Taking in new cases now · 9am–5:30pm, weekdays In a rush? Ring 0800 6890668
BHDR Birmingham Data Recovery 0800 6890668 Get it seen
BHDR / Faults we see / Volumes sealed by BitLocker

Cause of loss · BitLocker & TPM lockouts

BitLocker recovery in Birmingham. Find the key and the engineering can wait.

When a PC stops at the 48-digit prompt, nothing has broken. The TPM took a measurement of the machine at setup, the machine no longer matches it — new firmware, a boot setting changed, a board replaced — and the chip holds onto the key until the recovery key goes in. The platters are usually fine. That is why the first hour of a case like this goes on accounts rather than tools.

Nothing recovered, nothing to pay Diagnosed free, then one fixed price From Walsall, Dudley or Coventry, it travels by post

Tell an engineer what it is doing
0800 6890668

Reading the BitLocker symptoms, one by one.

No match here? Run the triage →
SymptomsWhat is behind itWhat to do
The boot screen asking you to enter the recovery key for this driveBoot measurements have changed, so the TPM will not release the keyGo and find the key; do not guess
Use the number keys or function keys F1-F10 (use F10 for 0).It is telling you how to type the 48 digitsDigits only; a Windows password is no use
Recovery key ID (to identify your key):Eight characters saying which of your keys this volume expectsLook the ID up in the escrows
For more information go to: aka.ms/recoverykeyfaqMicrosoft's own guidance pageYour account is where the key sits
BitLocker waiting for activationEncryption has been set up on it but never actually runOpen to anyone; no protection at all
A locked volume on hardware that is dyingDeal with the drive, then the keyCopy it locked; unlock the copy
Sending it by post: send it tracked and fully insured to our intake lab, and we cover the postage coming back; if you want the packing checked before it goes, an engineer will talk it through with you. Every step is written out on the posting page.

The four places keys turn up.

Your own Microsoft accountSign in at aka.ms/myrecoverykey from any machine, phone included. A home PC will often have stored the key there without ever mentioning it.
A work or college loginUse the work account at aka.ms/aadrecoverykey. A managed laptop puts its own key into Entra ID with nobody lifting a finger.
Your IT deskCompany hardware escrows to Intune or Active Directory. Give the Recovery Key ID to whoever answers and the match usually takes minutes.
A printout, a file, a stickThe BitLockerRecoveryKey…TXT file sitting in a folder, or that sheet Windows kept asking you to print while it encrypted the disk. It surfaces more often than you would think.

From arrival to the files going home.

Recent jobs on record →
01

Case opened, and the diagnosis costs nothing Free

Every item gets a case number of its own the day it lands. An engineer then works out what has actually failed and tells you plainly which files have a real chance of coming back and which do not. Only then does a price follow: one figure, fixed, in writing, and it costs you nothing to see it. Nothing is charged until you say yes.

The diagnosis is freeOne price, put in writingNothing agreed
02

Begin with the hunt

Everything hangs on the eight characters shown above the prompt, because they say which key this volume will accept. From there it is a list to work through: the personal Microsoft account behind the machine, a work or university sign-in, the escrow IT keeps in Entra ID or Active Directory, and the sheet printed on the day. Without a key there is nothing, for us or anyone else.

ID read and matchedAll escrows searched
03

Take the copy locked

If the drive is on its way out, we image every sector with the lock still on, so a weakening mechanism is never asked to sit through a decryption pass.

Copied with the seal onDrive risk taken out
04

Unlock the copy, repair it

Once the key turns up, the image opens. If the BitLocker metadata is damaged too, Microsoft's own repair-bde puts the volume back together on separate media, and the files leave on a fresh disk.

repair-bde applied to the copyGiven back on new media
05

Approved by you, then posted back

No invoice is raised until the full list of recovered files has sat in front of you and you have said go ahead. Your data comes back on media we buy new, posted at our expense, and the job is not closed here until every file has opened on your own machine.

Your say-so on the file listYour data on new mediaWe cover the postage back

What the first look turns up

  • Eight characters unlock nothing — the ID only names which 48-digit key the volume wants; typed in on its own it does nothing at all. Read it out to whoever runs your IT and they can look the key up.
  • Ask anyone who was working in July 2024 — a Windows update pushed entire fleets to the recovery screen, and the CrowdStrike failure days afterwards hit 8.5 million devices by Microsoft's own reckoning. Plenty of firms learned that week that not one key had been escrowed.
  • Damaged metadata is not the end — repair-bde can put a corrupted BitLocker volume back together on other media, but you still have to supply the key.
  • Locked and failing? Copy it first — decrypting means reading the entire volume in one long unbroken run, and that is the one thing tired heads will not manage.

Plainly, then: lose the 48 digits and that volume stays shut for good. It is Microsoft's position and it is ours, because encryption a laboratory could argue its way past would protect nothing. So the opening move is searching rather than engineering — the home sign-in, the work sign-in, the escrow the IT team keeps, a sheet of paper folded into the back of a ring binder. Find the key and the files nearly always come with it. If it truly no longer exists anywhere, nobody honest can open that volume, and we will tell you so at the free diagnosis rather than after billing you.

Recent pages of the casebook.

BH · BHD-2026-8642RECORDED ✓

A firmware update, and a Dudley architect shut out of their own workstation

The workstation came up demanding a recovery key that nobody in the practice had kept, an overnight firmware update having moved the TPM measurements beneath it. Its Recovery Key ID matched an entry in the practice's Entra ID escrow, and from there repair-bde put the damaged BitLocker metadata back onto a clean disk. Every project file came through.

100% recovered3 days from arrival

Before the parcel goes.

Do this first

  • Take down every character of the Recovery Key ID
  • Try aka.ms/myrecoverykey first, then aka.ms/aadrecoverykey
  • Ask IT — work machines escrow their keys to Intune or Active Directory
  • Look for the .TXT file or the sheet printed on the day

What not to do

  • Trying to guess the digits
  • Reinstalling Windows to get rid of the prompt — the files go too
  • Putting the eight-character ID in the key's box
  • Formatting it because you assume it is locked for good

The questions that come up every week.

Where do I go looking for the recovery key?

Read off the eight-character Recovery Key ID first: it tells you which key the disk is asking for. A personal machine usually parked its key in the Microsoft account used to set it up — aka.ms/myrecoverykey. A company laptop goes to aka.ms/aadrecoverykey, or to whoever runs Intune or Active Directory. Then check the drawer for a printed sheet.

Nobody can find the key. Is that the end of it?

It is. Microsoft cannot get past it either, and neither can we — a sealed volume with no key is encryption working as intended. The jobs that come good are the ones where a key does still exist somewhere and what has actually gone wrong is hardware or metadata.

Why is it demanding a key all of a sudden?

The TPM compares the machine it measured at setup against the one booting now, and something has moved. A firmware update, a Secure Boot change, a board swap, or the drive being lifted into another computer will all do it. A Windows update in July 2024 did it to thousands at once.

The drive is locked and it is also failing. Where do you start?

With the hardware. The whole volume is imaged while it is still sealed, and the key is applied to that image, not to the drive. Decryption reads the disk end to end, which is the last thing a dying one should be doing.

Nothing more is lost while the power stays off.

Every extra power-up takes something off a drive that is already going. Leave it switched off and let the free diagnosis say what still reads.

0800 6890668