Windows asks for a BitLocker recovery key — do not clear the TPM or reset the PC

First note the first eight characters of the recovery key ID shown on screen. On another device, open aka.ms/myrecoverykey, sign in with the Microsoft account used to set up the PC, and select only the matching 48-digit key. Do not share the key, clear the TPM, change BIOS settings at random, or reset Windows before checking every possible key location.

A laptop showing an abstract recovery screen with a phone beside it for finding the recovery key

Safe order of action

  1. Photograph only the recovery key ID or write down its first eight characters. Do not post or send the actual 48-digit key to an unknown person.
  2. Check whether the Windows 11 recovery screen shows a hint for the Microsoft account that stored the key. On another phone or PC, open aka.ms/myrecoverykey and sign in with that account.
  3. If the account lists several keys, match the key ID on the recovery screen to the ID in the list. Enter only the corresponding 48 digits.
  4. If the device has ever been used for work or school, check the work or school account device list or contact the organisation's IT support. The organisation may hold the key.
  5. Also check a printout, USB drive, and any other location selected when BitLocker was enabled. Consider whether somebody else originally set up the device with their account.
  6. After Windows opens, back up important data before further firmware or BIOS changes. If the prompt returns, investigate boot order, a dock or USB device, firmware updates, Secure Boot, and TPM state before changing anything.

Why is the key requested?

BitLocker protects an encrypted drive. It asks for recovery when the TPM cannot release the key automatically or the early boot environment appears to have changed. Triggers can include a BIOS or UEFI update, a Secure Boot or TPM change, altered boot order, a dock, bootable USB media, or a hardware change. The prompt alone does not prove that files are lost or that the PC was compromised.

What not to do

  • Do not clear or disable the TPM as an experiment. This can remove an available automatic unlock path and make recovery harder.
  • Do not toggle Secure Boot, boot mode, or drive order at random. If you know exactly which setting just changed, reverse only that change; otherwise stop.
  • Do not pay somebody to “crack” the key and do not share it in a support call, message, or photo. The correct 48-digit key cannot be derived from the key ID.
  • Do not choose Reset this PC or reinstall Windows simply to leave the screen. It can erase data on the encrypted drive and does not recreate a missing key.

When to stop

Stop before making BIOS, TPM, or Windows recovery changes if the key is missing. Microsoft cannot retrieve or recreate a lost recovery key. If no copy exists and the boot change cannot be safely reversed, the encrypted drive cannot be unlocked; resetting the device is a last resort only after accepting data loss.

Which description fits best?

Your answer is neither sent nor stored.

When is help worthwhile?

JVS Tuki can help identify the correct account and key, document boot-environment changes, and protect data before safe next steps. We cannot bypass or recreate a missing BitLocker key.

Ask about a BitLocker check

Verification sources

Back to guides