## TL;DR
In the Entra admin center go to Devices > the device > Recovery keys, or have the user find it themselves at myaccount.microsoft.com > Devices. Read the 48-digit key carefully; one wrong digit fails. Verify the key ID on the recovery screen matches the key you are reading.

## The error
```text
Enter the recovery key to get going again. Key ID: XXXXXXXX-XXXX-XXXX-XXXX-XXXXXXXXXXXX
```

## Steps
1. Match the Key ID shown on the blue recovery screen with the keys listed for the device. Expected: match found. A device can have multiple keys; the Key ID disambiguates.
2. Admin path: Entra admin center > Identity > Devices > search the device > Recovery keys. Expected: the 48-digit key displayed. Read it in groups, carefully.
3. Self-service path: the user signs in at myaccount.microsoft.com > Devices > the device > View BitLocker keys. Expected: key visible. Use this when the admin is unavailable.
4. Enter the key on the recovery screen. Expected: Windows boots. If it rejects the key, recheck the Key ID match; wrong-key attempts are the usual failure.
5. After boot, investigate why recovery triggered (hardware change, Secure Boot change, TPM issue) so it does not recur. Expected: cause noted.

## When to use
- User stuck at BitLocker recovery screen
- PIN forgotten or TPM issues

## When not to use
- FileVault recovery (macOS, different system)
- Key not escrowed anywhere (data is unrecoverable; be honest)

## Compatibility
- BitLocker on Windows 10/11; keys escrowed to Entra ID via Intune or GPO

## Variants
### Multiple keys listed
Match by Key ID exactly; trying them in random order wastes time.
### No key in Entra
Check AD (if hybrid) or the MBAM database; if nowhere, the data cannot be recovered.

## Why it happens
BitLocker enters recovery when it detects boot changes. The recovery key is the only way back in, which is why escrow at encryption time is non-negotiable.

## Edge cases
- Read the key over the phone in chunks and have the user read it back.
- After recovery, suspend and resume BitLocker protection to reseal to the new boot state.

## Provenance

Resolved from the public thread: https://vectle.com/posts/pst_YqST_qzLClEc2Q71u4uCqA
