The lab is taking new cases · 9am–5:30pm, Mon–Fri In a hurry? Call 0800 6890668
SDR Southampton Data Recovery 0800 6890668 Open a case
SDR / Casebook / My Own Fingerprint Shut Me Out

Case file · Honest limits · SDR-2025-0330

My Own Fingerprint Shut Me Out.

The reader on her laptop had stopped knowing her — it won't take my finger any more and now it just won't let me in — and the PIN I never use proved as memorable as that suggests. Microsoft's helpline took her nowhere. The SSD held two volumes: Windows on one, eight years of client bookkeeping on the other.

Result confirmed by the customer Details kept anonymous

Seeing the same thing yourself?
0800 6890668

The translation.

A Windows sign-in and the data behind it are two separate locks, and which one you are standing at decides everything else. The login is an account check bolted on top of a filesystem that anybody holding the disk may be able to read directly. BitLocker sits at a different level: it scrambles the volume itself, and with no key and no recovery password, nobody reads it — not us, not anyone. Which of the two you face takes minutes to establish, and it happens before money is mentioned.

Kit used on this job.

What happens in a case →
PlatformIts role in this caseWhy we use it
Atola Insight ForensicImaged the SSD behind a write blocker, nothing altered while the position was settledFast imaging of several drives at once, with write blocking and reporting included
PasswareOpened the BitLocker volume once its recovery key had been tracedDecryption in cases where ownership is lawful and a key can be found
UFS Explorer Professional RecoveryParsed the NTFS on the plain volume, then the encrypted one after it openedHandles the difficult filesystems better than most — APFS, ReFS, XFS, ZFS, Btrfs

In the lab.

01

Take the image before any decision gets made

The SSD was imaged through hardware write blocking as soon as it arrived. That counts for more than usual here: had encryption or any argument about entitlement come into it, the original needed to be provably untouched. Doing it that way costs nothing on the days it turns out not to be needed.

02

Establish whether it is encrypted before naming a price

Volume headers were read first. The partition holding her client files was ordinary NTFS — readable in full, the sign-in screen irrelevant to it. The Windows volume sat under BitLocker, which turned that half of the job from a reading exercise into a hunt for a key, and she was told exactly that before any quote was written.

03

Go looking for the key before writing it off

Microsoft accounts hold escrowed BitLocker keys far more often than owners realise, and hers did — she reached the account from her phone and found the key filed under the laptop's own name. The encrypted volume then opened as it should. Without that key, this half of her data was finished, and she would have been told so plainly.

The result.

Everything off both volumes — one read straight past the lock, the other opened with its own key. The fingerprint reader remains in disgrace. The recovery key now lives on paper, in a drawer, nowhere near the machine it unlocks.

The lesson here: A sign-in prompt is not encryption. Work out which wall you're behind before fearing the worst — or paying anyone.

Does this sound like your own drive?

The rule holds as in every case above: switch it off, and let a free diagnosis come before any decision.

0800 6890668