How to Find Your BitLocker Recovery Key
BitLocker is Windows’ built-in drive encryption, and it’s on by default on many modern PCs. When something changes — a hardware swap, a firmware update, a failed boot — BitLocker can demand a 48-digit recovery key before it’ll unlock the drive. If you don’t have it handy, here’s exactly where to look.
Where your BitLocker recovery key lives
Windows saves the key somewhere when BitLocker is first turned on. Check these, in order:
1. Your Microsoft account (most common). If you sign into Windows with a Microsoft account, the key is almost certainly saved online. Go to account.microsoft.com/devices/recoverykey (or aka.ms/myrecoverykey) and sign in — you’ll see the key, matched by its Key ID (the screen shows the first characters of the ID so you can match it to the one your PC is asking for). Check any Microsoft account you might have used.
2. A work or school account. On a managed/work device, the key is often stored in your organization’s Microsoft Entra ID (Azure AD) or by your IT department. Sign in at myaccount.microsoft.com → Devices, or ask your IT admin — they can retrieve it.
3. A saved file or printout. When BitLocker was enabled, you may have chosen to save the key to a file (a .txt named “BitLocker Recovery Key …”) or print it. Search your other computers, USB drives, and cloud storage (OneDrive, Google Drive) for that filename.
4. A USB flash drive. The key may have been saved directly to a USB stick — plug in any you have from around that time.
5. Active Directory (older business setups). On some corporate networks the key is escrowed in AD; your admin can pull it.
Match it by Key ID
Your PC’s BitLocker screen shows a Recovery Key ID. Wherever you find keys, match that ID — a Microsoft account can hold keys for several devices, so grabbing the wrong one won’t work.
If you truly can’t find it
Be honest with yourself about every Microsoft and work account you’ve used, and every place a file might be. If the key was never backed up anywhere and you don’t have it, the encrypted data is generally not recoverable — that’s by design; strong encryption without the key can’t be brute-forced in any practical timeframe. This is exactly why BitLocker asks you to save it.
Why this matters for data recovery
Here’s the part people miss: even a perfect physical recovery of a failed BitLocker drive yields only scrambled data without the key. If your encrypted drive dies and you send it to a lab, the recovery still depends on you supplying the recovery key (or password). So before anything else, find and safeguard that key — it’s as important as the drive itself.
The same is true across platforms: FileVault on Mac and device passcodes on phones all mean encryption + no key = no readable data, no matter how good the recovery.
The bottom line
Check your Microsoft account first (aka.ms/myrecoverykey), then any work account, saved files, and USB drives — matching by Key ID. And if you’re ever facing a failed encrypted drive, locate the key up front: it’s the difference between a successful recovery and a folder full of gibberish.
Dealing with a failed encrypted drive? Start a recovery with your key in hand, and you pay nothing unless we get your data back. Our guide to how data recovery works explains the rest.
