Skip to content
HOW BISCUITPractical guides

Explore How Biscuit

Search How Biscuit

Enter a word or phrase to search.

How to Check Whether BitLocker Is On and Back Up the Recovery Key

BitLocker can request its recovery key after security, firmware, TPM, startup, or hardware changes. Back up the key before the computer is the only device capable of reaching it.

What to know

  • BitLocker can request its recovery key after security, firmware, TPM, startup, or hardware changes. Back up the key before the computer is the only device capable of reaching it.
  • Check both **Device encryption** and **Manage BitLocker**. Back up the matching 48-digit recovery key before hardware, firmware, recovery, or repair work.

Check both Windows’ Device encryption page and the traditional BitLocker Drive Encryption control panel.

When encryption is enabled, back up the recovery key in at least two independent locations before updating BIOS or UEFI firmware, changing TPM or Secure Boot settings, replacing a motherboard, resetting Windows, restoring an image, or sending the computer for repair.

The BitLocker recovery password is a unique 48-digit code that may be required when Windows detects a security or hardware change it cannot automatically authorize.

Check Device Encryption

Open:

Settings → Privacy & security → Device encryption

When the page exists, it should show whether device encryption is on.

Device Encryption can automatically protect the operating-system drive and certain fixed drives on supported hardware. Availability depends on the computer, Windows edition, security hardware, and configuration.

A missing Device Encryption page does not prove that no drive uses BitLocker. Check the full control panel too.

Check BitLocker Drive Encryption

Search Windows for:

Manage BitLocker

or open:

Control Panel → System and Security → BitLocker Drive Encryption

Review every listed drive.

Possible states include:

  • BitLocker on
  • BitLocker off
  • Encryption in progress
  • Decryption in progress
  • Protection suspended
  • Waiting for activation

External drives can use BitLocker To Go separately from the internal system drive.

Back up the recovery key

Under the protected drive, select:

Back up your recovery key

Available destinations can include:

  • Microsoft account
  • USB drive
  • File
  • Printed copy
  • Microsoft Entra ID or Active Directory for a managed device

Save the recovery information somewhere other than the encrypted drive it protects.

A text file saved only in the encrypted Documents folder is not an independent recovery copy. It is the digital equivalent of locking the spare key inside the safe.

Check the Microsoft account

Use Microsoft’s official recovery-key page while signed into the account connected to the PC.

Compare:

  • Device name
  • Key ID
  • Recovery-key date
  • 48-digit password

An account can contain several keys from old computers, reinstalls, or security changes.

Record which key belongs to the current device. Do not delete older keys until the corresponding devices and drives are verified as retired or decrypted.

Store the key securely

Suitable arrangements include:

  • Microsoft account plus a printed copy in a secure location
  • Password-manager secure note plus an offline copy
  • Encrypted emergency vault plus a physical copy
  • Organization directory plus an authorized IT procedure

Do not place the full key in ordinary email, public cloud notes, unencrypted chat, a repair ticket, a photo album, or a label attached to the laptop.

Record the key ID in the equipment inventory so the correct password can be located without broadly exposing it.

Before firmware or hardware changes

  1. Confirm Windows is activated.
  2. Back up files.
  3. Verify the BitLocker recovery key.
  4. Save it outside the PC.
  5. Record the model and serial number.
  6. Preserve TPM and firmware settings.
  7. Follow the manufacturer’s procedure.
  8. Suspend BitLocker only when the documented process requires it.
  9. Resume protection afterward.
  10. Confirm the drive remains encrypted.

Do not permanently decrypt the computer merely because one firmware update requires temporary protection suspension.

When Windows asks for the key

The recovery screen displays a key ID.

Use that ID to select the matching recovery password from the Microsoft account, printed record, USB file, or organization administrator.

Microsoft cannot recreate a missing recovery key that was never backed up to an accessible location. When no valid key exists, resetting the device may be the only route, and that removes the encrypted data.

Do not repeatedly change firmware settings while guessing why recovery appeared. Preserve the key ID and determine what changed.

Work or school computers

Contact IT. The key may be stored in Microsoft Entra ID, Active Directory, device management, or an internal asset system.

Do not copy an organization’s recovery key into an unauthorized personal account.

Bottom line

Check both Device encryption and Manage BitLocker. Back up the matching 48-digit recovery key before hardware, firmware, recovery, or repair work.

Encryption protects files from unauthorized access. It remains admirably committed to that mission when the authorized owner loses the only key.

Sources reviewed

Limits and cautions

  • Not hands-on tested
Sources reviewed

Source notes

  1. https://support.microsoft.com/en-us/windows/back-up-your-bitlocker-recovery-key-e63607b4-77e7-48d8-8e1e-6924a1c84b70support.microsoft.com
  2. https://support.microsoft.com/en-us/windows/find-your-bitlocker-recovery-key-in-windows-6b71ad27-0b89-ea08-f143-056f5ab347d6support.microsoft.com
  3. https://support.microsoft.com/en-us/windows/device-encryption-in-windows-cf7e2b6f-3e70-4882-9532-18633605c7dfsupport.microsoft.com