Case file · Honest limits · SDR-2025-0330
My Own Fingerprint Shut Me Out.
The reader on her laptop had stopped knowing her — it won't take my finger any more
and now it just won't let me in
— and the PIN I never use
proved as memorable as that suggests. Microsoft's helpline took her nowhere. The SSD held two volumes: Windows on one, eight years of client bookkeeping on the other.
Seeing the same thing yourself?
0800 6890668
The translation.
A Windows sign-in and the data behind it are two separate locks, and which one you are standing at decides everything else. The login is an account check bolted on top of a filesystem that anybody holding the disk may be able to read directly. BitLocker sits at a different level: it scrambles the volume itself, and with no key and no recovery password, nobody reads it — not us, not anyone. Which of the two you face takes minutes to establish, and it happens before money is mentioned.
Kit used on this job.
What happens in a case →| Platform | Its role in this case | Why we use it |
|---|---|---|
| Atola Insight Forensic | Imaged the SSD behind a write blocker, nothing altered while the position was settled | Fast imaging of several drives at once, with write blocking and reporting included |
| Passware | Opened the BitLocker volume once its recovery key had been traced | Decryption in cases where ownership is lawful and a key can be found |
| UFS Explorer Professional Recovery | Parsed the NTFS on the plain volume, then the encrypted one after it opened | Handles the difficult filesystems better than most — APFS, ReFS, XFS, ZFS, Btrfs |
In the lab.
Take the image before any decision gets made
The SSD was imaged through hardware write blocking as soon as it arrived. That counts for more than usual here: had encryption or any argument about entitlement come into it, the original needed to be provably untouched. Doing it that way costs nothing on the days it turns out not to be needed.
Establish whether it is encrypted before naming a price
Volume headers were read first. The partition holding her client files was ordinary NTFS — readable in full, the sign-in screen irrelevant to it. The Windows volume sat under BitLocker, which turned that half of the job from a reading exercise into a hunt for a key, and she was told exactly that before any quote was written.
Go looking for the key before writing it off
Microsoft accounts hold escrowed BitLocker keys far more often than owners realise, and hers did — she reached the account from her phone and found the key filed under the laptop's own name. The encrypted volume then opened as it should. Without that key, this half of her data was finished, and she would have been told so plainly.
The result.
Everything off both volumes — one read straight past the lock, the other opened with its own key. The fingerprint reader remains in disgrace. The recovery key now lives on paper, in a drawer, nowhere near the machine it unlocks.
Similar cases on the index.
Also from Honest limits.
Does this sound like your own drive?
The rule holds as in every case above: switch it off, and let a free diagnosis come before any decision.