Call us — 0113 322 3083
Mon–Fri · 9am–5:30pm · No fix, no fee
Start a free diagnostic →
Service · BitLocker

BitLocker: locked out of your own drive.

A blue screen wanting your 48-digit key which you’ve never seen, to protect a hard drive containing all of your belongings. BitLocker recovery is actually a dual discipline, in the way you locate keys individuals did not realise existed, as well as recover failing drives through the encryption that exists there. The bench does both, but with the honest limits disclosed from the beginning.

two decades’ experience
In-house, never outsourced
Only pay if we recover your data, on most jobs
// the key hunt

Your key exists in more places than you think.

Almost all BitLocker lockouts are caused by one thing: the recovery key was saved somewhere but can’t be found. This list provides the best solution for a majority of people when their laptops are locked out: your Microsoft account (account.microsoft.com → Devices → recovery keys), which is what comes on new Windows computers as a default setting, and this is the easiest method for home users who never enabled BitLocker; work/school accounts, where your IT department has an Azure AD or Active Directory to store the recovery key; a printed or file copy from setup (searching ‘BitLocker recovery key’ in email and cloud drives often finds lost versions); and the USB stick method used by older versions. Bring every account identity you may have used to the diagnostic; matching key IDs to the drive is part of the service.

// failing and locked

Encryption on top of a dying drive.

Then there is the compound case. This is the type of failure we see most, when a drive fails and it also has BitLocker locked onto it. Bad sectors in encrypted space, a laptop that crashes into recovery key hell because the hardware underneath the laptop is sick. The order of operations is everything for these types of failures. Firstly the drives are stabilised and imaged while still encrypted, so the remaining life of the faulty hardware does not get spent trying to unlock the disk. Then decryption runs against the healthy image using your key. TPM wrinkles (board swaps or firmware changes that left the auto-unlock without a home) resolve the same way. And now we have the hard limit: no key from any source means no decryption by design. If someone promises otherwise, they are selling something. Our encryption and decryption page lists all of the different hardware that we handle, including BitLocker drives and hardware-encrypted WD, Seagate, LaCie and Transcend drives.

// questions

Asked often, answered straight.

Probably in an account through Microsoft. Most modern laptops will turn on “device encryption” automatically during the first sign-in, and store the key to this process in a secured area (escrow) on Microsoft’s servers. For every identity you have ever used to log onto the machine, go to account.microsoft.com > Devices. This single step will likely resolve most of the “I didn’t even turn it on” lockout issues.

The failure comes first, every time. Each boot cycle eats into what is left of the drive’s life span, and each attempt at unlocking the system is an expensive read operation. The bench images the disk gently while it is still encrypted; then the stable image is decrypted using your key. It’s common here for devices to be locked plus failing, but so long as there is still a valid key for the encrypted device, we can usually get back into the data.

No, and no one reputable can. Properly implemented BitLocker, without the key, the password or TPM cooperation, is designed to be unbreakable. Forensic tools like Passware Kit Forensic, which we run, don’t “crack” the encryption; instead they help locate the key when it physically exists, including reading it from an escrow such as a Microsoft account, Entra ID or Active Directory. The forensic tools search for the key on the drive itself, including its hibernation file, and in a memory capture if one was taken while the machine was still running. We don’t work on the TPM chip in the computer, as we only take the drive on its own and don’t accept complete laptops or computers. If we cannot recover the key through these means, then regardless of how many hours or years you spend trying to decrypt it, the volume remains unreadable, and that’s what it was intended to do. What we can do, after exhausting all escrow locations (and yes, keys are found there regularly), is to prepare the data for viewing once a key becomes available. We’ll have already recovered the drive, so it’s just a matter of waiting for a key to turn up.

0113 322 3083