware. Without a key, a password to attack, or a memory capture, the volume cannot be opened, and you are told so at the free look.

Protector → VMK → FVEK → volumeDecrypted from the clone, never the original
05

The file system rebuilt, and the list before the bill

Once the volume is open it is an ordinary NTFS or exFAT file system, and any damage in it is repaired on the image and the files recovered. What was recovered is listed for you first, and only then does a bill exist. The files go home on fresh media. The original drive is returned, or securely destroyed at your request; we never send the key and the data by the same route.

Files listed before any invoiceFresh media, supplied with the job3–7 days at the bench

From the bench

  • Retrieve the recovery key before any hardware change or TPM clear. A TPM-only drive has no other way in once the hardware it trusts is gone.
  • Refitting the original motherboard can restore access where a board swap caused it and the old board still works, because the original TPM still holds the key.
  • The data is intact; this is a find-the-key job, not a reinstall. Clearing the TPM again only removes another route in.

An AMD CPU change can reinitialise the firmware TPM on its own, and a BitLocker machine then will not boot without the recovery key.

One job, followed all the way through.

UK · BLK-2026-0709JOB LOGGED ✓

A desktop whose motherboard was replaced under warranty, TPM-only, whose owner had no idea BitLocker was on until the rebuilt machine demanded a key, with a photographer's edited catalogue on it

The new board meant a new TPM, so the drive asked for a recovery key the owner did not know existed. The drive was healthy. With ownership confirmed, we found that Device Encryption had escrowed the key to the owner's Microsoft account when the machine was first set up; the 48-digit key was there, and the drive opened. Had they cleared the old TPM or reinstalled Windows first, the catalogue would have been at risk; instead it was a find-the-key job with nothing to pay beyond the free look.

100% intact; key found in the accountSame day once the account was checked
Illustrative example — replace with a genuine case

What helps, and what harms.

Do this much first

  • Retrieve the recovery key before any hardware change
  • Enter the 48-digit key to get back in
  • Refit the original board if a swap caused it and it still works
  • Send proof the drive is yours if it needs lab work

What sets us back

  • Clearing the TPM again to try to fix it
  • Reinstalling Windows over intact data
  • Changing hardware on a TPM-only machine without the key in hand
  • Assuming a new board wiped your data; it did not
We recover BitLocker drives for the people who own them. Before any work begins we ask for proof that the drive is yours or that you are authorised to have it recovered: a purchase receipt, the device serial, a letter on company letterhead for a work machine, or written authorisation from the owner, together with photo ID and a signed authorisation. It is a condition of the work, not a formality, and it is what keeps the service on the right side of the Computer Misuse Act. A drive with no proof of ownership is returned unread.

Questions answered before you commit.

I replaced my motherboard and now it wants a BitLocker key. Why?

The new board has a different TPM, which never held your key, so the drive falls back to the 48-digit recovery key. Your data is intact; enter the key and it starts. If the old board still works, refitting it can also restore access, because the original TPM still has the key.

My AMD PC will not boot after a CPU or BIOS change and asks for a key. Is it broken?

No. On AMD systems the firmware TPM can reinitialise after a CPU change or a BIOS update, and a BitLocker machine then needs the recovery key to boot. The data is untouched; enter the 48-digit key. This is expected behaviour, not a fault.

I cleared my TPM and now I am locked out. What now?

Clearing the TPM destroyed its copy of the key, so only the 48-digit recovery key opens the drive now. If it is escrowed in your Microsoft account or your organisation's directory, you are fine; if it is genuinely nowhere, a modern TPM-only drive may not be recoverable, and we tell you honestly at the free look.

How should I handle a planned hardware upgrade with BitLocker on?

Retrieve and keep the recovery key first, and ideally suspend BitLocker before the change and resume it after. That way the drive has the key to fall back on and the TPM re-seals cleanly. The mistake to avoid is changing the hardware or clearing the TPM with no copy of the key.

What does it cost?

If the key is in your account and the drive is healthy, finding it costs nothing from us. A failed drive falls under single-disk recovery at £800 + VAT, 50% non-refundable on acceptance and 50% no fix, no fee.

The data is behind the key, not gone.

Looking at it is free. Tell us what the recovery screen says, what happened just before it, and whether you can find your recovery key, and send proof the drive is yours. Back comes an honest account of what can be done and the one price to do it. Until then, reinstall nothing, reformat nothing, and clear no TPM.

0800 6890668