Key not accepted · wrong key · key ID mismatch · MBAM single-use · typos
The BitLocker recovery key is not accepted. You have a 48-digit key, you are sure it is right, and the screen keeps refusing it.
A recovery key that is refused is maddening, and the cause is almost always one of a few ordinary things rather than a broken drive. Overwhelmingly, it is the wrong key: you have more than one encrypted device, and the key you are entering belongs to a different one. BitLocker guards against exactly this with a key ID, the first eight characters shown on the recovery screen, which identifies the specific key that drive wants; if the ID beside your key does not match the ID on the screen, the key will never work, however carefully you type it. The other causes are a single-use MBAM key that has already been used, a typo or a look-alike character, or, rarely, damage to the volume's metadata so that no key is accepted because the drive cannot read its own key store. This page sorts out which is which. The data is intact in all but the metadata-damage case, and even that is usually recoverable with the key and repair-bde. We are for when none of your keys fits and the data matters, or when the metadata is damaged.
Rather talk it through? An engineer answers the bench line
0800 6890668
Why a key is refused, in order of likelihood.
It is the wrong key. This is the cause in most cases. People with several encrypted machines, or several keys in a Microsoft account, enter a key that belongs to a different drive. The recovery screen shows a key ID, the first eight characters of the identifier for the key this drive wants. Find the stored key whose ID matches those eight characters, and use that one. A key whose ID does not match will be refused no matter what, so checking the ID is the first thing to do, not the last.
It is a used-up MBAM key. On corporate machines managed with MBAM, recovery keys are single-use: once a key has unlocked the drive, it expires, and a fresh one is issued. A previously working key being refused is the signature of this, and the fix is for the administrator to retrieve the current key.
It is a typo or a look-alike. Forty-eight digits are easy to mis-enter: a miscounted group, a transcription slip, or confusing characters when reading a key off a screen or a photo. Re-enter carefully, group by group. BitLocker recovery keys are purely numeric, so any letter you think you see is a misread.
The metadata is damaged. Rarely, no key is accepted because the volume's metadata, where the key store lives, is corrupt, so the drive cannot match any key against it. This is the one case where the drive genuinely needs work rather than the right key: with the key, repair-bde can rebuild the metadata at the block level onto a clone and recover the data. The free look tells a wrong-key case apart from a damaged-metadata case.
What you see, and what it means.
Describe yours to us →| What you see | The usual reason | Where that leaves you |
|---|---|---|
| A valid-looking key is refused | It belongs to a different device | Match the key ID on the screen to the right key |
| A key that worked before is now refused | An MBAM single-use key, already used | The administrator retrieves the current key |
| Every key you have is refused | Wrong keys, or damaged metadata | Check the key ID; if all match and fail, metadata work |
| The key is refused and has letters in it | A misread; recovery keys are numeric | Re-read carefully; letters are look-alike digits |
| No key fits and the drive reads oddly | Damaged volume metadata | With the key, repair-bde rebuilds it onto a clone |
From the drive arriving to your files going back.
Work we have closed →Logged the day it lands, and the first look costs nothing Free
A number goes on the parcel and the drive the day it is opened, matched to your enquiry by the booking sheet inside. Before anything is read we check the proof of ownership you sent. The drive is then connected through a write blocker, read-only, and examined: whether it is a healthy drive behind a lost key, or a failing drive behind a known key, is settled here, and so is whether what you want is possible. That first look is free, and you may stop at it owing nothing.
Imaged at the sector level, before anything else
A drive that answers at all is imaged in full on a hardware imager, behind a write blocker, weak areas last, with a map kept of what could not be read. The image is a copy of the encrypted sectors, so it is useless to anyone without your key, which is a privacy gain in itself. Every later step is done on the image. The original drive is never decrypted, never written to, and never worked on directly.
The physical fault repaired on the clone, when there is one
A drive that has failed, that reads slowly or that drops out is stabilised and imaged in passes; a mechanically failed disk is repaired and read on the bench, a dead SSD controller read at the chip level, before any decryption is attempted. The aim at this stage is one clean image of the encrypted volume to decrypt from. Where the drive is healthy and the problem is only the key, this stage is skipped.
The image decrypted with your key or password
With your recovery key, recovery password or the drive's password, the image is unlocked: the protector releases the Volume Master Key, the VMK releases the Full Volume Encryption Key, and the volume is decrypted from the clone. Where the metadata or header is damaged, repair-bde and the key package rebuild it at the block level onto a separate target. Where the key is lost but a memory image or hibernation file is available, the Volume Master Key is extracted from it with Passware. Without a key, a password to attack, or a memory capture, the volume cannot be opened, and you are told so at the free look.
The file system rebuilt, and the list before the bill
Once the volume is open it is an ordinary NTFS or exFAT file system, and any damage in it is repaired on the image and the files recovered. What was recovered is listed for you first, and only then does a bill exist. The files go home on fresh media. The original drive is returned, or securely destroyed at your request; we never send the key and the data by the same route.
From the bench
- Check the key ID before anything else. The eight characters on the screen must match the ID beside your key, or the key is for a different drive and cannot work.
- A key that worked before and now fails is the MBAM single-use signature. The administrator retrieves the current key.
- BitLocker recovery keys are all digits. Any letter you think you see is a misread of a look-alike character.
The key ID on the recovery screen is the fix for most refused keys: match its eight characters to the right stored key.
What helps, and what harms.
Do this much first
- Match the key ID on the screen to the right stored key
- Re-enter the key carefully, group by group
- Ask IT for the current key if it is an MBAM machine
- Send us the key ID if none of your keys matches
What sets us back
- Assuming a refused key means a dead drive; it rarely does
- Reformatting or reinstalling to clear the error
- Reusing an MBAM key that has already been used once
- Entering keys from other devices over and over
Questions answered before you commit.
Why is my BitLocker recovery key not working?
Almost always because it is the wrong key, for a different device. The recovery screen shows a key ID, the first eight characters of the key it wants; match that to the ID beside your stored key and use the one that matches. A key whose ID does not match the screen will always be refused.
I have several keys and none works. What do I do?
Check each key's ID against the eight characters on the recovery screen; only the matching one can work. If one matches but is still refused, and you use MBAM, it may be a single-use key already used, so ask your administrator for the current one. If a matching key genuinely fails, the metadata may be damaged, which we can assess.
My key worked last time and is refused now. Why?
That is the signature of an MBAM single-use key: once used, it expires and a new one is issued. Your administrator retrieves the current key. Outside MBAM, double-check you are using the key whose ID matches this drive, as it is easy to reach for the wrong one.
Could the drive itself be the problem?
Rarely. In a small number of cases no key is accepted because the volume's metadata is corrupt and the drive cannot match any key. That is the one case needing real work: with your key, repair-bde rebuilds the metadata onto a clone and recovers the data. The free look tells this apart from simply using the wrong key.
What does it cost?
If matching the key ID solves it, there is nothing to pay from us. Damaged-metadata recovery, or a failed drive, falls under single-disk recovery at £800 + VAT, 50% non-refundable on acceptance and 50% no fix, no fee.
The data is behind the key, not gone.
Looking at it is free. Tell us what the recovery screen says, what happened just before it, and whether you can find your recovery key, and send proof the drive is yours. Back comes an honest account of what can be done and the one price to do it. Until then, reinstall nothing, reformat nothing, and clear no TPM.