Your PC booted to a blue screen asking for a 48 digit recovery key, and you have never heard of BitLocker. Nothing is broken and you have not been hacked.
Windows encrypted the drive at some point, something about the machine changed, and it now wants proof you own it. I want to get you to the key first, then explain what set this off.
Work down this list in order. Most people find theirs at number one.
Before anything, write down what is on screen
There is a number on that screen you will need. It is easy to miss.
Documented by Microsoft on its find your recovery key page: "When you are prompted to enter a BitLocker recovery key, take note of the first 8 digits of the recovery key ID."
⭐ That ID is how you tell which key is yours. An account can hold keys for several machines and several drives, and they all look alike. Eight digits sorts it in one glance.
Write it down on paper. You are about to use another device. You cannot copy and paste off a locked PC.
1. Your Microsoft account, where most of them are
Start here, because Windows puts the key here on its own.
Microsoft's own address for it: `https://aka.ms/myrecoverykey`
Open it on your phone or another computer. Sign in with the Microsoft account you use on the locked PC. Then match the Key ID.
Microsoft on why it is there without you doing anything: "When you first sign in or set up a device with a Microsoft account, or work or school account, Device Encryption is turned on."
⚡ Try every Microsoft account you have ever used on that machine. An old address you signed in with once during setup is a common place for it to be sitting.
2. A work or school account
Different door, and the key will not be in your personal account if this is how it was set up.
Microsoft's address for these: `https://aka.ms/aadrecoverykey`
Sign in, choose Devices, expand the device, and select View BitLocker Keys. Match it on the ID.
⚠️ If the machine belongs to an employer, ask them rather than working through this alone. They may hold the key centrally, and on a managed device they are the only ones who can hand it over.
3. A printout, a USB stick or a saved file
If somebody set your PC up carefully, the key may be sitting in a drawer.
Microsoft lists four places a key can have been put. Backed up to a Microsoft account, saved to a work or school account, printed, or saved to a USB flash drive.
⚡ A saved file is plain text and it opens in Notepad. Look for a file with BitLocker in the name, on a USB stick, in Documents on another PC, or in OneDrive.
⭐ Check the box the PC came in. Machines set up in an office are often shipped with the key printed and taped inside.
4. Another account on the same PC
Worth a look before you give up, and people forget it.
If the PC has more than one user, the key went to whichever account had encryption switched on. That may not be yours.
Microsoft is precise about the local account case: "If you're using a local account, Device Encryption isn't turned on automatically." So a machine set up entirely on a local account should never have got here on its own.
⚠️ A machine that was later switched to a local account is a different story. The encryption was already on. The key is in whatever Microsoft account was signed in at the time.
5. When the answer is that there is no key
I would rather tell you this than let you spend three days on it.
An adviser answered this on Microsoft's board in April 2025, replying to somebody with three machines and no keys: "There is no option available to find a Bitlocker Recovery Key on a Local account, it is not stored locally, the only place the Bitlocker key is automatically stored is on the associated Microsoft account online that may have been previously used on the PC."
The owner asked the follow-up you are probably thinking of. Could they add a Microsoft account now and have the key appear?
The same adviser, the next day: "It is not possible to later add a Microsoft account after Bitlocker is enabled the old Bitlocker key would not be added to the Microsoft account, that only happens when Bitlocker is initially enabled."
⛔ And Microsoft closes the last door itself: "Microsoft Support doesn't have the ability to retrieve, provide, or recreate a lost BitLocker recovery key."
That is the end of it, and I would rather say so. No key, no data. The drive can be wiped and Windows reinstalled, and whatever you had on it is gone.
What set this off, and why now
The encryption was already on your machine. Something changed that BitLocker treats as suspicious.
Documented by Microsoft: "Device Encryption is a Windows feature that enables BitLocker encryption automatically for the Operating System drive and fixed drives."
The usual triggers are short and physical. Think back over the last week on your machine.
A firmware or BIOS update, a change to Secure Boot, a new drive or graphics card, a different boot order. Or a Windows update that touches the boot chain.
An owner described this in June 2026, on corporate tablets running local accounts, after installing KB5094126 on build 26100.8655. The machines rebooted straight into BitLocker recovery. No key was backed up anywhere.
An adviser on Microsoft's staff answered with an explanation and a route. The update hardened the boot chain, which changed the TPM register values BitLocker checks. Temporarily switching Secure Boot off in the firmware may let the machine past the prompt.
⛔ Nobody on that thread came back to say it worked. I am printing it because it is the only route offered by anyone with standing, not because it is proven.
⚠️ And it lowers a real security setting. Switch Secure Boot back on the moment you are in. Then suspend BitLocker before the next firmware update.
⛔ One answer on that thread was machine-written and labeled as such. I left it out, and this page records that rather than hiding it.
The one thing to do today, if you can still get in
This is the part that will actually save somebody. It takes two minutes.
If your PC is working right now, get the key off it. Do it before you ever need it.
Microsoft's route: from Start, type BitLocker and open Manage BitLocker. Then select Back up your recovery key next to the drive.
You get four choices. Save to your Microsoft account, save to a USB flash drive, save to a file, or print it. Any of them counts.
⭐ Do two of them. The account copy survives losing the paper, and the paper survives losing the account.
Microsoft's warning about where you put it: "Don't store this USB flash drive with the key on it with your computer. If a thief were to get the computer, they could steal the flash drive and bypass BitLocker encryption, leaving your data vulnerable."
⚡ This is the answer to the adviser's point above. The automatic backup only happens once, when encryption is first switched on. A manual backup you do yourself works any time you can still sign in.
⚠️ And if you are thinking of moving to a local account, that detaches you from the account holding the key. Back it up first.
What you can check on your own machine
Two commands exist and both have a catch worth knowing before you try them.
`manage-bde -status C:` in Command Prompt, or `Get-BitLockerVolume` in PowerShell. Either tells you whether the drive is encrypted and how far along it is.
Ours, and measured here on Windows 11 Home: both refused. `manage-bde` answered "An attempt to access a required resource was denied. Check that you have administrative rights on the computer", and the PowerShell version returned an access denied error.
⭐ So run either one from an administrator prompt, or use the Settings page instead: Privacy & security, Device encryption.
⚡ The tool ships on Home as well as Pro. It reported itself as version 10.0.26100 on a Home machine. Full BitLocker management is still a Pro feature by Microsoft's own comparison.
Status: gone over 23 August 2026 against Microsoft's BitLocker and Device Encryption pages. Microsoft documents the key ID, both account addresses, the four storage places, the manual backup from Manage BitLocker, and its own inability to retrieve a lost key. The local-account dead end and the June 2026 update case are dated Q&A reports, neither with a confirmed fix.
Where is my BitLocker recovery key?
Most often in the Microsoft account that was signed in when encryption was switched on. Go to aka.ms/myrecoverykey on another device. Match the first eight digits of the Key ID shown on the locked screen. For a work machine the address is aka.ms/aadrecoverykey, or ask whoever manages it.
Why is my PC asking for a BitLocker key when I never turned it on?
Because Device Encryption switches itself on when you set up a device with a Microsoft account. Microsoft documents that. Something then changed that BitLocker checks at boot. Usually a firmware update, a Secure Boot change, new hardware or a Windows update.
Can Microsoft recover my BitLocker key?
No. In Microsoft's own words, Microsoft Support does not have the ability to retrieve, provide or recreate a lost BitLocker recovery key. No copy in an account, on paper, on a USB stick or in a file means the data cannot be recovered.
Can I find the recovery key with a local account?
Not afterwards. An adviser on Microsoft's board states there is no way to find it on a local account, because it is not stored locally. Adding a Microsoft account later does not upload an existing key. There is still one move. While you can sign in, back it up yourself from Manage BitLocker.
The Short Version
- Write down the first eight digits of the Key ID from the screen before you do anything.
- aka.ms/myrecoverykey is where most personal keys are. Try every Microsoft account you have used.
- aka.ms/aadrecoverykey is the work and school version. On a company machine, ask them.
- It can also be on paper, on a USB stick, or in a text file somebody saved.
- Device Encryption switches itself on with a Microsoft account, and not with a local one.
- With no copy anywhere, the data is gone. Microsoft says it cannot recreate the key.
- Firmware updates, Secure Boot changes and new hardware are the usual triggers.
- If your PC still works, open Manage BitLocker and back the key up today, to your account and to paper.
Where to Next
If you are locked out right now, go to aka.ms/myrecoverykey on your phone. Take those eight digits with you. That is where the large majority are found.
If it happened to somebody else, open Manage BitLocker on your own machine and back the key up. Two minutes. It is the difference between an inconvenience and losing everything.
Before any firmware or BIOS update, suspend BitLocker first. That is the single change that prevents most of these prompts appearing at all.
And if you got past a recovery prompt some other way, tell me how below. Put it in the comments. That thread never reached a confirmed answer and better evidence would help the next person.

Isaac Smith is the founder and editor of PC Glance, a website that covers computers, laptops, and technology. He is a tech enthusiast and a computer geek who loves to share his insights and help his readers make smart choices when buying tech gadgets or laptops. He is always curious and updated about the latest tech trends.