The lab is taking new cases · 9am–5:30pm, Mon–Fri In a hurry? Call 0800 6890668
SDR Southampton Data Recovery 0800 6890668 Open a case
SDR / How it broke / Encrypted & BitLocker drives

Cause of loss · BitLocker & encrypted

That recovery prompt isn’t your trouble. The lost key is.

When BitLocker drops into recovery mode it is working as designed: hardware or firmware shifted, so the drive wants proof of ownership — 48 digits of it. Most 'BitLocker disasters' are key-management failures behind an alarming screen. Get hold of the key and what follows is engineering.

Most jobs: no data back, no charge Free diagnosis & quote in writing Postal intake across all of Hampshire

Speak to an engineer about it
0800 6890668

What those signs actually mean.

Not listed? Try the triage →
On screenWhat that tells youFirst step
BitLocker recovery — Enter the recovery key for this driveThe pre-boot prompt — your TPM will not hand the key over by itselfLocate the key, no guessing
Use the number keys or function keys F1–F10 (use F10 for 0).How the 48-digit key gets typed inDigits are wanted here, not a password
Recovery key ID (to identify your key):An 8-character tag showing WHICH key applies — not the key itselfPair that ID with the correct key
For more information go to: aka.ms/recoverykeyfaqMicrosoft's stock hint addressYour account holds the actual key
BitLocker waiting for activationEncryption is on, protection is pausedOpen, but with no protection
Encrypted disk that is also dyingA physical fault sits below the encryptionClone first, then unlock
Sending it in: send your device by tracked, fully insured post to our secure intake lab — return postage is free — or ring us first and we'll talk you through packing it. Postage details sit on the contact page.

Places that 48-digit key hides.

Your own Microsoft accountLog in to aka.ms/myrecoverykey on any device — on most home machines the key is stored there automatically.
Work or school loginaka.ms/aadrecoverykey, using your work sign-in — managed devices have their keys escrowed in Entra ID.
Your IT departmentOn managed fleets, keys sit escrowed in Active Directory and Intune — and the Recovery Key ID shown on screen is all IT needs to locate yours.
Print-out, USB or fileThe BitLockerRecoveryKey…TXT or printout Windows asked you to keep at setup. It turns up more often than people expect.

How the recovery runs, step by step.

Browse recent cases →
01

Logged in, checked at no cost Free

As soon as it lands with us, your device gets its own case number. An engineer works out the fault, says what can genuinely be pulled off, then puts one fixed price in writing — no charge for diagnosis, no obligation, and no chargeable work until you approve it.

No-cost diagnosisQuote fixed in writingNo commitment
02

The key comes first

We take the Recovery Key ID from the prompt and trace it to the real 48-digit key: a Microsoft account, a work account, IT's escrow, or the printout. Without a key nobody gets the data — that is the design — so this precedes any engineering.

ID paired with keyAll escrows searched
03

Steady it, then clone

If the disk is dying as well, we take a complete copy first, encrypted sectors included, so that unlocking never has to work against failing hardware.

Encrypted copy madeDrive risk taken out
04

Unlocking and repair on the clone

Once we have the key, the volume opens on the image; if BitLocker's own metadata is corrupt, Microsoft's repair-bde route rebuilds it onto new media.

repair-bde on the cloneRestored onto fresh media
05

Checked, returned, signed off

You sign off a complete list of the recovered files first; only then does the recovery fee fall due. Everything returns on fresh media, postage paid, and the job stays open until you confirm the files open at your end.

Sign-off on the file listFresh media suppliedReturn postage on us

First checks on the bench

  • An ID is not a key — that 8-character Recovery Key ID merely says which 48-digit key applies. Read it out to your IT team and they can look yours up.
  • Two lessons in July 2024 — a Windows update pushed machines into recovery mode, then within days came CrowdStrike's outage, 8.5 million devices by Microsoft's count, leaving organisations everywhere hunting for recovery keys they had never escrowed.
  • repair-bde handles the nastier cases — should BitLocker's metadata itself corrupt, Microsoft's repair utility can rebuild that volume onto a second disk, as long as you have the key.
  • Encrypted and dying? Copy first — unlocking means long, unbroken reads: the cruellest load you can put on a failing disk.

The blunt but useful truth: a BitLocker volume with no 48-digit key cannot be opened, and that is the whole point of it — Microsoft states as much, and so do we. So the job becomes a search: personal account, work account, IT escrow, a sheet of paper. Where the key survives somewhere, the files usually follow; where it genuinely does not, no honest lab can do anything — and you'll hear that from us free of charge, not after a bill.

Out of the casebook.

EX · SDR-2026-0642CONFIRMED ✓

An Eastleigh architect's workstation, shut out by a BIOS update of its own

Overnight a firmware update altered the TPM measurements, and the machine asked for a key nobody had noted down. Its Recovery Key ID pointed to the practice's Entra ID escrow; repair-bde rebuilt the damaged BitLocker metadata onto a fresh disk, and no project file was lost.

100% retrieved3 days on the bench

While it's still with you.

Do

  • Write the Recovery Key ID down precisely
  • Try aka.ms/myrecoverykey and aka.ms/aadrecoverykey
  • Ask IT: on managed fleets, AD and Intune hold escrowed keys
  • Dig out the setup printout or the saved .TXT

Avoid

  • Trying to guess 48 digits
  • Reinstalling Windows to make the prompt go away — the data dies with it
  • Mistaking the 8-character key ID for the key
  • Formatting the disk since it's 'locked anyway'

Bench questions, straight answers.

Where is my BitLocker recovery key kept?

Look in your Microsoft account at aka.ms/myrecoverykey, or a work or school account at aka.ms/aadrecoverykey; ask IT about Active Directory or Intune escrow; or find the printout or text file saved at setup — then match it against the Recovery Key ID on screen.

Without the key, is BitLocker data recoverable?

No. We can't, Microsoft can't, nobody can — that is exactly what the encryption is meant to do. Cases that do come back are those where the key still exists somewhere and the fault lies in the drive or its metadata.

Why is my PC suddenly demanding the key?

One of the values the TPM measures shifted — a firmware or BIOS update, an altered Secure Boot setting, a board repair, the drive moved into a different machine, or a Windows update, which caught many people out in July 2024.

My drive is encrypted and it's failing too — what happens in what order?

Imaging comes before decryption. We copy the whole encrypted disk so the unlock happens on a sound duplicate — asking a failing drive to decrypt itself is the wrong order.

Whatever has gone wrong, keep it switched off.

Powering a damaged device up again costs you data. Start a case first; diagnosis is free whatever you decide.

0800 6890668