bitlocker recovery key: where to find it in entra id
Finds a BitLocker recovery key in Microsoft Entra ID for a locked device. Covers admin lookup, self-service, and verification. Use when a user is stuck at the BitLocker recovery screen. Not for FileVault (separate).
TL;DR
In the Entra admin center go to Devices > the device > Recovery keys, or have the user find it themselves at myaccount.microsoft.com > Devices. Read the 48-digit key carefully; one wrong digit fails. Verify the key ID on the recovery screen matches the key you are reading.
The error
Enter the recovery key to get going again. Key ID: XXXXXXXX-XXXX-XXXX-XXXX-XXXXXXXXXXXXSteps
- Match the Key ID shown on the blue recovery screen with the keys listed for the device. Expected: match found. A device can have multiple keys; the Key ID disambiguates.
- Admin path: Entra admin center > Identity > Devices > search the device > Recovery keys. Expected: the 48-digit key displayed. Read it in groups, carefully.
- Self-service path: the user signs in at myaccount.microsoft.com > Devices > the device > View BitLocker keys. Expected: key visible. Use this when the admin is unavailable.
- Enter the key on the recovery screen. Expected: Windows boots. If it rejects the key, recheck the Key ID match; wrong-key attempts are the usual failure.
- After boot, investigate why recovery triggered (hardware change, Secure Boot change, TPM issue) so it does not recur. Expected: cause noted.
When to use
- User stuck at BitLocker recovery screen
- PIN forgotten or TPM issues
When not to use
- FileVault recovery (macOS, different system)
- Key not escrowed anywhere (data is unrecoverable; be honest)
Compatibility
- BitLocker on Windows 10/11; keys escrowed to Entra ID via Intune or GPO
Variants
Multiple keys listed
Match by Key ID exactly; trying them in random order wastes time.
No key in Entra
Check AD (if hybrid) or the MBAM database; if nowhere, the data cannot be recovered.
Why it happens
BitLocker enters recovery when it detects boot changes. The recovery key is the only way back in, which is why escrow at encryption time is non-negotiable.
Edge cases
- Read the key over the phone in chunks and have the user read it back.
- After recovery, suspend and resume BitLocker protection to reseal to the new boot state.
Provenance
Resolved from the public thread: https://vectle.com/posts/pstYqSTqzLClEc2Q71u4uCqA
Maintainer review
No maintainer verification is recorded for this version.
This records the version a maintainer checked. It does not assert that the version is the latest upstream release.