To find your BitLocker recovery key in Windows 11, sign in at account.microsoft.com/devices on a phone or a second computer, find the locked PC in the device list, click Show details, then open Manage recovery keys under BitLocker data protection. The 48-digit key shown there is what you type on the blue BitLocker recovery screen. For a work or school laptop, the key lives in your organisation’s directory instead — check myaccount.microsoft.com/device-list or ask your IT department.
Applies to: Windows 11 (23H2, 24H2, 25H2) and Windows 10 (22H2) | Last updated: August 7, 2026
Key Takeaways
- This is almost never something you did. Windows 11 turns on device encryption automatically on qualifying hardware and saves the key to whichever Microsoft account was signed in at setup — without ever clearly telling you.
- The key is tied to the account that set up the PC, not the account you use today. If a family member or the shop you bought it from did the initial setup, the key is sitting in their account.
- Work and school laptops store the key somewhere else entirely — in Microsoft Entra ID or Intune. Your IT department can pull it in about a minute.
- If the PC was set up with a local account, the key was never saved anywhere. Microsoft cannot retrieve, provide or recreate a lost recovery key, and neither can a repair shop.
- Every “BitLocker bypass” or “unlocker” tool you find in a search is selling you nothing. There is no backdoor, and a 48-digit key is not something that can be worked out.
Quick Steps
- On a phone or another computer, go to account.microsoft.com/devices and sign in.
- Find the locked PC in the list and click Show details.
- Under BitLocker data protection, click Manage recovery keys.
- Match the Key ID shown on the blue recovery screen to the Key ID listed on the page.
- Type the matching 48-digit key on the recovery screen and press Enter.
- If nothing is listed, repeat with every Microsoft account you have ever used on that PC.
- For a work or school laptop, check myaccount.microsoft.com/device-list or contact IT.
- Once you are back in, back the key up properly so this cannot happen twice.
Why Windows 11 Locked You Out Without Warning
Windows 11 enables device encryption by itself on hardware that supports it, and it saves the recovery key to whichever Microsoft account happened to be signed in at the time. Nobody clicks a button that says “encrypt my drive” — it happens during setup, before most people have done anything at all with the machine. That is why the recovery screen feels like it came out of nowhere.
What triggers the lockout is usually something completely ordinary. BitLocker ties itself to your hardware through the TPM chip, so when the machine changes in a way the TPM notices, it refuses to hand the key over automatically and falls back to asking you for it. The common triggers are a BIOS or firmware update, turning Secure Boot on or off, moving the drive to another machine, or sending the laptop in for a repair.
In my repair shop I saw this land on people who had done nothing wrong at all — a customer would accept a routine update, restart, and be staring at a blue screen asking for 48 digits they had never seen. If that is where you are right now, you did not break anything.
Where to Find Your BitLocker Recovery Key (Personal PC)
For a personal Windows 11 PC, the recovery key is stored in your Microsoft account, and this is where it is for the large majority of people. On your phone or another computer, go to account.microsoft.com/devices and sign in. You will get a list of every device linked to that account. Find the PC that is locked out, click Show details, look for the BitLocker data protection section, and click Manage recovery keys.
The page shows the 48-digit key along with a Key ID. The blue recovery screen on the locked PC also shows a Key ID — match those two before you start typing, because a machine with more than one encrypted drive will have more than one key listed. Print the page or save it as a PDF, then type the key in on the recovery screen.
Tip: Do not try to read the key off a phone screen while typing it into the recovery prompt. Print it or write it out first. The key contains no letters, only digits in groups of six, and a single transposed number sends you back to the start.
The Mistake That Catches Most People: The Wrong Microsoft Account
The recovery key is tied to the Microsoft account that was signed in when the PC was first set up — not the account you happen to use now. This is the single most common reason someone checks the devices page, sees nothing, and gives up.
Check every account before you conclude the key is gone. Sign in at the same URL with each Microsoft account you have ever used, including an old address you no longer check. If a family member set the machine up, or you bought it from a shop or a second-hand seller who ran through the initial setup, the key is sitting in that person’s account. It is worth the phone call — they can read it to you in a minute.
Where the Key Lives on a Work or School Laptop
A managed laptop stores its recovery key in your organisation’s directory rather than a personal Microsoft account. Go to myaccount.microsoft.com/device-list, sign in with your work or school account, and look under your devices for the BitLocker keys.
Honestly, on a managed machine the fastest route is to just ask IT. They can pull the key out of Microsoft Entra ID or Intune in about a minute, and they will not think less of you for asking — this happens constantly. Microsoft also confirmed that one of their own updates could prompt for the recovery key on the first restart on certain enterprise configurations, so it is worth asking whether that is what hit you.
The Boring Places Worth Checking
Before giving up, check the low-tech options. Some manufacturers print the recovery key on paperwork that ships in the box, so dig out whatever came with the laptop. If the PC was set up by someone careful, the key may have been saved to a USB flash drive as a plain text file — plug in any old stick you have lying around and search it for a file named with the device ID.
It is also worth checking any printout filed with your household paperwork or a note saved in your password manager. None of these are likely, but they cost you five minutes and the alternative is losing the data.
When the Key Was Never Saved At All
If the computer was set up with a local account — an offline account, with no Microsoft account attached — then there was no account for Windows to upload the key to, and it was never saved anywhere. Adding a Microsoft account afterwards does not fix it either, because the key is escrowed at the moment encryption is switched on, not later.
I would rather be straight with you than waste your time: in that situation the key is gone. These are Microsoft’s own words — Microsoft support cannot retrieve, provide or recreate a lost recovery key. Not a repair shop, not Microsoft, nobody. Microsoft documents this on their own find your BitLocker recovery key page.
That also means every BitLocker “unlocker” or “bypass” tool that turns up when you search for this cannot do it either. There is no backdoor in the encryption, and a 48-digit key is not something that can be brute-forced in any useful amount of time. If a tool claims otherwise, it wants your money or your credit card details.
The only remaining option at that point is a clean install, and you lose whatever was on that drive. If you have any drive left readable afterwards and want to try salvaging deleted files from a different, unencrypted disk, my guide on how to recover permanently deleted files for free with PhotoRec covers that — but it cannot read an encrypted volume without the key.
Back Up the Key Properly Once You Are Back In
The moment you are back into Windows, save the key somewhere you can reach without that computer. Open the Control Panel, go to BitLocker Drive Encryption and click Back up your recovery key. Windows will not let you save it onto the encrypted drive itself, which makes sense when you think about what you would be doing.
Save it to a USB flash drive and print a physical copy. I lean hard on the printed copy, because if you hit a boot failure you cannot read a text file off a USB stick from the recovery screen anyway. A sheet of paper in a drawer beats a file you cannot open.
The other habit worth building: before you update your BIOS or change Secure Boot, open BitLocker Drive Encryption and click Suspend protection first. That lets the machine boot no matter what the TPM sees change. Do the update, boot back into Windows, and turn protection on again. It takes ten seconds and it is the difference between a routine firmware update and a very bad evening.
If you would rather this never happened again, you can stop Windows from auto-encrypting in the first place. I cover that in full in my guide on how to disable forced BitLocker encryption on Windows 11 24H2, including the registry value you can set during setup before the drive is ever encrypted. If you build your own installation media, Winhance can bake that setting into an answer file so it applies on every install without you touching a command prompt.
Frequently Asked Questions
Can Microsoft support give me my BitLocker recovery key?
No. Microsoft support cannot retrieve, provide or recreate a lost recovery key — that is Microsoft’s own stated position. The key only exists where it was escrowed at the time encryption was enabled, which is either your Microsoft account, your organisation’s directory, a file you saved, or nowhere at all.
I never turned BitLocker on. Why is my drive encrypted?
Windows 11 enables device encryption automatically on hardware that meets the requirements, and it does this during setup rather than asking you. You need UEFI firmware, Secure Boot and a TPM, which covers most machines sold in the last several years. It applies to a much wider range of PCs since Windows 11 24H2 than it used to.
Do BitLocker bypass tools actually work?
No. There is no backdoor in BitLocker’s encryption and the 48-digit recovery key cannot be calculated or guessed. Any tool advertising a bypass is either useless or a scam. If the key was never saved, the data is not recoverable by any tool at any price.
What is the Key ID on the recovery screen for?
The Key ID identifies which recovery key belongs to that specific drive. If your Microsoft account lists several keys — because you have multiple PCs or multiple encrypted drives — match the Key ID on screen to the one on the page before typing the 48 digits. Entering a valid key for the wrong drive will not unlock it.
Will I lose my files if I enter the recovery key?
No. Entering the correct recovery key unlocks the drive and boots Windows normally with everything intact. The recovery key is a way in, not a reset — nothing on the drive is erased or changed by using it.
