BitLocker cannot be recover

Masa LEE 1 Reputation point
2022-08-22T03:21:22.72+00:00

Hi there,

We got a laptop under our domain and had retrieved the BitLocker recover key several times (on Microsoft BitLocker Administration and Monitoring console)

Yesterday, a Windows update from 1909 to 20H2 has performed on the laptop, it was normal after the update.

However, it ask for BitLocker recover key after a normal restart, and the recovery key could not be retrieved from Microsoft BitLocker Administration and Monitoring console.

We have ensure the User Domain, User ID and Key ID weren't wrongly input but it still showing "User is not valid for this drive" . Can you please advise on the situation? Thank you.

233353-image.png

Windows for business | Windows Client for IT Pros | Devices and deployment | Configure application groups
0 comments No comments
{count} votes

4 answers

Sort by: Most helpful
  1. Dillon Silzer 57,831 Reputation points Volunteer Moderator
    2022-08-22T03:46:36.19+00:00

    Hi @Masa LEE

    If you or the client do not have the keys it is best to reset Windows.

    Download the Windows 10 ISO from https://www.microsoft.com/en-ca/software-download/windows10 and reinstall Windows (or push a new image if you have remote software such as SCCM or AutoPilot).

    -----------------------------------

    If this is helpful please accept answer.


  2. rizky dwi saputra 1 Reputation point
    2022-08-22T04:15:00.433+00:00

    same problem to my friend. the case is he never login to microsoft account in the device (laptop), then in the account it's not have device, then how he get the key id?. finally he asked to asus center and they said it have to reinstall the software (windows) and paid RP. 250.000 ($16.81)

    0 comments No comments

  3. Limitless Technology 39,926 Reputation points
    2022-08-22T14:42:46.883+00:00

    Hello there,

    MBAM uses a unique volume ID as the identifier for each disk volume to store BitLocker recovery keys. However, if imaging procedures are performed incorrectly, the volume IDs may not be unique in some cases. When this problem occurs, BitLocker recovery keys for some disk volumes are missing in the MBAM recovery database.

    You cannot retrieve the BitLocker recovery key for disk recovery in BitLocker Administration and Monitoring https://support.microsoft.com/en-us/topic/you-cannot-retrieve-the-bitlocker-recovery-key-for-disk-recovery-in-bitlocker-administration-and-monitoring-f8e1628b-a11e-b595-2118-ecece4b178d4

    I hope this information helps.

    ----------------------------------------------------------------------------------------------------------------------------

    --If the reply is helpful, please Upvote and Accept it as an answer--

    0 comments No comments

  4. Carl Fan 6,881 Reputation points
    2022-08-23T05:34:26.937+00:00

    Hi MasaLEE-9140,

    According to your description, if the account is part of the AdvHelpDeskUser group. if we could only provide Key ID and reason code fields to check.

    That means, if we have logged in with system admin account, then we do not have to supply user domain and user ID.

    If you have logged in with normal helpdesk account, you have to supply all-User domain, User ID, Key ID, Reason for Drive Unlock.

    Did the user logged in to the machine? if No, you may will receive the error "user is not valid for this drive". We could try to log in the problematic machine locally than check.

    Meanwhile, The recovery key gets stored in the table "RecoveryandHardwareCore.keys" inside the Recovery and Hardware database.

    We could check the SQL server to get the bitlocker recovery key.

    https://www.ronnipedersen.com/2016/01/04/how-to-access-the-mbam-bitlocker-recover-keys-directly-in-sql/

    Of course, if we have backup the recovery key to DC, we could find the recovery key from DC.

    https://www.top-password.com/blog/find-bitlocker-recovery-key-from-active-directory/

    Best Regards,

    Carl

    0 comments No comments

Your answer

Answers can be marked as Accepted Answers by the question author, which helps users to know the answer solved the author's problem.