Managing and enforcing security policies for devices and apps to protect organizational data through Intune
Urgent – BitLocker recovery key unavailable although protector shows Microsoft Account Backup and AAD Backup
We have an HP Pavilion x360 Convertible 15-er0xxx running Windows 11 that is currently stopped at the BitLocker recovery screen.
We are unable to locate the required 48-digit BitLocker recovery password in any of the Microsoft Entra tenants or Microsoft accounts that we have checked.
We have performed read-only diagnostics from Windows Recovery Environment and confirmed that the BitLocker recovery protector currently requested by the machine reports that it had previously been backed up to both a Microsoft account and Azure AD / Microsoft Entra ID.
Device information
Device name / drive label shown by BitLocker:
DESKTOP-JP1HPFI
BitLocker screen drive label:
DESKTOP-JP1HPFI C: 7/26/2022
Computer model:
HP Pavilion x360 Convertible 15-er0xxx
Product number:
49X66UAR#ABA
System board:
HP 88BC
BIOS:
F.16
Windows:
Windows 11
BitLocker recovery protector requested by the machine
E1BE0FF4-5E0C-4FA7-9ED7-AF49D2F71DE6
The BitLocker recovery screen requests the recovery password corresponding to this exact Key ID.
From Windows Recovery Environment, we ran:
manage-bde -protectors -get F: -type RecoveryPassword
The output shows:
Numerical Password
ID: {E1BE0FF4-5E0C-4FA7-9ED7-AF49D2F71DE6}
Backup type:
Microsoft account Backup
AAD backup
There is also a second numerical recovery protector:
704F6C54-F177-4C17-ACA6-4BC88E41D5A3
However, the BitLocker recovery screen is specifically asking for:
E1BE0FF4-5E0C-4FA7-9ED7-AF49D2F71DE6
Current BitLocker status
The Windows partition is detected as F: in Windows Recovery Environment.
manage-bde -status F: reports:
- BitLocker Version: 2.0
- Encryption Method: XTS-AES 128
- Lock Status: Locked
- Automatic Unlock: Disabled
- Key Protectors:
- TPM
- Numerical Password
- Numerical Password
- Numerical Password
- TPM
TPM / BIOS checks
We verified that the TPM is present and active.
WMI TPM information reports:
-
IsActivated_InitialValue=TRUE -
IsEnabled_InitialValue=TRUE -
IsOwned_InitialValue=TRUE - Manufacturer:
INTC - TPM specification:
2.0
BIOS currently shows:
- TPM Device: Available
- TPM State: Enabled
- Clear TPM: No
- Secure Boot: Enabled
- Platform Key: Enrolled
- Pending Action: None
- UEFI boot mode
- OS Boot Manager present
We have not cleared the TPM, reset BIOS security settings, removed BitLocker protectors, formatted the drive, or reinstalled Windows.
Account / tenant situation
The laptop may previously have been associated with the user:
******@kbeenergy.me
That user account may have been deleted more than 30 days ago.
We administer multiple Microsoft Entra / Microsoft 365 tenants and have searched the tenants available to us, but we have not located the required recovery password or a device record containing the matching BitLocker key.
We have also checked the Microsoft account BitLocker recovery-key locations available to us and have not found the matching recovery password.
What we need Microsoft Support to investigate
Please help us determine:
- Which Microsoft Entra tenant received the BitLocker recovery password for protector ID:
E1BE0FF4-5E0C-4FA7-9ED7-AF49D2F71DE6
Whether a Microsoft Entra device object corresponding to DESKTOP-JP1HPFI previously existed in one of our tenants.
Whether that device object was deleted, and if so, when it was deleted.
Whether there is any recoverable or retained BitLocker recovery-key record associated with that historical device object.
Whether the recovery password was escrowed under a deleted Entra user/device relationship that is not visible in the current Entra portal.
Whether Microsoft can identify the tenant ID associated with the historical AAD backup based on the recovery protector ID or backend audit/device information.
Whether there are any Entra audit logs, deleted-device records, Intune records, or backend records that can help identify where this BitLocker key was originally escrowed.
Please confirm whether the reported AAD backup metadata means that this specific numerical-password protector was successfully backed up to Microsoft Entra at some point, and whether Microsoft can determine the destination tenant.
Our priority is data recovery. We do not want to wipe or reinstall this computer unless Microsoft confirms that the recovery key cannot be located or recovered from any Microsoft-hosted backup location.
Please escalate this case to the appropriate Microsoft Entra / BitLocker device recovery team if first-line support cannot determine the historical tenant/device relationship.