How to find BitLocker recovery key on Windows 11

If you can't boot your computer because of BitLocker blue screen, in this guide, you can find the steps to find and apply the recovery key on Windows 11 and 10.

Windows 11 BitLocker recovery key
Windows 11 BitLocker recovery key / Image: Mauro Huculak
  • To find your PC’s BitLocker recovery key on Windows 11 (or 10), open your “Microsoft account” online and confirm the recovery from the “Devices” page.
  • You can also retrieve the encryption key from a text file, printout, or network administrator, depending on how the feature was initially configured.
  • These instructions work for Windows 11 Pro and Home.

Windows 11 can encrypt your device automatically, even if you never remember turning on BitLocker. On supported devices, the operating system can enable Device Encryption during setup, while Windows 11 Pro and higher editions also provide BitLocker for managing drive encryption.

When encryption is enabled, Windows 11 creates a unique 48-digit recovery key that can unlock the encrypted drive when the system can’t automatically verify the device. You normally won’t need this key, but changes to the TPM (Trusted Platform Module), firmware, boot configuration, hardware, or the Windows startup environment can trigger the BitLocker recovery screen.

If Windows asks for the recovery key and you don’t have it, there is no supported way to bypass the encryption and access the protected files. That’s why it’s important to know where your recovery key is stored before you encounter a problem.

Depending on how encryption was configured, you may find the key in your Microsoft account, a saved text file, a printed copy, or through your organization’s network administrator. If you have multiple recovery keys, you’ll also need to match the Recovery Key ID displayed on the BitLocker recovery screen with the correct key.

In this guide, I will show you how to find your BitLocker or Device Encryption recovery key on Windows 11 and Windows 10, how to use it when Windows asks for it, and how to make sure you have a backup before you need it.

How to find your BitLocker recovery key on Windows 11

On Windows 11 (and 10), you can find your computer’s BitLocker or Device Encryption recovery key in multiple ways, depending on how encryption was configured.

1. Find your recovery key from your Microsoft account

To find your BitLocker key on your Microsoft account, follow these steps:

  1. Open the BitLocker recovery keys page (aka.ms/myrecoverykey) online.

  2. Sign in with your Microsoft account credentials (as necessary).

  3. Confirm the available recovery keys and identify the one associated with your computer.

  4. Compare the “Key ID” with the “Recovery Key ID” shown on the BitLocker recovery screen.

    Microsoft account BitLocker Recovery key

The Key ID is important if your Microsoft account contains multiple recovery keys. Don’t simply choose the newest key. Make sure the ID matches the one displayed on the recovery screen.

Get the Pureinfotech newsletter

Expert Windows guides, practical tips, and the latest updates that make your PC easier to use, delivered to your inbox

It’s important to note that the system will only upload the encryption recovery key if you choose the “Save to your Microsoft account” option during encryption, if Windows 11 enables BitLocker automatically during installation, or if you turn on “Device Encryption” from the Settings app and your account uses a Microsoft account.

Once you complete the steps, the page will show available recovery keys along with information such as the date the key was uploaded, the Key ID, and the drive type.

The drive type can have different values, depending on where drive encryption was configured.

  • OSV: Operating System Volume. This would be the primary drive where the operating system resides.
  • FDV: Fixed Data Volume. This would be any secondary drive where you only store files and apps.
  • RDV: Removable Data Volume. This would apply to removable drives, such as USB flash drives or USB external storage devices.

If the recovery key isn’t available on your Microsoft account, you can try disabling BitLocker and re-enabling it on Windows 11 Pro, or Device Encryption on Windows 11 Home or Pro.

2. Find your recovery key from a printed copy

If you enabled BitLocker manually on Windows 11 or 10, you may have selected the “Print the recovery key” option.

If that’s the case, look for the printed text file where you normally keep important records.

Make sure the Key ID on the printed text file matches the Recovery Key ID displayed on the BitLocker recovery screen.

3. Find your recovery key from a text file

If you select the “Save to a file” option during the encryption process, you must access the file’s storage location with the BitLocker recovery key. Usually, you would have saved the file on a USB drive. If this is the case, connect the flash drive to a device to have access, and open the file with any text editor to find the recovery key.

BitLocker file with recovery key
BitLocker file with recovery key / Image: Mauro Huculak

4. Ask your organization or IT administrator

If your device is connected to an organization or school, the recovery key may be managed by your organization’s IT department rather than stored in your personal Microsoft account.

Contact your administrator and provide the Recovery Key ID shown on the BitLocker recovery screen.

On managed devices, organizations can store recovery keys through their device-management or directory infrastructure, depending on how BitLocker was deployed.

5. Check whether BitLocker or Device Encryption is enabled

If you aren’t sure whether your PC is encrypted, Windows provides settings that can help you check. Here’s how:

  1. Open Settings.

  2. Click on Privacy & Security.

  3. Click the Device encryption page under the “Security” section.

  4. Confirm that the Device encryption toggle is turned on.

    Windows 11 Home enable BitLocker

Once you complete the steps, if “Device Encryption” is available, you can see whether encryption is enabled.

On Windows 11 Pro, you can also check the BitLocker configuration through the BitLocker management tools in Control Panel.

This is worth checking before you encounter a recovery screen because you can then verify that your recovery key has been backed up.

How to use the BitLocker recovery key on Windows 11

If the device encounters an issue during startup due to BitLocker, you will be prompted to confirm your recovery key. In this case, you will have to follow these steps:

  1. Confirm the “Recovery Key ID” (first octet).

  2. Open the BitLocker recovery key using one of the methods outlined above.

  3. Find the “Key ID” that matches the “Recovery Key ID” (see step 1) to confirm the “Recovery Key” for the computer.

    Microsoft account BitLocker Recovery key

  4. Enter the recovery key in the BitLocker blue screen.

    BitLocker blue recovery screen

  5. Click the Continue button.

After you complete the steps, the computer will unlock, and Windows will start normally. However, you will still need to sign in with your credentials to access your account.

Keep in mind that entering the recovery key only unlocks the drive. It doesn’t necessarily fix whatever caused BitLocker to enter recovery mode. If the underlying problem involves the TPM, firmware, boot configuration, or another system component, the operating system may ask for the recovery key again until the issue is resolved.

My experience with BitLocker recovery

BitLocker recovery isn’t just a theoretical problem for me. I’ve personally encountered the recovery screen during startup because of an issue involving the system’s TPM.

At the time, I didn’t realize that Windows 11 had automatically configured encryption on the computer. When I went looking for the recovery key, I discovered that the key wasn’t available in my Microsoft account.

Without the recovery key, I couldn’t unlock the encrypted drive or access the files stored on it. I ultimately had to reset the operating system, which meant losing everything on that drive.

On the bright side, this happened on a secondary computer I use for testing, so I didn’t have any important files that I needed to recover.

That experience changed how I think about BitLocker. The important lesson isn’t simply to know how to find the recovery key after Windows asks for it. It’s to verify that you have a backup of the key before you need it.

If your computer is encrypted, I strongly recommend checking your recovery-key backup now rather than waiting for a TPM, firmware, or boot problem to leave you staring at the BitLocker recovery screen.

FAQs about BitLocker recovery keys on Windows 11

Here’s a list of frequently asked questions (FAQs) and answers about the BitLocker recovery keys on Windows 11.

Where can I find my BitLocker recovery key on Windows 11?

You can find your recovery key in several ways, depending on how encryption was configured. It may be stored in your Microsoft account under the “Devices” section, printed out during the initial setup, saved as a text file on a USB drive or other external storage, or (if your device is managed by an organization) available by contacting your network administrator.

Do Windows 11 Home devices have BitLocker?

Windows 11 Home does not include full BitLocker, but it offers “Device Encryption,” a limited version that automatically encrypts your drive on supported hardware. The recovery key is saved to your Microsoft account when you sign in with one.

Can Windows 11 automatically encrypt my computer?

Yes. Many modern Windows 11 devices with TPM 2.0 and Secure Boot are encrypted automatically during setup. Even if you didn’t enable BitLocker manually, your system may already be encrypted.

When would I need to use my BitLocker recovery key?

You might be asked to enter your recovery key if BitLocker detects a potential security risk. This can happen when the TPM chip notices changes in firmware or hardware, system files become corrupted, a system update activates BitLocker Recovery Mode, or the operating system can’t verify the integrity of the boot environment.

How do I know which recovery key to use on the BitLocker recovery screen?

You have to match the Recovery Key ID displayed on the BitLocker blue screen with the Key ID listed in your Microsoft account, printed copy, or text file. Enter the corresponding 48-digit key to unlock your device.

What should I do if I cannot find my recovery key?

If you lose the recovery key, you won’t be able to unlock the drive. The only solution is to reset the computer and reinstall the operating system, which will erase all files. Always ensure you have multiple backups of your recovery key.

How can I prevent losing my BitLocker recovery key in the future?

To ensure you don’t lose access to your encrypted device, it’s important to securely back up your recovery key. You can save it to your Microsoft account during the encryption setup, keep a printed copy, or store it as a text file on a secure USB drive. After enabling encryption, it’s also a good idea to verify that the key has been successfully uploaded to your cloud account.

Thank you for your feedback!
About the author

Mauro Huculak is a Windows How-To Expert and founder of Pureinfotech in 2010. With over 23 years as a technology writer and IT Specialist, Mauro specializes in Windows, software, and cross-platform systems such as Linux, Android, and macOS.

Certifications: Microsoft Certified Solutions Associate (MCSA), Cisco Certified Network Professional (CCNP), VMware Certified Professional (VCP), and CompTIA A+ and Network+.

Mauro is a recognized Microsoft MVP and has also been a long-time contributor to Windows Central.

You can follow him on YouTube, Threads, BlueSky, X (Twitter), LinkedIn and About.me. Email him at [email protected].

Comments

Join In