Find Your BitLocker Recovery Key in Windows 11 and 10

Logeshwaran

Your BitLocker recovery key is almost certainly sitting in your Microsoft account. On a phone or another computer, go to aka.ms/myrecoverykey, sign in with the Microsoft account that set up the locked PC, and compare the first 8 characters of the Key ID on your blue recovery screen with the Key IDs listed there. Type the matching 48-digit number into the PC. If that machine was ever issued by an employer or a college, use aka.ms/aadrecoverykey with the work account instead. If it is in neither, there are four more places it hides — and one case where it is genuinely gone, which this page will not pretend otherwise about.

⚡ Quick Answer

Personal PCaka.ms/myrecoverykey, sign in, match the Key ID

Work or college laptopaka.ms/aadrecoverykey, or ask your IT desk — it takes them seconds

Saved it yourself once → hunt a file named BitLocker Recovery Key, a printout, or a USB stick

Windows still starts → an admin prompt and one command prints it

48 digits, no letters. The code with letters is the Key ID — it says which key, not what it is

Nothing in any of those places? Read this before you spend money.

A blue screen with a number on it

A customer brought Jake a two-year-old laptop that would not start. Not a crash — a calm blue page asking for a BitLocker recovery key, with a long identifier printed underneath. She had never heard of BitLocker. The laptop held six years of her catering business.

Jake did what most people do: found a page listing five places to look, and worked all five on speakerphone. Two hours. Nothing.

"Read me what is on the screen," Ethan said. "Including the code underneath. That is the Key ID, not the key. Did you check it against the ones in her account?"

"Four devices were listed. I tried the first, it said wrong key, so I assumed the account was a dead end."

"It was the right lead. You picked the wrong entry off it. That code exists to tell you which of the four to use."

Ninety seconds later she was in — after two hours lost to a field every guide tells you to ignore. So we start there.

Read the Key ID first. It is the index

The screen shows two different things, and confusing them costs people hours.

The recovery key: 48 digits, no letters

A recovery key is forty-eight digits, in eight groups of six separated by hyphens, with no letters anywhere.

That one fact closes a lot of dead ends: if what you found has letters in it, it will never unlock the drive. The digits are not arbitrary either — each group of six divides by eleven, a checksum, which is why Windows rejects an invalid key the instant you finish typing.

The Key ID: a label saying which key

Underneath the prompt sits a recovery key ID — a long string with letters in it. It is not a password, and typing it achieves nothing.

"Think of it as a name tag," Ethan said. "Every key BitLocker makes gets one, and the two are filed together. Your account doesn't show you a key — it shows every key you have ever had. The tag says which."

"So three of her four devices were irrelevant."

"You never had a wrong-account problem. You had a filing problem, and the label was printed on the screen the whole time."

So when your saved list shows four devices, or a laptop you sold in 2021, compare the first eight characters against your screen and exactly one entry matches. Write those eight on paper before you leave the machine — going back to squint at it a third time is how transcription errors begin.

On 24H2 and later, the screen also hints at the account

This is newer, and most guides predate it. Current builds show a hint of the Microsoft account holding the key, usually a partly masked email address — which, if you have three accounts and no idea which set the machine up, removes an entire category of wasted afternoon. No hint means an older build.

Which situation are you in?

Work down this in order — arranged by how often each is the answer, not by how clever it is.

Your situation Where the key is Go to
Home PC, signed in with a Microsoft account Uploaded automatically. The common case, by a wide margin. Route 1
Laptop from an employer, school or college Your organization directory, readable by IT Route 2
You switched encryption on yourself and chose where to save the key A text file, a USB stick, or a printout Route 3
The PC starts; a second or external drive is locked Readable from inside Windows with one command Route 4
Local account only, never signed in, nothing saved Possibly nowhere — read the limits honestly The hard case

One thing to settle first: the locked PC does not need to be online or working while you look. Every route here happens on a phone or a borrowed laptop.

Route 1: your Microsoft account

Start here even if you never saved a key — especially then, because Windows saved it for you.

  1. On a phone or second computer, go to aka.ms/myrecoverykey.
  2. Sign in with the account used on the locked PC.
  3. You get a list of devices, each with a Key ID and a Recovery key.
  4. Find the entry whose Key ID starts with the same eight characters as your screen.
  5. Type that 48-digit key into the locked PC. Digits only, and the number pad works.

Why a key you never created is in an account you barely use

Since Windows 11 version 24H2, drive encryption is on by default on new PCs and clean installations, including Home editions, where it is called Device Encryption. Nobody prompts you.

Jake did not take that well. "It encrypted her drive, never asked, never told her, then locked her out of six years of invoices. That's not a safety net. That's a trap with a help page."

"It's the right call and I'll defend it," Ethan said. "A stolen laptop used to be a filing cabinet anybody could open. Now it's a brick. What Microsoft got wrong isn't the encryption, it's the silence — one screen at setup saying your drive is encrypted, here is your key would end most of these searches. Switching it on quietly was right. Not mentioning it was cowardly."

What Windows does is escrow the key to the Microsoft account you signed in with during setup — which is why a key you have no memory of creating exists at all.

Older machines differ. Before 24H2, somebody usually turned this on deliberately and the key went wherever that person chose. Our walkthrough of device encryption on Home editions covers that setup, and those choices still decide where an older machine's key ended up.

You have more than one Microsoft account. Most people do

An old Hotmail address, an Xbox account, something from a phone setup. The key is in exactly one of them: the account signed in on that PC. Ways to work out which:

  • The hint on the recovery screen, if the build is new enough.
  • The sign-in screen of the locked PC, if it got that far. The email under the user name is the account.
  • Another device signed in as the same person — a phone with Outlook, an Xbox, a tablet.
  • Check each account you have. Two minutes apiece, and exhaustive.

If the account name itself is the puzzle, our guide to finding your Windows user name helps. And if you are unsure the PC used a Microsoft account at all, telling a local account from a Microsoft account is the check to run first — if it was local, Route 1 was never going to work.

The page loads but the list is empty

Four explanations, and only one is bad news.

Wrong account. Much the most likely. Try the next.

A local account. Nothing was uploaded because there was nowhere to upload it. Try Routes 3 and 4.

Someone else set the machine up. A spouse, a son, the shop that sold it. The key is in their account and invisible from yours — the commonest resolution of all.

The device was removed from the account. Keys can be deleted, by tidying a device list or by an interrupted factory reset. That one is genuinely bad news, and it is why the limits section exists.

Route 2: a work, school or college machine

If the laptop was ever issued by an organization — even one you left years ago — the key almost certainly went into that directory rather than your personal account.

Go to aka.ms/aadrecoverykey and sign in with the work or school account, not a personal one. Depending on the configuration, you may see your own devices' keys directly.

If you cannot, stop and contact the IT desk. Genuinely, stop. This is among the most routine requests a help desk handles, it takes under a minute, and every hour spent avoiding the call is wasted.

Two variations worth knowing:

  • Older company networks keep keys in an on-premises directory rather than a cloud one. You will never see those yourself; an administrator reads them from their console.
  • A personal PC once joined to a work account to read email can have its key in the company directory. People forget they ever did this.

If the organization no longer exists, that route is closed. Ask anyway — former employers routinely hand over a key for a device that is clearly personal.

🔬 How this was tested

Re-checked on 9 August 2026 against Windows 11 25H2 (build 26200), 24H2 (26100) on a second machine, and a Windows 10 22H2 (19045) laptop. The account routes were walked end to end from a phone, with the locked machine left at its recovery screen. The command routes were run in an elevated session on 25H2 and Windows 10, and the output described is what they printed.

What we could not verify first-hand: the exact wording of the recovery screen across every manufacturer's firmware; the behavior of an organization-managed device, since we do not administer one, so Route 2 follows Microsoft's documented paths; and the account hint, confirmed on current builds but not on every hardware combination. Where this page says "usually", that is deliberate.

Route 3: the file, the printout and the USB stick

If anyone enabled encryption deliberately, Windows made them choose where to keep the key. Three offers, three traces.

A text file with a predictable name

Saving to a file produces a plain text document named BitLocker Recovery Key followed by a long identifier, which makes it easy to search for. Search every drive you own, not the obvious one: other computers in the house, external disks, USB sticks in a drawer, cloud storage. Search your email too — a good number of people mailed it to themselves, and searching a mail account for "BitLocker" takes ten seconds.

One place it will never be: the encrypted drive itself. Windows refuses to save a key onto the drive it unlocks.

A printout, or a PDF pretending to be one

Look in the file drawer, the warranty folder, the back of the manual. Many people chose print and then printed to a PDF, which puts it on a disk under a name they invented. Sort a documents folder by date and look at what was created when the machine was new.

A USB stick, and the one that is not a recovery key

Check every stick you own, including ones that look empty, and switch on hidden files first. Two things live on USB sticks and only one is what you want. A startup key is a small hidden file that unlocks a drive automatically when the stick is plugged in. It is not the recovery key and holds no 48-digit number — but if such a stick exists, plugging it in may let the machine boot.

Route 4: read it out of a Windows that still works

"This is the one every forum leads with, and it's the worst of the four," Ethan said. "Not because it fails. It works perfectly. Because the machine that would run the command is the machine that won't start. It's a brilliant answer to a question nobody asks at midnight."

Which is to say it works when Windows starts normally and something else is locked — a second internal drive, an external disk, a drive moved from another machine. It also works as prevention: run it today on the machine you are reading this on, and save what it prints.

It cannot help you at the recovery screen: no command typed at a blue prompt will produce the key.

The command prompt method

You need an elevated prompt — one with administrator rights, since Windows keeps that power switched off by default even for administrator accounts. Our step-by-step on opening Command Prompt as administrator covers the ways in.

manage-bde -status
manage-bde -protectors -get C:

The tool is manage-bde, with "bde" standing for BitLocker Drive Encryption. The first command lists every volume and says which are protected, locked or untouched, so run it first. The second prints that volume's protectors: scroll to the section headed Numerical Password, where the long number is your 48-digit recovery key and the identifier above it is the Key ID matching the blue screen.

The PowerShell method, which is easier to save

(Get-BitLockerVolume -MountPoint "C:").KeyProtector

Same information as a table, and PowerShell must also be elevated — our explainer on opening PowerShell and how it differs from the ISE is a two-minute read.

Prefer it here because you can send the output straight to a USB stick in the same breath, turning "I read my key once" into "I have a copy". Add | Out-File E:\key.txt, with your stick's letter in place of E.

⚠ One limit on Home editions

The manage-bde tool and the BitLocker control panel are Pro, Enterprise and Education only. On Home they are simply absent, and a missing command is not a sign that something is broken. Home still encrypts, through Device Encryption, using the same technology and producing the same kind of recovery key. On Home the account route is the route, and the key lives in Settings under Privacy & security, in the Device encryption section, with a button to back it up.

"So a Home customer gets locked out by something they can't even open a control panel for," Jake said.

"They can, and they're the least likely to know a key exists at all," Ethan said. "On a Home machine, ignore every command-line guide you find and go straight to the account page. Half the advice out there is written by people who have only ever used Pro."

With a key in hand, an encrypted secondary drive unlocks straight from File Explorer — double-click and it asks. Where Explorer is unavailable, reaching a command prompt at boot is the way in, and it is also where the drive repair tool lives.

Why it asked you in the first place

Normally you never see this screen. The key is held by the TPM — a small security chip on the motherboard — which hands it over silently at every boot, which is why an encrypted laptop feels like an unencrypted one.

It does that on one condition. At startup it measures the firmware and the boot path, and releases the key only if those measurements are what it expects. Change any of them and it refuses, which means asking you. That is the feature working: a thief who moves your drive into another machine gets different measurements and a blue screen instead of your files.

What actually trips it, roughly in order of frequency:

  • A firmware or BIOS update. The commonest cause by a distance, often delivered overnight, so yesterday's working machine demands a key today.
  • Changing a firmware setting — Secure Boot, boot order, virtualization, or the chip itself.
  • Hardware changes. A graphics card, a memory upgrade, sometimes a new docking station.
  • Moving the drive to another computer. Working as intended.
  • Dual-boot changes, such as installing Linux and altering the boot loader.

It keeps asking every single time

Typing the key gets you in, but the mismatch remains, so the next boot asks again — which means keeping a 48-digit number on a sticky note, quietly undoing the point of encryption.

Make the chip take fresh measurements. From inside a working Windows, suspend protection and resume it: on Pro, manage-bde -protectors -disable C: then manage-bde -protectors -enable C:; on Home, the pause and resume controls in Device encryption settings. Restart and the prompt should be gone. If it returns, the chip may be reporting errors, which is a hardware problem.

Stopping it happening next time

Before any firmware update, before opening the case, before changing firmware settings: suspend BitLocker first. On Pro, Suspend-BitLocker -MountPoint "C:" -RebootCount 1 in an administrator PowerShell suspends protection for one restart and resumes automatically, with the drive staying encrypted throughout. Thirty seconds of typing removes the commonest cause of this problem, and while most manufacturer update tools now do it for you, most is not all.

The other options on the recovery screen

The recovery screen usually offers a route into the wider recovery environment — startup repair, system restore, a command prompt. None of it decrypts anything without the key, but it earns its place when the drive is unlocked and Windows still will not boot; our guide to reaching Advanced Startup walks the menus. Do not touch reset or reinstall while a drive is locked: on an encrypted drive that is not a repair, it is a wipe.

🙋‍♂️ Jake's Reality Check

"Honest question, and I feel stupid asking it. I sell computers. If the key is nowhere, is there really nothing? A shop two streets over advertises data recovery for $200. Are they lying?"

Data recovery is a real trade, and a good shop does remarkable things with a failing, dropped or wiped drive. None of that skill applies here. Those techniques read what is physically on the platters, and on an encrypted drive that is noise until the right key transforms it. The best lab in the country recovers, perfectly, a complete copy of noise.

So ask one question before paying: do you need my recovery key? If yes, they are honest and may well help, because there is real work in a drive that has a key but is damaged. If no, walk out.

On Windows 10, specifically

Every route here works identically on Windows 10. Same account pages, same commands, same 48 digits, same Key ID matching. Three real differences:

  • Encryption was far less likely to be on by accident. Default-on arrived with 24H2, so somebody usually chose it — making the file and printout route far more likely to pay off.
  • The settings sit elsewhere. Device encryption is under Update & Security rather than Privacy & security; the Pro control panel is where it always was.
  • No account hint on the recovery screen. You identify the right account yourself.

The honest bit, which matters more here than most: Windows 10 reached end of support on 14 October 2025. It still boots and your drive is still encrypted, but free security updates stopped. There is an odd tension in a machine that guards its contents against a thief with a screwdriver while taking nothing new against anything arriving over the network.

Two ways to close that. Consumer extended security updates enroll from Windows Update, are free if you sync settings with Windows Backup, and now run into October 2027. Or move to Windows 11 if the hardware qualifies — our rundown of the Windows 11 requirements and how to check eligibility answers that in minutes.

If the key is nowhere: the honest answer

Every account checked, every drawer searched, no key. Here is the part most pages will not put in writing.

⚠ The limit, stated plainly

If no copy of the key exists in any account, file, printout or directory, the data on that drive cannot be recovered. Not by you, not by Microsoft, not by a recovery lab, not by software you can buy.

There is no master key and no support override, because either would mean the encryption never protected anything. Nor can the key be guessed: 48 digits is a space no computing works through, and it cannot be rebuilt from a few remembered characters. If a product page says otherwise, you are reading marketing.

"Say it to the customer in one word," Ethan said. "Not 'difficult', not 'we'll try'. Gone. Every hour you let somebody hope is an hour they are not spending rebuilding from what they still have."

"That is a horrible conversation to have."

"It's a five-minute horrible conversation instead of a three-week one. And anything advertising that it unlocks a BitLocker drive without the key is a scam, with no clever exception. If it worked, nobody would use the encryption."

Worth trying before you accept it

  • Every Microsoft account you have ever had, including addresses you no longer use.
  • Whoever set the machine up. A family member, a colleague, the shop.
  • Any organization the device was ever enrolled with, however briefly.
  • Old machines and old backups. A key file copied during a migration survives in unexpected places.
  • Old phones and photo libraries. Photographing the screen is how many people saved this.

What the drive repair tool does and does not do

You will find references to a BitLocker repair tool, run from a command prompt in the recovery environment. It is real and useful — for a damaged drive, where the encryption information is corrupted, it reconstructs enough to salvage files. It still requires a valid recovery key, plus a key package saved earlier if the damage is bad. It repairs damage. It does not remove the need for a key.

What to do with the machine now

Reinstall Windows on the drive. The hardware is fine, it just holds unreadable data. A clean installation formats it and you have a working machine again. Everything on it is gone.

Or shelve the drive. Keys turn up — in an old email, inside a manual, in a spouse's account. If the data mattered enough to spend a week on, it is worth a $40 caddy rather than a format.

And the one people forget: the data may already exist elsewhere. Photos synced to a phone, documents in cloud storage, email on a server. List what was on the drive and check each item, because the irreplaceable part is often small.

Five minutes that prevent all of this

Do this on every machine you own, now rather than next week.

1. Find out whether encryption is on at all. Home: Settings, Privacy & security, Device encryption. Pro: the BitLocker control panel, or manage-bde -status. On a PC bought in the last two years, expect yes.

2. Back the key up in two places, one physical. The account copy is automatic and excellent, but it fails in the exact situation where you have lost the account. A printout in a drawer covers that.

3. Verify it. Everyone skips this. Open the account page on your phone now and check a key is listed for this machine, with a Key ID beside it. An unverified backup is a belief.

4. Never keep the only copy on the encrypted drive. Windows blocks the obvious version, but a key in a notes app that syncs nowhere else is the same mistake in a hat.

5. Back up the data as well as the key. Encryption protects against a stolen laptop. It does nothing against a failed drive, a deleted folder or ransomware, and a key is not a copy of your files. If you have never set one up, making a full system image captures everything rather than just the documents folder.

If you would rather not have encryption at all, you can turn it off and Windows decrypts in the background.

"Fair enough on a desktop that never leaves the house," Ethan said. "On anything you carry, keep it. That same laptop, left on a train, becomes a folder anybody can read. The answer to being locked out is a key you saved, not a drive you left open."

Questions people actually ask about this

Where is my BitLocker recovery key stored?

Almost always in the Microsoft account signed in when the drive was encrypted, because Windows uploads it there by itself. Otherwise a text file, a printout, a USB stick, or an employer directory.

How do I find my BitLocker recovery key with a Microsoft account?

Go to aka.ms/myrecoverykey from a phone and sign in with the account used on the locked PC. Match the first eight characters of the Key ID on your screen, then type the 48-digit key beside it.

What is the recovery key ID on the blue screen for?

It is a label, not the key. It says which key you need out of every key you have ever saved. Match its first eight characters and exactly one entry is right.

What does a BitLocker recovery key look like?

Forty-eight digits, in eight groups of six separated by hyphens, with no letters anywhere. If what you found contains letters, it is not a recovery key and will never unlock the drive.

Why is my drive encrypted when I never turned BitLocker on?

Because on Windows 11 version 24H2 and later encryption is on by default on new PCs and clean installs, including Home. The key is escrowed to the Microsoft account used during setup.

Can Microsoft support recover my BitLocker key for me?

They can help you back into the right account and see what is stored there. They cannot produce a key that was never uploaded. There is no master key and no support override.

What if there is no recovery key anywhere?

Then the data on that drive is not recoverable. You can reinstall Windows on the drive, which wipes it, or shelve the drive in case a copy of the key turns up later.

How do I find the recovery key for a work or school laptop?

Go to aka.ms/aadrecoverykey and sign in with the work or school account. If the device is managed, the key sits in your organization directory. If you cannot see it there, ask IT.

Can I get the recovery key from Command Prompt or PowerShell?

Yes, but only from a Windows that is already running and unlocked, with administrator rights. It cannot help you at the recovery screen, because the system holding that information has not started.

Why does Windows keep asking for the recovery key at every startup?

Because the security chip is still measuring something it does not recognize, so the automatic unlock fails on every boot. Suspend protection and resume it from inside Windows so the chip re-measures.

Does a BIOS or firmware update trigger BitLocker recovery?

Often, and it is the commonest cause of a surprise recovery screen. Changing the firmware changes what the chip measured at boot, so the automatic unlock refuses. Suspend protection before updating.

Is BitLocker available on Windows 11 Home?

Home does not get the full management tools, so the control panel and command line utility are absent. It does get Device Encryption, which produces the same kind of recovery key.

My key was rejected as incorrect. What now?

Check the Key ID first, because a real key belonging to a different drive is the usual explanation. Then check for transcription slips, and look for older entries in the same account.

How do I back up my BitLocker recovery key properly?

Keep it in two places that are not the encrypted drive, and make one of them physical. Then verify it by finding the key from another device the way you would in an emergency.

Does any of this work differently on Windows 10 now that support has ended?

Every route here works the same on Windows 10 today. What changed is the risk around it, since free security updates stopped in October 2025. Extended security updates close that gap.

What Jake does now

The catering laptop went back with its invoices intact. What stood between that customer and a night of believing six years of work had ended was an eight-character code she was too frightened to read.

"It should have taken ninety seconds," Jake said. "Not two hours."

"It took two hours because you did what every guide says, which is start looking. The screen was telling you which one to look for. And if the account had been empty?"

"Then you tell her the truth on Saturday morning instead of letting her hope until Wednesday. A worse conversation, and a much better one to have."

Jake now checks encryption on every machine that comes through the shop and asks one question: do you know where your recovery key is? Almost nobody does.

Which is the point of this page. The blue screen is a lock working as designed. The problem is that the key was escrowed somewhere you never looked, or nowhere at all, and you find out which on the worst possible morning. Check yours now.

Revision note. Originally published in December 2016, from an evening helping a friend who had encrypted a drive, not saved the key, and had no internet on the machine at the time. Rewritten on 9 August 2026 after re-testing every route on Windows 11 25H2, 24H2 and Windows 10 22H2. Most of what changed is not our doing: in 2016 BitLocker was switched on deliberately, and since 24H2 it arrives by default with the key escrowed to your Microsoft account automatically — which turns the question from "where did I put it" into "which account is it in". Hence the account routes and Key ID matching leading this version. One thing in the original does need correcting outright: it suggested reconstructing a key from remembered fragments. A 48-digit key cannot be guessed or partially recalled into existence, and we would rather say so in the first minute than let anyone spend a fortnight on it. If your machine shows something this page does not describe, do write in through the contact page and tell us what you saw. We read every one, and this page is better for it.

Related