Open, and the first look is free · 9am–5:30pm, Mon to Fri Quicker to ring: 0800 6890668
RDR Reading Data Recovery 0800 6890668 Get it quoted
RDR / By symptom / The BitLocker key is missing

The fault · BitLocker, the TPM and a missing key

BitLocker recovery for Reading. Nothing is wrong with the disk; the key is what went missing.

A machine sitting at the 48-digit prompt is usually a healthy machine. When the volume was encrypted the TPM measured the board and the boot path; something has changed since — new firmware, a Secure Boot setting, a swapped motherboard — and until those digits are typed in the chip keeps the key to itself. So this job starts with sign-ins rather than screwdrivers. Most of them arrive in Reading as managed work laptops: a Caversham consultant's machine, an office PC from a Theale warehouse, a lab workstation from Didcot. The look is free, a single drive is £300 + VAT, and you are told on day one whether a key exists to be found.

Nothing recovered? On most jobs, nothing to pay The diagnosis is free; then one fixed figure in writing Parcels arrive from Newbury, Woodley and Theale

An engineer answers, and looking is free
0800 6890668

Match the symptom to the fault.

Different fault? Begin at the triage →
What you noticeWhat is likely wrongWhat happens next
A blue BitLocker screen where Windows should beThe TPM's measurements no longer match, so it keeps the key sealedFind the key. Never guess at it.
The note about the number keys and F1-F10That line only tells you how to type the digitsThe digits alone; a Windows sign-in is no use here.
Recovery key ID (to identify your key):The full ID of the one key this volume takes; its first eight characters are what the lookups match onTake that ID to each escrow in turn
For more information go to: aka.ms/recoverykeyfaqMicrosoft's own page about the promptMost keys are already sitting in an account
BitLocker waiting for activationThe volume is encrypted, but its key is stored unprotected on the disk as a clear key; the protection has not been switched onThe volume opens as normal. It is encrypted, but not yet locked.
A failing disk with a sealed volume on itHardware first, and the search for the key alongsideCopy it sealed, then unlock the copy
Packing and posting: pack it so nothing shifts, put a value on the parcel that reflects the data rather than the hardware, and send it tracked to the intake lab. The return journey is on us. If you would rather talk the packing over with an engineer before you tape the box, ring first. Every step of it is on the packing and postage page.

Four places the BitLocker key is usually sitting.

A home Microsoft accountSign in at aka.ms/myrecoverykey from any browser, including a phone. A home PC files its key there while Windows is being set up, and never says a word about it.
A workplace or college accountSign in at aka.ms/aadrecoverykey with the account your employer or college issued. A managed laptop puts its key into Entra ID by itself, without being asked.
Whoever runs the ITA company machine files its key with Intune or Active Directory. Give whoever runs it the Key ID and the lookup is usually a matter of minutes.
A printout, a text file, a stickA BitLockerRecoveryKey…TXT saved into a folder nobody opens, or the page Windows pressed you to print while the encryption ran. Both turn up more often than people expect.

From your parcel to your files coming back.

Jobs we have closed →
01

Logged the day it lands, and the look costs nothing Free

A case number goes on your device the day it reaches us, and an engineer then finds the real fault — free, and before anything else happens. You are told plainly what will come back and what will not, with one fixed figure in writing beside it. Nothing chargeable starts until you have read that and said yes.

The look costs you nothingA fixed price, in writingStill nothing to pay
02

The search for the key comes first

The Key ID above the prompt names the one key that fits this volume — its first eight characters are what every lookup matches on — and there is a short list of places it may be sitting. A printout somebody filed at setup. The Microsoft account Windows was first signed into. A work or college log-in. Entra ID or Active Directory, where an IT team has ever managed the machine. We work through the lot. If no key was ever saved, the volume stays shut for everybody, this lab included — and you are told that before money enters the conversation.

The Key ID read off the screenEach escrow checked
03

Copied with the encryption left on

A failing disk changes the order of work, not the outcome: image first, with the volume still locked, so the mechanism is spared a decryption pass it would probably not finish. The rest happens on the image.

Copied with the lock still onNothing more asked of the disk
04

Decrypt the copy, then rebuild it

As soon as a key turns up, the copy is unlocked. If BitLocker's own metadata has been damaged as well, repair-bde — Microsoft's own utility — writes the volume out onto fresh media, and your files come home on new storage bought for the job.

repair-bde run on the copyNew media, bought for the job
05

The list first, then the bill, then the files

You see the file list first, then decide. Nothing is invoiced until you have said yes, and on most jobs there is no fee at all if the data does not come back. What we pull off goes onto media bought in for your job, and the postage home is ours. The case stays open on the bench until you tell us the files open on your own machine.

Nothing billed until you say yesNew media, bought for the jobPostage home is on us

What goes wrong most often

  • Typing the ID achieves nothing — the Key ID is only a label pointing at the 48-digit string, so the box will reject it every time. Give its first eight characters to whoever runs your IT instead: from that reference a key can usually be found in minutes.
  • July 2024 is the case study — a Windows update on 9 July sent some devices to that prompt, and the CrowdStrike outage ten days later affected 8.5 million Windows machines, a figure Microsoft published itself. Plenty of firms learned that month that nobody had escrowed a key.
  • Damaged metadata can still be workable — repair-bde writes the decrypted contents of a broken BitLocker volume out onto different media, given the recovery password or key; where the metadata itself is damaged it also needs the backup key package, which exists only if it was escrowed, so the 48 digits alone are not always enough. What it cannot produce is the key itself. That half of the job stays with you.
  • Sealed and failing? Copy it first — decryption sweeps the heads over every sector without a pause, and a tired drive is precisely what will not last the run.

Put plainly: lose the 48 digits and the volume stays shut. That is Microsoft's position and it is ours, for the obvious reason — encryption any workshop could walk round would never have been worth buying. So the first move on this bench is a search rather than a teardown: home account, work account, IT escrow, a folded sheet in a ring binder. Turn one up and the data nearly always follows. Turn nothing up and no honest lab can open that disk, which is something you hear during the free diagnosis rather than read on an invoice.

How one of these actually went.

RG · RDG-2026-1792ON FILE ✓

An overnight update, and a Shinfield practice locked out of its own workstation

The key was already there — the practice simply did not know it. An overnight update changed what the TPM measures, so the workstation booted asking for 48 digits nobody had thought to write down. The Recovery Key ID on screen matched an escrow entry the firm already held in Entra ID, and that was the whole job. repair-bde wrote the decrypted contents out onto a new disk, and every project file opened as it always had.

100%was recovered3 days from arrival to return

What helps, and what makes it worse.

First things to do

  • Write the Key ID out in full; the first eight characters are what the lookup needs
  • Check aka.ms/myrecoverykey first, then aka.ms/aadrecoverykey
  • Ask IT: a managed machine files its key in Intune or AD
  • Look for the saved .TXT or the printout from setup

What makes it worse

  • Guessing at the digits
  • Reinstalling Windows so the prompt stops; that takes the files with it
  • Typing the Key ID where the key belongs
  • Formatting the drive on the assumption it has gone

Answers before you commit to anything.

Where will the recovery key actually be?

Start with the Recovery Key ID shown above the prompt: it names the one key this volume will take, and its first eight characters are what every lookup matches on. Home machines nearly always filed the key in whichever Microsoft account set Windows up, so aka.ms/myrecoverykey is the first stop. Work laptops go to aka.ms/aadrecoverykey, then to whoever runs Intune or AD. After that, the printed copy in somebody's drawer.

If nobody kept a key, is that the end of it?

Yes — that is exactly what it was sold to do. Neither Microsoft nor this lab holds a way in, so a locked volume whose key has gone stays locked. What tends to succeed is the other case: a key that was kept somewhere after all, and a fault that turns out to be a worn disk or broken metadata.

Why is it suddenly demanding a key?

The TPM compares the machine that is booting with what it measured when the volume was encrypted, and something no longer matches. A firmware update on its own will do it. So will a Secure Boot change, a new motherboard, or moving the disk into a different computer. July 2024 was the month a Windows update sent some devices to the prompt.

It is sealed and the disk is failing. Which comes first?

Hardware, first. The disk gets imaged with the volume left locked, and the key is applied afterwards to that image instead of to the original. Decryption in place demands one uninterrupted pass over the whole surface, which a worn mechanism is unlikely to survive.

Nothing gets worse while it sits switched off.

You pay nothing for the look. What comes back is a list — the files that opened, the ones that did not, and one fixed figure to finish the job. Leave it switched off until you have that in writing.

0800 6890668