What the BitLocker recovery key is, why Windows asks for it, where to find it and how to check protection with manage-bde.
A BitLocker recovery key is a 48-digit numerical password that unlocks a drive encrypted with BitLocker or device encryption when Windows cannot unlock it automatically, for example after firmware, TPM or hardware changes. Without the key, the data on the encrypted drive cannot be recovered.
In the Microsoft account used on the PC (account.microsoft.com/devices/recoverykey), in a work or school account (Microsoft Entra ID), printed or saved to a file or USB drive when BitLocker was turned on, or with the organisation's IT department.
The recovery screen shows a Key ID; the matching key has the same ID.
BitLocker asks for the key when it detects a change that could mean an attack: BIOS/UEFI updates or settings, Secure Boot changes, TPM resets, moving the drive to another PC, or some boot configuration changes.
'manage-bde -status' shows each drive's encryption and protection status. 'manage-bde -protectors -get C:' lists the protectors, including the numerical password (recovery key) ID.
manage-bde -protectors -get C:Note: Rain Cleaner's Protection page includes a disk and BitLocker check.
Last updated: 2026-10-08
What WinRE is, how to open it, what tools it offers, and how to check it with reagentc /info.
What SmartScreen is, why it shows 'Windows protected your PC' for new downloads, and how to check a file before running it.
What the Windows.old folder is, why it appears after an upgrade, how long Windows keeps it and how to remove it safely.