Windows asks for a BitLocker recovery key when the encrypted drive does not unlock through its normal startup check. That can happen after a legitimate change to the PC. It does not, by itself, prove that the drive has failed or that someone attacked the computer.

If the recovery screen is already open: do not clear the TPM, reset Windows, reinstall the operating system, or keep changing BIOS/UEFI settings. First record the recovery key ID shown on the screen. Never share the separate 48-digit recovery key in a screenshot or support message.

Short answer: the trusted startup state changed

On many Windows PCs, BitLocker works with the Trusted Platform Module (TPM). During a normal startup, the TPM checks parts of the early boot environment before releasing the information Windows needs to unlock the system drive. If those measurements no longer match the state it trusts, BitLocker asks for the recovery key instead.

This is a security stop, not a diagnosis. A firmware update, a changed boot path, a replaced motherboard, or an altered partition layout can resemble an unauthorized change from BitLocker's point of view. The recovery key proves that the person at the keyboard is allowed to unlock the drive.

Common reasons the screen appears

What changedWhy BitLocker may reactSafest first check
BIOS/UEFI, Secure Boot, or early-startup firmwareThe startup measurements seen by the TPM may differ from the previously trusted state.Confirm whether a firmware update or settings change was intentional. Do not change several firmware options at once.
Motherboard or TPMA replacement motherboard normally brings a different TPM, while clearing or disabling the TPM removes the expected trust relationship.Ask the repair shop or IT administrator exactly what was replaced or reset.
Boot order, external boot media, docking, or network bootThe PC may be starting through a different path from the one BitLocker previously measured.Remove only newly attached, nonessential boot media and restore a known intentional setup.
Boot manager or partition layoutChanges to boot files or the disk's partition layout can trigger recovery.Stop partition editing and write down the tool and operation that ran immediately before the prompt.
Encrypted drive moved or clonedThe drive is now attached to a different hardware and startup environment.Keep the original drive unchanged and confirm which disk the firmware is trying to start.
Repeated PIN attempts or a TPM errorThe normal unlock method may be unavailable or locked out.Do not keep guessing. Retrieve the recovery key through the account or administrator that manages the PC.

What to do now

  1. Record the exact screen. Note the recovery key ID exactly as shown, along with any message or web address. The key ID helps you choose the correct stored key; it is not the secret key itself.
  2. Think back to the last successful startup. Was there a firmware update, repair, SSD change, BIOS/UEFI adjustment, dock change, or failed boot immediately afterward? One clear change is more useful than a long list of guesses.
  3. Find the matching key. Use our BitLocker recovery-key checklist to check the appropriate Microsoft account, work or school account, printout, or USB record.
  4. Match the ID before entering anything. An account may contain keys for several devices or old BitLocker configurations. Use only the recovery key listed beside the ID on the locked PC.
  5. Enter the key privately. Type it directly on the locked computer. Do not send it to RestorePath Lab, a forum, a repair listing, or anyone who cannot explain why they need complete control of the encrypted drive.
  6. After Windows starts, restart once before declaring the issue fixed. If recovery appears again, investigate the triggering change rather than repeatedly entering the key and ignoring it.

If the prompt followed a BIOS or firmware update

A planned firmware update can be legitimate even when it changes something BitLocker measures. If you trust the update source and have the matching recovery key, unlocking the drive is the normal recovery path. After Windows starts, confirm that the update finished and that BitLocker protection is active, then test one ordinary restart.

For a future planned firmware or hardware change, Microsoft recommends suspending BitLocker protection beforehand and resuming it afterward. Suspension leaves the drive encrypted but temporarily avoids the normal platform-validation check. This is preparation for a known change, not a way to fix a PC that is already locked.

If the prompt followed an SSD clone or drive move

Do not erase the old drive merely because the copy operation completed. A clone can contain the expected Windows files and still fail the startup checks because of firmware boot order, partition layout, encryption state, or the new hardware path.

Keep the old disk disconnected but unchanged while you identify the new and old drives by model and capacity. Then work through the safe checks for a cloned SSD that will not boot. Before another migration attempt, use the SSD migration checklist to record the recovery key and preserve a rollback copy.

If you never remember turning on BitLocker

Some Windows devices enable Device Encryption automatically during setup. Microsoft says that, in this situation, the recovery key is saved to the Microsoft account or work or school account used when protection was activated. The relevant account may belong to the person who first configured the PC, not necessarily its current everyday user.

Starting with Windows 11 version 24H2, the recovery screen can show a hint for the Microsoft account associated with the key. Treat that hint as a direction for where to sign in, not as permission to share the recovery screen publicly.

What if the recovery key cannot be found?

There is no recovery-software shortcut around correctly implemented BitLocker encryption. A scanning tool may recover files from storage that is accessible and unencrypted, but it cannot turn encrypted sectors into usable files without the required decryption material. Microsoft Support also cannot retrieve or recreate a lost key.

Resetting is a data-loss decision. Microsoft states that if the key cannot be found and the change that triggered recovery cannot be undone, resetting the device removes its files. Do not describe a reset as recovery of the locked data.

Reduce the chance of being stuck next time

  • Confirm that the current recovery key is backed up somewhere you can reach from another device.
  • Keep the key separate from the encrypted PC and label the record with the device, not with the full key in an exposed filename.
  • Before a planned motherboard, TPM, firmware, or boot-layout change, check the key and follow Microsoft's suspend-and-resume procedure.
  • For an organization-managed computer, let IT manage the recovery record and planned hardware work.
  • Keep a separate backup of important files. A recovery key restores access to an encrypted volume; it does not replace a backup if the drive itself fails.

Bottom line

A BitLocker recovery prompt means the automatic unlock check did not pass. Start by preserving the current state, matching the recovery key ID, and identifying the last intentional change. Use the correct key if you have it; do not clear security hardware or reset Windows in the hope that encrypted files will become readable.

Official references checked July 30, 2026: Microsoft's BitLocker overview, finding a BitLocker recovery key, and Microsoft Learn's BitLocker recovery scenarios.