{{page_title}}

BitLocker Recovery Process

Windows 11 / Microsoft Intune / Microsoft Entra ID

Documentation Status: Current as of August 2026

This document defines the standard BitLocker recovery process for organization-managed Windows devices. The procedure covers end-user self-recovery, Help Desk recovery, Microsoft Intune recovery-key retrieval, Microsoft Entra ID recovery-key retrieval, key validation, recovery-key rotation, and post-recovery activities.

The process is designed for Windows devices managed through Microsoft Intune and Microsoft Entra ID, while also identifying the appropriate recovery path for Microsoft Entra hybrid joined and traditional Active Directory joined devices.

1. Title & Scope

Title: BitLocker Recovery Process — Windows Devices

Scope: This procedure applies to organization-managed Windows devices protected by Microsoft BitLocker and covers the process used when a device enters BitLocker Recovery Mode and requires a recovery key to regain access.

Target:

  • Service Desk and Help Desk technicians
  • Endpoint Management administrators
  • Microsoft Intune administrators
  • Microsoft Entra ID administrators
  • Systems administrators
  • Security administrators
  • End users performing approved self-service recovery
Important: A BitLocker recovery key is sensitive authentication information. It can unlock an encrypted drive and should only be retrieved, displayed, transmitted, and used by authorized personnel. Recovery-key access is audited in Microsoft Entra ID.

2. Purpose

  • Provide a standardized process for recovering BitLocker-protected Windows devices.
  • Identify the correct recovery-key source for the affected device.
  • Provide Help Desk personnel with a controlled recovery procedure.
  • Reduce unnecessary device reimaging or data loss.
  • Validate the recovery key before providing it to the user.
  • Document the reason for BitLocker recovery.
  • Rotate the BitLocker recovery key when required by security policy.
  • Ensure the device returns to a normal protected state after recovery.

3. Prerequisites

  • The affected Windows device must be identified by device name, serial number, or other approved identifier.
  • The requesting user must be verified according to organizational identity-verification procedures.
  • The technician must have the appropriate Microsoft Intune or Microsoft Entra permissions.
  • The device must have a BitLocker recovery key escrowed in an approved recovery location.
  • The technician must have access to Microsoft Intune and/or Microsoft Entra ID as appropriate.
  • The recovery event should be documented in the organization's ticketing system.

Microsoft recommends storing BitLocker recovery information in Microsoft Entra ID or Active Directory Domain Services rather than relying on printed or locally saved recovery information.

4. Understanding BitLocker Recovery

BitLocker Recovery Mode occurs when Windows cannot automatically unlock a protected drive using the normal authentication mechanism. A recovery event can be triggered by changes to the trusted boot environment, firmware, TPM state, boot configuration, or other conditions that cause BitLocker to require additional verification.

The recovery screen requests a 48-digit BitLocker recovery password. The technician must retrieve the recovery key corresponding to the affected device and provide the key through the organization's approved support process.

Security Warning: Never guess a BitLocker recovery key. Do not provide a recovery key based solely on a device name. Always validate the device identity and match the BitLocker Key ID displayed on the recovery screen with the Key ID stored in Microsoft Intune or Microsoft Entra ID.

5. Recovery Process

Step 1 — Identify the BitLocker Recovery Screen

When BitLocker Recovery Mode is displayed, record the information presented on the screen. The most important identifier is the Recovery Key ID.

The Recovery Key ID is used to match the recovery request to the correct BitLocker recovery key stored by the organization.

BitLocker Recovery

Enter the recovery key to get going again.

Recovery Key ID:
XXXXXXXX-XXXX-XXXX-XXXX-XXXXXXXXXXXX

Recovery Key:
48-digit recovery password

Do not attempt to retrieve a key until the device and Recovery Key ID have been properly identified.

Step 2 — Verify the User and Device

Before retrieving or disclosing a recovery key, verify the identity of the requesting user according to the organization's Help Desk security procedure.

Collect the following information:

  • User's name
  • User's organizational account
  • Computer name
  • Device serial number when available
  • Recovery Key ID displayed on the BitLocker screen
  • Reason the device entered recovery mode
  • Date and time of the recovery request

Step 3 — Determine the Device Join Type

Determine whether the affected device is Microsoft Entra joined, Microsoft Entra hybrid joined, or traditional Active Directory joined.

For Microsoft Entra joined and Microsoft Entra hybrid joined devices, recovery information can be retrieved from Microsoft Entra ID when the key has been properly escrowed. Traditional domain-joined devices may use Active Directory Domain Services for recovery information.

Step 4 — Retrieve the Recovery Key from Microsoft Intune

For Intune-managed devices, the preferred administrative recovery workflow is through the Microsoft Intune admin center.

Navigate to:

Microsoft Intune admin center
    |
    +-- Devices
        |
        +-- All devices
            |
            +-- Select the affected Windows device
                |
                +-- Monitor
                    |
                    +-- Recovery keys

Select Recovery keys and review the available BitLocker recovery information.

Microsoft's current Intune workflow displays the BitLocker Key ID, recovery key, and drive type when recovery information is available in Microsoft Entra ID.

Step 5 — Match the BitLocker Key ID

Compare the Recovery Key ID displayed on the user's Windows recovery screen with the BitLocker Key ID displayed in Intune.

The identifiers must correspond to the same recovery key before the key is provided to the user.

Recovery Screen Key ID
        |
        | Match
        v
Intune / Entra BitLocker Key ID
        |
        | Confirm
        v
Retrieve 48-digit Recovery Password
Validation Requirement: Only provide the recovery password after the device identity and BitLocker Key ID have been successfully matched.

Step 6 — Retrieve the Recovery Key from Microsoft Entra ID

If the recovery key must be retrieved directly from Microsoft Entra ID, navigate to the device record in the Microsoft Entra admin center.

Microsoft Entra admin center
    |
    +-- Devices
        |
        +-- All devices
            |
            +-- Select Windows device
                |
                +-- Show Recovery Key

Select Show Recovery Key and identify the key that matches the Recovery Key ID displayed on the BitLocker recovery screen.

Microsoft Entra ID records an audit event when a BitLocker recovery key is accessed. The activity is recorded under the KeyManagement category.

Step 7 — Provide the Recovery Key

Provide the verified 48-digit recovery password to the user through the organization's approved support channel.

The user enters the recovery password into the BitLocker recovery screen.

The recovery password is a 48-digit numeric value and should be entered exactly as provided.

Step 8 — Confirm Windows Starts Successfully

After the correct recovery password is entered, Windows should unlock the protected volume and continue the normal boot process.

Allow Windows to fully start before performing additional troubleshooting or configuration changes.

Step 9 — Determine Why Recovery Was Triggered

A successful recovery does not necessarily mean the underlying issue has been resolved. Determine why BitLocker entered recovery mode.

Investigate recent changes such as:

  • BIOS or UEFI firmware updates
  • TPM changes or TPM clearing
  • Secure Boot configuration changes
  • Boot configuration changes
  • Operating system changes
  • Hardware replacement
  • Motherboard replacement
  • Changes to security configuration
  • Unexpected system or firmware changes

The BitLocker recovery process should include identifying the root cause whenever possible so repeated recovery events can be prevented.

Step 10 — Synchronize the Device with Intune

After Windows successfully starts, initiate an Intune synchronization to ensure that the device communicates successfully with the management service.

Windows
    |
    +-- Settings
        |
        +-- Accounts
            |
            +-- Access work or school
                |
                +-- Organizational Account
                    |
                    +-- Info
                        |
                        +-- Sync

Alternatively, initiate the synchronization from the Intune admin center using the device's available remote actions.

Step 11 — Review BitLocker Encryption Status

Verify that BitLocker remains enabled and that the operating system volume remains protected.

The Intune encryption report can be used to review encryption status across managed Windows devices.

On the Windows device, administrators can also verify the local BitLocker status using PowerShell.

Get-BitLockerVolume

Review the output for the operating system volume and confirm that the expected protection and encryption status are present.

Step 12 — Rotate the Recovery Key When Required

Organizations should rotate a BitLocker recovery key when the existing recovery credential has been exposed, disclosed outside the approved process, or when required by organizational security policy.

Intune supports remote BitLocker recovery-key rotation for supported Windows devices. The device must meet the applicable key-rotation prerequisites and have recovery information configured for Microsoft Entra ID.

Navigate to:

Microsoft Intune admin center
    |
    +-- Devices
        |
        +-- All devices
            |
            +-- Select device
                |
                +-- BitLocker key rotation

If the BitLocker key rotation action is available, initiate the action according to the organization's change-control requirements.

Step 13 — Verify the New Recovery Key

After key rotation completes, verify that the new recovery key has been successfully escrowed and is available in Microsoft Entra ID and/or Intune.

Do not close the recovery ticket until the new key has been confirmed when rotation was part of the recovery procedure.

Step 14 — Document the Recovery Event

Update the service ticket with the recovery details. Do not store the complete BitLocker recovery password in an ordinary ticket comment unless the organization's approved security policy specifically permits it.

Document:

  • Device name
  • Device serial number
  • User
  • Recovery Key ID
  • Date and time of recovery
  • Reason for recovery
  • Technician who performed the recovery
  • Recovery source used
  • Whether key rotation was performed
  • Root cause or suspected cause
  • Final device status

6. End-User Self-Service Recovery

Organizations may permit users to retrieve recovery information through approved self-service methods. Microsoft documents self-service recovery through Microsoft Entra ID and the Intune Company Portal experience for supported organizational devices.

Company Portal Recovery

For supported Intune-enrolled devices, users can sign in to the Company Portal website, open Devices, select the affected Windows device, select Get recovery key, and then select Show recovery key.

The displayed recovery key can then be entered into the BitLocker recovery screen. Microsoft currently notes that the displayed key is hidden after five minutes of inactivity for security purposes.

Security Consideration: Self-service recovery should only be enabled when it aligns with the organization's security model. If Help Desk verification is required before releasing recovery information, users should be directed to the approved support process instead.

7. Recovery Key Access Permissions

Access to BitLocker recovery keys should be restricted to authorized administrators and support personnel.

Microsoft Entra roles that can provide access to BitLocker recovery keys include Cloud Device Administrator, Helpdesk Administrator, Intune Administrator, Security Administrator, and Security Reader, subject to the applicable permissions and organizational configuration.

The underlying Microsoft Entra permission for reading BitLocker recovery keys is microsoft.directory/bitlockerKeys/key/read.

8. PowerShell Verification

Check BitLocker Status

Get-BitLockerVolume

Check Operating System Drive

Get-BitLockerVolume -MountPoint "C:"

Review Recovery Protectors

(Get-BitLockerVolume -MountPoint "C:").KeyProtector

Use these commands for local verification only. They should not be used to bypass organizational recovery controls or expose recovery information unnecessarily.

9. Troubleshooting

Issue: No BitLocker Recovery Key Found

  • Confirm the correct device was selected.
  • Confirm the device is Microsoft Entra joined, hybrid joined, or otherwise associated with the expected recovery system.
  • Verify that the recovery key was escrowed.
  • Check whether the device has multiple recovery keys.
  • Match the Recovery Key ID against available keys.
  • Check the device's Intune encryption status.
  • Review BitLocker policy configuration.

Intune displays that no BitLocker key was found when recovery-key information is not available in Microsoft Entra ID.

Issue: Key Does Not Match the Recovery Screen

Do not provide the key. Recheck the device name, serial number, Recovery Key ID, and available BitLocker keys. A device may have more than one recovery key.

Issue: Device Is Not Appearing in Intune

  • Confirm the device is enrolled.
  • Confirm the device has recently synchronized.
  • Confirm the correct tenant is being used.
  • Check Microsoft Entra device registration.
  • Review Intune enrollment and device-management status.

Issue: BitLocker Recovery Happens Repeatedly

Investigate TPM, Secure Boot, firmware, BIOS/UEFI, boot configuration, and hardware changes. Repeated recovery events should be escalated to Endpoint Administration rather than repeatedly supplying recovery keys without identifying the cause.

Issue: Recovery Key Rotation Fails

Verify that the device meets the supported Windows requirements, the recovery-key backup configuration is enabled, and the required Intune RBAC permissions are available. Microsoft documents recovery-key rotation prerequisites for Microsoft Entra joined and hybrid joined devices.

10. Validation & Troubleshooting

  • Verify the user's identity.
  • Verify the affected Windows device.
  • Record the BitLocker Recovery Key ID.
  • Locate the matching recovery key.
  • Confirm the recovery key source.
  • Provide the verified key through the approved process.
  • Confirm successful Windows startup.
  • Investigate the recovery trigger.
  • Synchronize the device with Intune.
  • Verify BitLocker protection remains enabled.
  • Rotate the recovery key when required.
  • Verify the new key is escrowed after rotation.
  • Document the recovery event.
Tip: Always match the Recovery Key ID before providing a recovery password. This is the most important validation step in the Help Desk recovery process.

11. Escalation Path

  1. Level 1 — Help Desk: Verify the user's identity, device information, Recovery Key ID, and retrieve the approved recovery key.
  2. Level 2 — Endpoint Administration: Investigate Intune enrollment, BitLocker policy, encryption status, recovery-key escrow, synchronization, and repeated recovery events.
  3. Level 3 — Identity Administration: Investigate Microsoft Entra device registration, permissions, device ownership, audit events, and recovery-key access.
  4. Level 4 — Security: Investigate suspected unauthorized recovery-key access, exposed recovery credentials, or other security incidents involving BitLocker recovery information.
  5. Level 5 — Microsoft Support: Escalate persistent platform or service issues after collecting device information, timestamps, error messages, policy configuration, logs, and troubleshooting results.

12. Recovery Completion Checklist

  • User identity verified.
  • Device identity verified.
  • BitLocker Recovery Key ID recorded.
  • Recovery key located.
  • Recovery Key ID matched.
  • Recovery key provided through approved procedure.
  • Windows successfully unlocked.
  • Root cause investigated.
  • BitLocker protection verified.
  • Intune synchronization completed.
  • Recovery key rotated when required.
  • New recovery key escrow verified when rotated.
  • Service ticket updated.
  • Recovery event closed or escalated.
Recovery Completion Criteria: The recovery process is complete when the authorized user has regained access to the Windows device, BitLocker protection remains enabled, the recovery event has been investigated, required key rotation has been completed, and the recovery activity has been documented according to organizational security requirements.

13. Security Best Practices

  • Never send recovery keys through unapproved communication channels.
  • Never store recovery keys in ordinary ticket notes unless explicitly approved.
  • Always verify the Recovery Key ID before providing a key.
  • Limit recovery-key access using role-based permissions.
  • Review Microsoft Entra audit logs for recovery-key access.
  • Rotate recovery keys when organizational policy requires it.
  • Investigate repeated BitLocker recovery events.
  • Maintain reliable recovery-key escrow before enabling BitLocker encryption at scale.
  • Use Microsoft Entra ID or Active Directory as the organization's approved recovery-key repository.
  • Do not rely on locally stored or printed recovery keys as the primary enterprise recovery mechanism.

14. Final Validation

The technician should confirm that the Windows device is operational, BitLocker remains enabled, the device is communicating with Microsoft Intune, and the recovery event has been properly documented.

For organization-managed devices, the preferred recovery architecture is centralized recovery-key escrow with controlled administrative access and auditing. Microsoft documents Microsoft Entra ID and Active Directory Domain Services as supported locations for enterprise recovery information.

Final Status: BitLocker recovery successfully completed and the Windows device returned to a managed and protected operational state.