Open, and work is coming in · weekdays, 9am–5:30pm Faster by phone: 0800 6890668
PDR Plymouth Data Recovery 0800 6890668 Get a price
PDR / Common faults / BitLocker wants the key

The fault · BitLocker and TPM lockouts

BitLocker recovery for Plymouth. The disk is sound; the key is what has gone.

A computer sitting at the 48-digit prompt is rarely a computer with anything wrong with it. At encryption time the TPM recorded what the machine and its boot path looked like; one of those things is now different — new firmware, a Secure Boot setting, a board swap — and the chip will not release the key until those digits go in. The disk underneath is usually fine. Most arrive as managed work laptops, a Plymouth practice at Sutton Harbour or a supplier's office out at Derriford, encrypted by policy, so the work begins with sign-ins rather than screwdrivers.

Nothing readable? Most jobs carry no bill Free diagnosis, then one written price Boxes come to the lab from Truro, Newquay and Tavistock

You will be talking to an engineer
0800 6890668

BitLocker: what each symptom points to.

Yours not here? Start at the triage →
What happensWhat that points toWhat to do
A blue recovery screen where Windows should beThe TPM's measurements no longer agree, so the key stays sealedGo looking for the key. Never guess it.
The line about using the number keys or F1-F10That line only tells you how to enter digitsDigits alone. A Windows password will not help.
Recovery key ID (to identify your key):Eight characters naming the key this volume needsMatch that ID against each escrow
For more information go to: aka.ms/recoverykeyfaqMicrosoft's own explanation of itMost keys are sitting in an account
BitLocker waiting for activationSwitched on for the volume but never actually runNothing is encrypted at all. It reads openly.
A dying disk with a sealed partition on itHardware first, then the hunt for the keyImage it sealed, then open that copy
Getting it to us: wrap it so nothing can shift, cover it for what it is worth, and post it tracked to the intake lab in Bristol. We cover the postage back. If you want an engineer to check the packing before the box is taped, ring first. It is spelled out on the contact page.

The four places to look first.

The Microsoft accountSign in at aka.ms/myrecoverykey in any browser — a phone will do. Home PCs quietly file the key there during setup and never say so.
A work or study accountSign in at aka.ms/aadrecoverykey using the account issued by work or college. A laptop under management passes its key up to Entra ID on its own, unprompted.
Whoever handles ITCompany machines escrow to Intune or Active Directory. Give whoever picks up the Recovery Key ID and the match usually takes minutes.
A sheet, a text file, a stickA BitLockerRecoveryKey…TXT saved into some folder nobody looks in, or the page Windows nagged you to print as it encrypted. They turn up far more often than people expect.

What happens to a drive while it is here.

Cases in the log →
01

A number on arrival, then the free diagnosis Free

Whatever arrives is booked in under a case number on the day it reaches the bench. An engineer then works out the actual fault, and that part is free. You get a plain answer on what can come off the drive and what cannot, followed by one price in writing. Nothing further happens until you have read it and agreed.

Diagnosis at no chargeA single written figureYou owe nothing yet
02

Start by finding the key

Everything turns on the eight characters printed over the prompt: they identify the one key that will open this volume. What follows is a list to be worked through — whichever Microsoft account the computer was first signed into, a work or study log-in, anything the IT team holds in Entra ID or in Active Directory, and the page somebody printed on the day. Where no key survives, nobody is getting in, ourselves included.

Key ID identifiedEvery escrow searched
03

Image it still sealed

Where the disk is failing, the sector copy comes off with the encryption left exactly as it is, so a worn mechanism is spared a full decryption run altogether. All of the rest happens on the copy.

Imaged with the lock onNothing further asked of it
04

Open the copy, then mend it

As soon as a key appears, the image opens. Where BitLocker's own metadata has taken damage too, repair-bde — a Microsoft utility — rewrites the volume onto fresh media, and what is recovered goes back to you on new storage bought for the purpose.

repair-bde on the imageWritten to fresh media
05

You give the word, and it ships back

Thinking it over costs you nothing. Everything the drive gave up is listed for you before any invoice exists, and the bill only follows your go-ahead. Files travel back on media bought in for your job, with return carriage paid at this end, and the case stays on the bench until you confirm they open on your own computer.

You see the list and decideWritten to fresh mediaWe pay the postage home

The faults we see most

  • The ID and the key differ — those eight characters merely label the 48-digit string the volume is waiting for. Typed into the box by themselves, nothing happens. Pass them to whoever looks after your IT and the key can be looked up.
  • Think back to July 2024 — that month a Windows update dropped whole fleets at the recovery prompt, and the CrowdStrike failure a few weeks later hit 8.5 million computers, on Microsoft's figure. Plenty of firms discovered right then that no key had been escrowed by anyone.
  • Broken metadata can still be worked with — repair-bde rebuilds a damaged BitLocker volume onto other media. The one thing it will not do is conjure the key; that stays your side of the job.
  • Sealed and failing? Image it first — decrypting drags the heads across every sector without pause, and a worn drive is precisely what will not last that.

Plainly put: lose the 48 digits and the volume is shut permanently. Microsoft says as much, and so do we, since encryption that a workshop could get around would be of no value to anybody who bought it. That makes the opening move a hunt rather than a teardown: the home account, the company account, whatever sits in an IT escrow, a printed page folded into a file. Find it and the data very nearly always follows. Where nothing exists to find, no straight-dealing lab can open that disk, and you are told so during the free diagnosis instead of reading it on a bill.

A job out of the casebook.

PL · PLY-2026-0642LOGGED ✓

A Newquay practice, locked out of its workstation by an update that ran overnight

The key existed. Nobody at the practice knew that. An update had run in the night and shifted what the TPM measures, so the machine came up wanting a key nobody there had thought to record. Its Recovery Key ID matched an entry already held in the firm's Entra ID escrow, and that was the whole answer. repair-bde then put fresh BitLocker metadata on a new disk, and the project files opened as before.

100% read back3 days start to finish

Before you seal the box.

Get these done

  • Write down all eight characters of the Key ID
  • Try aka.ms/myrecoverykey, then aka.ms/aadrecoverykey
  • Ask IT — a managed machine escrows to Intune or to AD
  • Look for the saved .TXT file or the setup printout

What to avoid

  • Guessing at digits
  • Reinstalling Windows to clear the prompt — the files clear with it
  • Typing the eight-character ID into the key box
  • Formatting the drive because you assume it is gone

Questions that come up most weeks.

Where would the recovery key actually be?

Begin at the eight-character Recovery Key ID above the prompt — that label tells you which key the volume will take. Domestic machines nearly always parked it in whichever Microsoft account set Windows up; look at aka.ms/myrecoverykey. Company laptops go to aka.ms/aadrecoverykey, and failing that the person who administers Intune or AD. Then the paper copy in someone's drawer.

If no key exists anywhere, is that the end?

Yes. There is no back door at Microsoft and none in this lab either. A volume sealed with the key gone is encryption doing precisely the job it was sold to do. The ones that end well are those where a key had survived somewhere and the genuine fault turned out to be a tired disk or damaged metadata.

Why has it started demanding a key now?

The TPM measures the machine that is booting against what it recorded when the volume was first encrypted, and something no longer agrees. A firmware update alone will do it. So will a change to Secure Boot, a replacement motherboard, or the disk being lifted into another computer. In July 2024 a Windows update put entire fleets at the prompt.

It is sealed and the disk is dying. Which comes first?

Hardware. The sector image is made before anything is unlocked, and the key is put against that image, never against the original disk. A decryption run must read the surface end to end without stopping, and a mechanism this tired is unlikely to survive it.

A drive that stays switched off gets no worse.

The diagnosis is free, and it comes back as a list: which files read, which do not, and what getting them off would take. Until then, leave the drive unplugged.

0800 6890668