SPC Servis PC Brno

BitLocker Wants a Recovery Key: Where to Find It via aka.ms (Personal vs. Work Account)

The BitLocker blue screen doesn't mean a faulty drive. We'll show you where to look for the 48-digit key for a personal account, where for a work account, and what to do if you can't find it anywhere.

Ing. Miroslav Jaroš updated July 16, 2026 12 min read
BitLocker Wants a Recovery Key: Where to Find It via aka.ms (Personal vs. Work Account)

You left your computer to update overnight. In the morning, instead of the login screen, you’re met with a blue screen showing a key icon, the text “BitLocker recovery,” and a field for a 48-digit number. The drive isn’t necessarily faulty, and the system isn’t necessarily broken—Windows simply couldn’t verify that the computer is starting in the same state it was in when the encryption was turned on.

The problem is that at that moment, no one knows where that number is. And until it’s found, your data is behind an impenetrable wall.

The immediate answer: For a private computer, look up the key on another device via aka.ms/myrecoverykey and sign in with the personal Microsoft account that was used to set up the computer for the first time. For a work or school laptop, go to aka.ms/aadrecoverykey and sign in with your work account. Always match the Key ID from the blue screen with the ID of the key in your account—there are often several in the list. Before you change anything in the BIOS or clear the TPM, take a photo of the screen. No one—not even a repair service—can open a properly encrypted drive without a valid key.

What Actually Happened

When you turn on BitLocker encryption, it remembers how your computer starts: its UEFI settings, its firmware, its bootloader. The key to unlock the drive is then held by the TPM chip on the motherboard, and it is released only if this fingerprint matches. If the fingerprint changes, the TPM refuses to release the key, and BitLocker asks for the backup—the recovery key.

There are a few triggers for this, all of them innocent:

  • an intervention in the UEFI/BIOS (enabling or disabling Secure Boot, switching from UEFI to Legacy, changing the boot order),
  • a firmware or BIOS update, which a laptop often performs silently in the background,
  • clearing or resetting the TPM, typically during a computer “cleanup,”
  • replacing the motherboard or moving the drive to another machine,
  • removing the drive and connecting it to another Windows machine via a USB adapter.

So, the blue screen itself says nothing about the health of the drive. However, if it appeared after a series of freezes or strange noises, address the hardware first—that topic is covered in the article on data recovery from a drive with bad sectors. If you didn’t even know encryption was on, you’re not alone: newer Windows versions often encrypt silently on many devices, which we discuss in the article on BitLocker turning itself on.

The First Five Minutes: What to Do Before Changing Anything

Most needlessly lost data happens when someone panics and starts trying to “fix it somehow.”

  1. Take a photo of the entire screen. It contains the recovery key ID, which you’ll need for comparison. Write down at least the first eight characters.
  2. Find out who set up the computer for the first time. The key was saved to their account, not yours.
  3. Decide if the machine is private or connected to a corporate Microsoft 365. This leads down two different paths.
  4. Search using another phone or computer. The locked machine won’t help you with this.
  5. Don’t touch anything else for now. No more BIOS changes, no clearing the TPM, no reinstallation, no formatting. You won’t get the key this way and will only complicate the recovery.

The recovery Key ID is not the recovery key. It’s just a label to help you identify the right number in your account when you have more than one.

Personal or Work Account? This Is Where Most Confusion Arises

Microsoft maintains two separate account worlds: a personal Microsoft account (Outlook, Hotmail, Live, or even a Gmail address) and a work or school account in Microsoft Entra ID. The key is saved in one of them, and searching in the other is pointless.

How the Computer Was Set UpWhere to Find the KeyWhat to Sign In With
Private laptop, Microsoft accountaka.ms/myrecoverykeyPersonal Microsoft account
Signed in to an organization’s Microsoft 365aka.ms/aadrecoverykeyWork or school account
Managed via Microsoft IntuneWork account or IT adminOrganization account
Classic corporate domainNetwork administratorKey is often in Active Directory
BitLocker was turned on by someone elseThat person’s accountOriginal owner or technician
Key was saved manuallyPaper, USB, or a text fileNo account needed

An @gmail.com address can also be the login name for a personal Microsoft account—many people set up such an account years ago and forgot about it. Conversely, having a corporate domain in an email address doesn’t automatically mean it’s a Microsoft 365 work account. What matters is how the computer was set up, not what the email looks like.

Personal Computer: The Path via aka.ms/myrecoverykey

On another device, open https://aka.ms/myrecoverykey and sign in with the Microsoft account that was used to initially set up the laptop or turn on encryption.

A list of keys will appear—often for several devices and several drives. Don’t choose based on the computer’s name. Compare the recovery key ID from the blue screen with the ID of the item in the list. When you find a match, copy the 48-digit number; it’s divided into eight groups of six digits, and the hyphens usually don’t need to be typed.

If the account is empty, go through all the accounts that might have ever been on that computer:

  • the account of the business owner or freelancer who bought the machine,
  • the account of the employee who unpacked and set up the laptop,
  • an older account with an Outlook, Hotmail, or Live address,
  • an account set up with a different email address (even Gmail or Seznam),
  • the account of a family member or an external technician who prepared the device.

For a computer bought second-hand, the key is typically in the previous owner’s account. Without their cooperation, you cannot transfer it to yourself—Microsoft doesn’t reassign the key to a new owner.

Work Laptop: The Path via aka.ms/aadrecoverykey

If the machine was connected to Microsoft 365, Microsoft Entra ID, or Intune, open https://aka.ms/aadrecoverykey and sign in with your work account. In the device overview, select the locked computer, display the BitLocker keys, and again, compare their IDs with the one on the blue screen.

The “aad” abbreviation in the address is a remnant of the older name, Azure Active Directory. The service is now called Microsoft Entra ID, but the link has remained.

The key might not be visible to a regular employee, even if it exists in the organization—the company can disable self-service viewing. In that case, it’s up to the administrator to check:

  • Microsoft Entra ID,
  • Microsoft Intune,
  • on-premises Active Directory for a classic domain,
  • the account of the device’s original user,
  • a key registry maintained by internal or external IT.

Send the administrator a photo of the screen, the computer name, the serial number, and the Key ID. Do not send the 48-digit number itself to a group chat or save it to a shared document accessible to half the company. Whoever has the key and physical access to the drive can open it. In a company subject to the Cyber Law and NIS2, handling keys is often a direct part of internal policy.

Why the Account Shows a Different Key, or None at All

The most common cause is not a page error, but the wrong account. The key is tied to the account or organization where it was saved when BitLocker was turned on—it’s not found based on who currently logs into Windows.

Also, consider these possibilities:

  • BitLocker was turned on by another computer administrator,
  • the laptop originally belonged to another employee,
  • the device was previously managed by a different organization,
  • the key was printed or saved to a USB drive instead of the cloud,
  • after a reinstallation or re-enabling encryption, a new key was created, and the old one is no longer valid,
  • the device has multiple keys, but only one ID matches.

Search corporate storage, backup drives, and USB keychains for files named something like “BitLocker Recovery Key.” And be careful of one thing: enter your login credentials exclusively on genuine Microsoft domains. Links from internet forums promising a “key recovery tool” are a typical phishing attempt—the target is your account, not your drive.

What Won’t Help

The recovery key cannot be derived from the laptop’s serial number, the Windows license, a PIN, or the account password. It’s not a code that can be calculated. Neither a repair service nor Microsoft support can manufacture a lost key.

None of the following will work:

  • guessing the numbers,
  • removing the SSD and connecting it via a USB adapter—the drive will remain encrypted there, too,
  • taking ownership of files from another Windows installation,
  • CHKDSK,
  • a standard deleted file recovery program,
  • resetting the Microsoft account password,
  • a Windows reinstallation, if you want to keep your data.

The manage-bde and repair-bde tools in Windows are useful for diagnostics or for a damaged volume, but even they require a valid method of unlocking—a key, a password, or a functioning TPM. They are not tools for bypassing BitLocker, and they don’t claim to be.

The Reset this PC option will get the machine running with a clean installation, but it will not unlock the original data. Therefore, only confirm a reset or format when you are reconciled to losing your files, or you have a verified backup—ideally one that follows the 3-2-1 rule.

When It Makes Sense to Call a Service

Paid help makes sense in a few specific situations: you don’t know which account was used during setup; the computer has passed through several hands; the request returns even after entering a seemingly correct key; or you need to safely assess the drive’s health first before anyone touches it.

A technician can:

  • distinguish a personal account from an organization’s work account and find where the key belongs,
  • help locate the device using the Key ID,
  • determine if the request was triggered by a TPM, UEFI, or boot order change,
  • verify the condition of the SSD or HDD without unnecessary writes,
  • securely copy the data after unlocking,
  • diagnose a damaged BitLocker volume,
  • coordinate a procedure with a corporate Microsoft 365 administrator.

And they will also tell you where the boundary lies: without a recovery key or another valid means, a healthy, correctly encrypted drive cannot be read. If anyone promises upfront to “crack BitLocker” without the key, demand a precise technical explanation and payment conditions before handing anything over.

The price depends on whether it’s just an account lookup and a settings check, or also involves a faulty drive, data copying, or system repair. Basic diagnostics with us in Brno start at approximately 500 CZK, and we will give you both the result and an estimated price for further work in advance—we don’t proceed with anything without your consent. If the drive is also physically ailing, the case shifts into data recovery mode, where different rules and a different price level apply. For a company-owned device, clarify in advance who is authorized to order the service and who the data can be released to.

The Key Is Accepted, but Windows Still Won’t Start

The key being accepted means only one thing: the drive is unlocked. It says nothing about whether the boot files are intact, whether an update failed, or whether the SSD is malfunctioning.

And if BitLocker asks for the key on every boot, don’t solve it by permanently turning off encryption “for peace of mind.” On a work laptop, you could be violating a security policy, and on a private one, you’d be needlessly removing a layer of protection you’ll one day appreciate. First, back up, then have the drive’s health, BitLocker’s protection mechanisms, and the UEFI configuration checked—the cause is almost always one specific thing, not “Windows acting up.”

When it’s all over, store the recovery key somewhere outside the computer: in a Microsoft account, on a piece of paper in a drawer, in a password manager. A company should keep a record—which device and which current Key ID it belongs to, who has access to it, and whether a new key was created after a change in protection. It’s five minutes of work that will one day save a day of panic. The article on what BitLocker is summarizes how it works and when you actually want it.

  • #BitLocker
  • #recovery key
  • #šifrování disku
  • #Windows
  • #TPM
  • #Brno
Share:

Found this useful? More security and privacy write-ups at ithope.cz.

Call Contact