Bit-Locker Recovery Key retrieval

Cronce Andrew 0 Reputation points
2026-04-09T18:23:20.29+00:00

I need help retrieving the bit-locker recovery key for one of our employees that is locked out of their computer.

The device is not listed in my list of devices, but it should be. I am only seeing devices that were added as far back as May of last year (2025), but the device would have been added in December of 2024.

Windows for business | Windows Client for IT Pros | Devices and deployment | Recovery key
0 comments No comments

1 answer

Sort by: Most helpful
  1. Domic Vo 29,960 Reputation points Independent Advisor
    2026-04-09T23:11:34.4633333+00:00

    Hello,

    BitLocker recovery keys are stored depending on how the device was provisioned. If the machine was joined to Microsoft Entra ID (Azure AD) or to an on‑premises Active Directory domain, the recovery key is automatically escrowed to the directory service. In Entra ID, you can retrieve it from the Microsoft 365 Admin Center or the Entra portal under Devices > BitLocker keys. In AD DS, the key is stored in the computer object attributes and can be queried with the Active Directory Users and Computers console or PowerShell.

    The fact that you only see devices added as far back as May 2025, while the locked device was supposedly added in December 2024, suggests that either the device was never properly joined to your tenant/domain, or the BitLocker key escrow failed. This can happen if the machine was set up with a local account or a personal Microsoft account instead of the organizational account, or if Group Policy/Intune policies for BitLocker key escrow were not applied at the time.

    To proceed, verify whether the device is actually joined to your domain or Entra tenant. From another administrative session, you can check the computer object in AD or Entra ID. If the device object is missing, the recovery key will not be available in your admin portal. In that case, the only way to retrieve the key is from the original account that enabled BitLocker on the device. If it was a personal Microsoft account, the key would be stored at https://account.microsoft.com/devices. If it was organizational but the key escrow failed, unfortunately there is no supported method to bypass BitLocker without the recovery key.

    In summary, if the device does not appear in your tenant or AD object list, the recovery key was never escrowed there. You will need to confirm whether the employee used a personal Microsoft account or organizational account when enabling BitLocker. If it was organizational but the key is missing, you should escalate to Microsoft Support to confirm whether the escrow failed. Without the recovery key, access cannot be restored.

    I hope you've found something useful here. If it helps you get more insight into the issue, it's appreciated to accept the answer. Should you have more questions, feel free to leave a message. Have a nice day!

    Domic Vo.

    Was this answer helpful?

    0 comments No comments

Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.