How to Find Your BitLocker Recovery Key in Windows 11

To get past the BitLocker recovery screen in Windows 11, note the recovery key ID shown on the screen, open https://aka.ms/myrecoverykey on a phone or another computer, sign in with the Microsoft account used on the locked PC, and type the matching 48-digit recovery key. If the PC belongs to a workplace or school, the key is usually held by that organization instead. There is no supported way around the screen without the key.

Applies to: Windows 11 (the same recovery screen appears in Windows 10). Checked against Microsoft Learn documentation on October 7, 2026.

What the BitLocker recovery screen is asking for

BitLocker is the Windows feature that encrypts a whole drive so nobody can read it by removing the drive or starting the PC from other media. Normally the PC unlocks the drive by itself at startup using its TPM, a security chip on the motherboard. When the TPM cannot confirm that the startup environment is unchanged, Windows stops and asks for recovery information instead.

Microsoft describes two forms of recovery information:

  • Recovery password: a 48-digit number divided into eight groups. This is what most people mean by “the BitLocker recovery key”, and it is what you type on the recovery screen.
  • Recovery key file: a key file saved on a USB flash drive, which the recovery screen reads directly when the drive is plugged in.

The screen also shows a recovery key ID. The ID is not the key. It is a label that tells you, or your help desk, which saved key belongs to this drive, which matters when an account holds keys for several PCs or drives.

Before you start

  • A second device with internet access (a phone is fine), because the locked PC cannot browse the web.
  • The email address and password of the Microsoft account that was used to sign in to the locked PC. If more than one person in the household has signed in as an administrator, the key may be in their account.
  • A photo or written note of the recovery key ID from the screen.

Find the key in your Microsoft account and unlock the PC

This is the route for a personally owned PC. On PCs that use device encryption, Windows uploads the recovery key to the online Microsoft account when an administrator signs in with that account, so many people have a saved key without remembering that they made one.

  1. On the locked PC, read the recovery screen. Write down the recovery key ID and any hint underneath it. For a key saved to a Microsoft account, the hint is the address https://aka.ms/myrecoverykey. Starting in Windows 11 version 24H2, the hint also shows which Microsoft account was used to store the key.
  2. On your phone or another computer, open a browser and go to https://aka.ms/myrecoverykey. Microsoft’s documentation also gives the direct address account.microsoft.com/devices/recoverykey.
  3. Sign in with the Microsoft account used on the locked PC. The page shows the recovery keys saved to that account.
  4. Find the entry whose key ID matches the ID on the locked PC. If nothing matches, sign out and try any other Microsoft account that has been used on the PC.
  5. Back on the locked PC, type the 48-digit recovery password. Microsoft notes that the recovery screen checks each 6-digit block as you type it and lets you correct a mistyped block, so a typing slip will not lock you out.
  6. Confirm the entry. Windows unlocks the drive and continues to the normal sign-in screen.
Illustration of the path to find a BitLocker recovery key: note the recovery key ID, open aka.ms/myrecoverykey, sign in, match the key ID, enter the 48-digit key
Illustration: the route from the BitLocker recovery screen to the saved key in a Microsoft account.

Other places your recovery key can be

Microsoft lists a small number of places a recovery key can be saved. Work through the ones that apply to you; the hint on the recovery screen tells you which was used most recently.

A work or school account

If the PC was signed in to a work or school account, the key is typically stored in Microsoft Entra ID, the organization’s directory, and the recovery screen hint is https://aka.ms/aadrecoverykey. Microsoft’s self-recovery route is:

  1. On another device, go to https://myaccount.microsoft.com and sign in with the work or school account.
  2. Open the Devices tab.
  3. Select the Windows device you own, then select View BitLocker Keys.

Organizations can switch this self-service option off. If you see no keys, go to your administrator, as described below.

A printout or a saved text file

When the hint reads Look for a printout or a text file with the key, the key was printed or saved to a file when BitLocker was turned on. Check the folder where you keep computer paperwork, and check USB drives and other computers for a saved text file. A key cannot be saved on the encrypted drive itself, so it will not be on the locked PC.

A USB flash drive

If the recovery key was saved to a USB drive as a key file, plug the drive into the locked PC and follow the instructions on screen. If the USB drive holds the key as a text file instead, the locked PC cannot read it: open the file on a different device and type the 48 digits by hand.

Your organization’s administrator or help desk

On a managed PC, recovery keys are normally backed up to Microsoft Entra ID or to Active Directory, and the screen may simply say Contact your organization’s help desk. Have these ready when you call:

  • The device name, if you know it.
  • The recovery key ID from the screen. Administrators can search by the first eight characters of it.
  • Proof that you are the authorized user. Microsoft’s guidance tells help desks to verify identity before reading out a key, so expect questions.

How to confirm it worked and stop the screen coming back

A single recovery prompt is usually a one-off. According to Microsoft, when a drive is unlocked with the recovery password, the TPM’s measurements are reset to match the PC’s current configuration, so the next restart should be normal. Restart once to check.

If the PC asks for the key at every startup, Microsoft’s documented fix is to suspend BitLocker and resume it, which makes BitLocker record the current startup configuration again. Suspending does not decrypt anything; the data stays encrypted and only the automatic protection is paused.

  1. Unlock the PC with the recovery key and sign in with an administrator account.
  2. Open Windows PowerShell as an administrator.
  3. Type Suspend-BitLocker -MountPoint “C:” -RebootCount 0 and press Enter. A reboot count of 0 keeps protection suspended until you resume it.
  4. Restart the PC. It should start without the recovery screen.
  5. Open PowerShell as an administrator again, type Resume-BitLocker -MountPoint “C:” and press Enter to turn protection back on.

Do not skip the last step. While BitLocker is suspended, the drive is not protected if the PC is lost or stolen.

Back up the key before you need it again

Once you are signed in, make sure you have at least two copies of the key. Microsoft says a recovery key can be saved to a Microsoft account, saved to a folder, saved to one or more USB drives, or printed.

  1. Select Start, type BitLocker, and select Manage BitLocker to open the BitLocker Drive Encryption page in Control Panel, where each encrypted drive is managed. PCs that only have device encryption may not show this page; their key is stored in the Microsoft account automatically.
  2. To see the current key and its ID yourself, open PowerShell as an administrator and run (Get-BitLockerVolume -MountPoint C).KeyProtector. The entry with the type RecoveryPassword lists the ID and the 48-digit number.
  3. Store the copies away from the PC. Microsoft specifically warns against keeping a recovery USB drive in the same bag as the laptop.

Why Windows 11 asks for the recovery key

The prompt does not mean the drive is damaged or that someone attacked the PC. Microsoft’s list of triggers includes:

  • A BIOS or UEFI firmware update, or a TPM firmware update, installed without suspending BitLocker first.
  • Turning off, disabling or clearing the TPM, or turning off Secure Boot.
  • Changing the boot order so another drive starts before the internal one, or starting with bootable media inserted.
  • Adding or removing hardware, replacing the motherboard, or moving the drive to a different computer.
  • Docking or undocking a laptop on some configurations.
  • Entering the wrong BitLocker PIN, or the wrong sign-in details, too many times.

Ordinary Windows updates are not on the list. Microsoft states that no action is needed for BitLocker when installing quality and feature updates from Microsoft. It is firmware updates from outside Windows Update, and manual changes in the firmware settings, that call for suspending BitLocker first using the two commands above.

In Windows 11 version 24H2 and later you can press the Alt key on the recovery screen to open Additional recovery information, which shows an error category and an error code. A code that mentions Secure Boot being disabled, for example, is resolved by turning Secure Boot back on in the firmware settings and restarting.

Troubleshooting

The key is rejected

Compare the recovery key ID on the screen with the ID next to the key you are typing. A different ID means the key belongs to another drive or another PC, and it will never work on this one. Look for more entries in the same account, then try other accounts.

The recovery screen returns in a loop even after the right key

Microsoft documents this workaround, which still requires your own recovery key:

  1. On the BitLocker recovery screen, select Skip this drive.
  2. Select Troubleshoot > Advanced Options > Command Prompt.
  3. Type manage-bde.exe -unlock C: -rp followed by a space and your 48-digit recovery password, including the dashes, then press Enter.
  4. Type manage-bde.exe -protectors -disable C: and press Enter. This suspends protection so the PC can start.
  5. Close Command Prompt, shut the PC down, and start it again. After you sign in, resume protection as described above.

No key appears in any Microsoft account

Check whether the PC was ever signed in with a work or school account, even briefly, and look there. Then go back to printouts, text files and USB drives. A PC that has only ever used local accounts has no automatic online backup.

It is a work or school PC

Do not change firmware settings or clear the TPM to get in. The organization holds the key and may also want to know what triggered recovery before the PC goes back into use.

You cannot find the key anywhere

Microsoft’s wording is direct: BitLocker is designed to make the encrypted drive unrecoverable without the required authentication. Software or services that claim to bypass or calculate a BitLocker key cannot deliver that, and clearing the TPM does not help because the TPM is not part of recovery at all. The only way to use the PC again is to erase the drive and do a clean install of Windows 11, which permanently removes the files on that drive. Restore your files from a backup afterward.

Frequently asked questions

Is the recovery key ID the same as the recovery key?

No. The ID only identifies which key you need. The key itself is the 48-digit number stored in your account, on paper, in a file or with your administrator.

Can Microsoft or the PC maker bypass BitLocker for me?

No supported bypass exists. Recovery always needs the 48-digit recovery password or the key file on a USB drive.

I never turned on BitLocker. Why is my drive encrypted?

Device encryption turns BitLocker on automatically on qualifying PCs, in every edition of Windows, and backs the key up to the Microsoft account, work account or domain the PC is signed in to. Starting in Windows 11 version 24H2, Microsoft relaxed the hardware requirements, so more PCs qualify.

Will resetting the PC remove the recovery screen?

A reset is not a substitute for the key: your files stay encrypted until the drive is unlocked. If you have the key, unlock the PC normally and you will not need a reset. If you want one anyway, see how to reset Windows 11.

Can I read the drive by putting it in another computer?

Only with the same recovery key. A BitLocker drive moved to another PC stays locked until the recovery password or key file is supplied.

Does the key change after I use it?

On a personal PC it stays the same unless you create a new one. On work and school PCs, administrators can set the recovery password to rotate automatically after it has been used, so an old note of the key may stop working.

Microsoft’s own references for these steps are the BitLocker recovery process and BitLocker preboot recovery screen pages. Once you are back in, save a second copy of the key somewhere away from the PC today.

Get Our Free Newsletter

How-to guides and tech deals

You may opt out at any time.
Read our Privacy Policy