Recovery Key Help

Shane Martin 0 Reputation points
2026-06-18T21:20:08.0166667+00:00

Where can i find an employees BitLocker key recovery?

Windows for business | Windows Client for IT Pros | Devices and deployment | Recovery key
0 comments No comments

2 answers

Sort by: Most helpful
  1. Jason Nguyen Tran 24,545 Reputation points Independent Advisor
    2026-06-19T00:14:41.3333333+00:00

    Hi Shane,

    The recovery information is stored in a few different places depending on how your organization has configured BitLocker. If the device is joined to Azure Active Directory, the recovery key is automatically backed up to the user’s Azure AD account and can be retrieved from the Microsoft Endpoint Manager admin center. For traditional Active Directory environments, the recovery key is typically stored in the computer object’s properties under the “msFVE-RecoveryInformation” attribute.

    Another option is to check the employee’s Microsoft account if the device was originally set up with one, recovery keys are often saved there. If none of these apply, the key may have been saved manually to a file or printed during setup, so it’s worth asking the employee if they have a copy. To confirm whether the Secure Web Gateway or other policies are interfering, you can also run manage-bde -protectors -get C: from an elevated command prompt to see the available recovery protectors.

    You can try these steps and let me know which path works best for your environment. If you find this answer helpful, kindly hit “accept answer”

    Jason

    Was this answer helpful?

    0 comments No comments

  2. AI answer

    2026-06-18T21:20:34.5533333+00:00

    For an employee’s BitLocker recovery key, check the locations that correspond to how the device is managed and how BitLocker was enabled:

    1. Microsoft account (personal/consumer devices)
      If the employee’s device was set up with a personal Microsoft account, the recovery key is typically backed up there:
      • From another device, go to https://aka.ms/myrecoverykey.
      • Sign in with the Microsoft account used on the device.
      • Match the Key ID shown on the BitLocker screen with the entry in the portal and use the corresponding 48‑digit key.
    2. Work or school (Microsoft Entra ID) account
      If the device is joined to your organization (work/school account):
      • From another device, go to https://aka.ms/aadrecoverykey.
      • Sign in with the employee’s work or school account (or an admin account with rights to view device keys).
      • Select Devices, expand the relevant device, then select View BitLocker Keys.
      • Use the Key ID from the recovery screen to identify the correct recovery key.
    3. Intune Company Portal (Intune‑managed devices)
      If the device is enrolled in Intune and encrypted by your organization:
      • On any device, sign in to the Company Portal website with the employee’s work account.
      • Go to Devices and select the locked PC.
      • Select Get recovery key, then Show recovery key and provide that 48‑digit key to unlock the drive.
      • If no key appears but the device is encrypted, direct the employee to your IT helpdesk or use admin tools to retrieve the key.
    4. Helpdesk / admin recovery (Microsoft Entra ID, AD, or MBAM/SCCM)
      For centrally managed devices, IT can retrieve keys via:
      • Microsoft Entra ID for Entra‑joined or hybrid‑joined devices.
      • Active Directory for domain‑joined devices.
      • A BitLocker administration portal (such as the BitLocker administration and monitoring website) where helpdesk staff:
        • Open Drive Recovery.
        • Enter the first 8 digits of the recovery key ID from the employee’s screen.
        • Retrieve and provide the matching recovery password.
    5. Other possible locations
      Depending on how BitLocker was set up, the key might also be:
      • Printed and stored with the employee’s device paperwork.
      • Saved as a text file on a USB flash drive.
    6. If no recovery key can be found
      If the key is not in any of these locations and no backup exists, the drive cannot be decrypted. The only remaining option is to reset/reimage the device using Windows recovery options, which removes all files on the drive.

    References:

    AI-generated content may be incorrect. Read our transparency notes for more information.

    Was this answer helpful?

Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.