Data Recovery Case File · Trust, Practice & Honest Limits · The Key That Isn't in the Account
Encryption first, hardware second: why the key question outranks the drop — the two readings of a device listed without a recovery key, the four places keys actually live, and the honest wall where no legitimate key exists
His enquiry contained the right facts in nearly the right order, and this page's only contribution is to move one of them to the front. "My laptop has died after I accidentally dropped it, and the 104GB SSD is not seen when put onto a new laptop using a caddy. It's Windows 11 and has probably BitLocker encryption. I've logged into my Microsoft account and my old laptop is listed as a device, but there is no BitLocker key. There's data on the disk I would like to recover." The drop is dramatic; the caddy is frustrating; but the sentence that governs the entire outcome is the last one. Because if that drive is encrypted and no legitimate key exists anywhere, then no amount of successful imaging produces readable data — and any laboratory that suggests otherwise is misleading him. Equally, the absence of a key in his account has a genuinely hopeful reading, which most people never learn. This page sets out both, names the four places keys actually live, and only then turns to the hardware.
| Media | 104GB SSD from a dropped Windows 11 laptop — not detected when connected to another machine via a caddy; encryption status to be confirmed; no recovery key visible in the owner's Microsoft account |
| Reported situation | Laptop dead following an accidental drop · SSD invisible via caddy on a replacement machine · device listed in the Microsoft account without an associated recovery key · data recovery sought |
| Fault class | Two-stage case: encryption viability (legitimate key required) followed by SSD accessibility — module, interface or controller fault; no route exists without a lawful key if encryption is confirmed active |
| Equipment used | Key-status establishment first, at no cost · module assessed on native equipment; caddy bypassed · write-blocked imaging (Atola TaskForce 2, native NVMe/SATA paths as applicable) · Passware Kit Forensic decryption strictly with legitimately-held credentials · honest limits stated in writing where no key exists |
The decode: two readings, four places, and the wall
Why the key question comes first: encryption is not a layer that recovery works around — it is the layer that determines whether recovery means anything. A perfectly imaged encrypted drive without its key yields ciphertext: mathematically indistinguishable from noise, and honestly unrecoverable. This archive's fixed position, stated in every encryption case it publishes: legitimately-held keys only; strong encryption without a key is not a challenge to be defeated, it is a limit to be stated plainly. So establishing key status is step one — and it costs nothing, requires no bench, and can be done before he commits to anything.
The two readings of "no key against the device": the hopeful one first, because it is common. Windows lists devices in an account for many reasons, and a device appearing there does not imply its drive was ever encrypted. Device encryption is enabled by circumstance — hardware capability, sign-in type, edition, whether a user or organisation switched it on — and a great many ordinary consumer laptops run entirely unencrypted. An absent key may simply mean there was never anything to protect, in which case the drive's contents are readable the moment the hardware cooperates. The final reading is the other side: encryption was active, and the key was deposited somewhere other than that account — in which case the data is reachable only if the key is found. Which of the two applies is determined by examining the drive itself, and it is the first thing an assessment establishes.
The four places a key actually lives: worth hunting before concluding anything. A different account — keys attach to the account signed in when protection was enabled, so a personal account may hold the key for a device now listed under another, and vice versa. A printout or a saved file — Windows offers to print or save the key at setup, so it may be in a folder, on a USB stick, or in a drawer with the machine's paperwork. An organisation's directory — for work or study devices, the key is typically escrowed with the employer's or institution's IT, who can retrieve it on request. Another signed-in device — the account's recovery-keys page should be checked from a browser rather than a device summary, since the two views differ. Four checks, no cost, and the outcome of the case frequently turns on them.
The hardware, in its proper place: only then does the drop matter. Solid-state drives survive impacts far better than mechanical ones — there is nothing spinning to crash — so an SSD invisible in a caddy is often a fault of the connection rather than the device: a caddy that doesn't suit the module's type or protocol, a damaged connector, or a controller knocked into silence. Native assessment on proper equipment settles which; if the module answers, it is imaged write-blocked and completely, and the decryption question is then answered with whichever legitimate key the earlier hunt produced.
On the bench
The order was preserved: the key question first, at no cost — the drive's encryption status established directly from its own structures rather than inferred from an account page, and the four hiding places worked through with him in writing. With the position clear, the hardware was assessed on native equipment with the caddy removed from the chain, and the module's silence resolved into its actual cause. Where it answered, a complete write-blocked image was taken on the Atola TaskForce 2, and decryption was performed against the legitimately-held credential through Passware Kit Forensic — the only kind of key this bench ever turns. His data was verified by opening from the decrypted image and delivered; and had the hunt found nothing while encryption proved active, he would have received the same clarity in the opposite direction — in writing, free, with nothing sold.
The outcome
The encryption question settled before any spend, the module assessed natively, the drive imaged and decrypted with a lawful key, and the data verified and delivered. Free assessment, one fixed written figure including VAT, no recovery, no fee. The doctrine, posted for everyone holding an encrypted drive and an empty account page: establish key status before paying for anything, because without a legitimate key an imaged drive yields nothing readable and no honest lab will pretend otherwise; a device listed without a key may simply never have been encrypted, which is good news worth confirming; keys live in four places worth checking — another account, a printout or saved file, an organisation's IT escrow, or the account's recovery-keys page itself; and dropped SSDs usually survive the fall, so the invisibility is generally a connection or controller matter rather than a verdict.
Encrypted drive, and no recovery key where you expected it
Settle the key before you spend anything on the hardware — without a legitimate key, an encrypted drive images perfectly and reads as noise, and that limit is real regardless of who you ask. Check all four places: any other Microsoft account you've used (keys attach to the account signed in when protection was enabled), printouts or key files saved to a USB stick or folder, your employer's or university's IT if the machine was ever managed by them, and the account's dedicated recovery-keys page in a browser rather than the device list. Take heart from the hopeful reading too: many consumer laptops were never encrypted at all, and a device listed without a key often means there was nothing to protect. Meanwhile, don't keep trying caddies — SSDs generally survive drops, and repeated improvised connections risk the module. Get its encryption status and its health established together, then decide.
Key status first, at no cost — call Leeds Data Recovery on 0113 322 3083; native assessment, write-blocked imaging, decryption only with your lawful key, honest limits in writing — no recovery, no fee.
Request a quote online →
Our case files are drawn from genuine enquiries received by our laboratory over the past ten years, anonymised to protect client confidentiality. Each one describes the diagnostic and recovery procedure our engineers apply to that fault, using the equipment listed.