## TL;DR
Get the 48-digit recovery key from Intune or Entra ID, unlock the drive once, then disable and re-enable the BitLocker protectors so the key reseals to the new boot measurements. That reseal is the actual fix; without it the recovery screen returns on every boot. Then check whether a firmware update or a Secure Boot change triggered it.

## The error
```text
Enter the recovery key to get going again
```
The blue BitLocker recovery screen, appearing on every boot after a Windows or firmware update.

## Steps
1. Find the key: Intune admin center / Devices / the device / Recovery keys, or Entra ID / Devices / the device / BitLocker keys. Expected: a 48-digit recovery key for the OS drive.
2. Enter the key at the recovery screen and let Windows boot. Expected: the machine reaches the desktop.
3. Open an elevated command prompt and run `manage-bde -protectors -disable C:` followed by `manage-bde -protectors -enable C:`. Expected: protection resumes, and the next reboot does not ask for the key. This reseals the key to the new boot measurements.
4. Check what changed: firmware or UEFI updates and Secure Boot setting flips are the classic triggers. Confirm Secure Boot is on and matches your fleet baseline. Expected: settings match the standard.
5. If the loop returns, update the BIOS or UEFI to the vendor's latest version, reseal again, and watch for a pattern if several machines hit it from the same update. Expected: one fix, no recurrence.

## Use this when
- The BitLocker recovery screen appears on every boot after a Windows update
- The recovery screen appears after a firmware or BIOS update
- A user is stuck in a recovery-key loop and the key works but the prompt keeps returning

## Not for this skill when
- Nobody has the recovery key and it was never escrowed (the drive is unrecoverable; reimage is the only path)
- The drive was encrypted by a third-party tool rather than BitLocker
- BitLocker prompts once after a legitimate hardware change and then stops (expected behavior, not a loop)

## Compatibility
- Windows 10 and Windows 11 with BitLocker and a TPM
- Intune or Entra ID key escrow for the key-lookup steps

## Variants
### Recovery loop after a docking-station firmware update
Same reseal fix applies. Dock firmware can change the measured boot path, so reseal after any dock update that triggers the screen.
### TPM was cleared in BIOS
Clearing the TPM destroys the sealed key. Unlock with the recovery key, then fully re-enable protectors and confirm the new key escrows to Entra ID.

## Why it happens
BitLocker seals its key to measurements of the boot chain taken by the TPM. An update that changes boot components changes those measurements, so the TPM refuses to unseal and Windows demands the recovery key. Disabling and re-enabling protectors records the new measurements, which is why the prompt stops.

## Edge cases
- Users who keep rebooting and guessing at the key can trip lockout counters; fetch the escrowed key before they try anything.
- If the key is not escrowed anywhere and nobody recorded it, stop troubleshooting and reimage. No tool recovers a BitLocker drive without the key.
- A fleet-wide spike after one update means the update changed something structural; pause the update ring and reseal the affected machines.

## Provenance

Resolved from the public thread: https://vectle.com/posts/pst_kwqniRmawYh5Ip4k_ONdGw
