BitLocker Dive Encryption Recovery Key Identifier Location & Identifier validity?

Pepper Rout 21 Reputation points
2025-12-16T17:38:01.5933333+00:00

Have a questions concerning where to look for the identifier associated with a BitLocker Recovery key and the actual accuracy of the KEY ID itself.

This is the info that appears when looking up the recovery key:

"To verify that this is the correct recovery key, compare the start of the following identifier with the identifier value displayed on your PC.

Identifier:

C1A8R900-aaaa-bbbb-cccc-xxxxxxxxxxxx

If the above identifier matches the one displayed by your PC, then use the following key to unlock your drive."

The above identifier is an example of the real sequence of characters presented when looking up the Recovery Key by logging into your account at https://aka.ms/myrecoverykey.

My question is: Where is this identifier value located? I've looked in Settings - System - About, and see 2 items:

Device ID - which has the same grouping sequence as above - but Device ID character string first 8 characters does not match the Recovery Key identifier.

Product ID - not even close

If the Recovery Key 'identifier value' is the Product ID in settings - why doesn't Microsoft say so in the supporting Recovery Key documentation? If the Product ID is not the correct ID, what is? Where do you look it up?

MOST IMPORTANT: If the Product ID found via Settings - System - About (that first group of 8 characters) does NOT match the KEY ID listed for the PC via the MS account BitLocker Recovery Keys what do you do fix this problem??

Thanks - any thoughts and suggestions are appreciated.

Windows for home | Windows 11 | Security and privacy
0 comments No comments
{count} votes

2 answers

Sort by: Most helpful
  1. DaveM121 816K Reputation points Independent Advisor
    2025-12-16T18:11:52.45+00:00

    The Bitlocker ID is not found in the Settings App, to find the Bitlocker ID for a drive to match it with the Bitlocker Recovery Key on your account, open Command Prompt, then run this command (replace X with the drive letter).

    manage-bde -protectors -get X:


  2. Pepper Rout 21 Reputation points
    2025-12-17T18:19:07.85+00:00

    Hi DaveM121,

    Reading your last post: "I honestly do no know why that information is not available on their support website, but usually, if your PC asks for a Bitlocker Recovery Key, in the same notification, the associated Bitlocker ID would be provided to the user."

    This highlights a real issue. Yes, agree that the BitLocker ID is listed when BitLocker goes into recovery mode upon restart or boot and the Key input screen is shown by the PC.

    But the issue here is that upon original BitLocker activation and the Key is generated along with the ID, you need to check what the PC has stored internally to verify that the Key and the Key ID match what BitLocker generated and is stored in your account.

    You need to perform the look up you suggested in the prior post to confirm that both sets of information match. If they do you are good to go. If these don't, something is wrong and you should turn BitLocker drive encryption off until the mismatch is resolved.

    How is a BitLocker key deleted from your account if there is a mismatch? How do you replace it? This should be handled by the support website also and if it is I can't find it.

    A verification check step should be included on the support web site when going through BitLocker Key generation description.

    Thank you for posting the PC side of things check.

    0 comments No comments

Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.