A blue screen asking for 48 digits is not a fault and it is usually not a job for a laboratory. In most cases the key was filed automatically the day the drive was encrypted and can be back on your screen inside two minutes. This page finds it first. What comes after is for the smaller group whose drive is failing as well.
Finding your key costs nothing, and nobody here charges for telling you where to look. Decryption on a drive where you can supply the key is £400 + VAT, in writing after the free diagnostic. Without a key there is nothing to sell you.
A BitLocker recovery key is 48 digits, printed in eight blocks of six. Windows will not switch encryption on without offering to store a copy somewhere, so the useful question is not whether a key exists but which of these took the copy on the day the drive was locked.
Go to account.microsoft.com/devices/recoverykey on a phone or any other computer and sign in. Every key tied to that account is listed against the device it belongs to. If the laptop was set up by signing in rather than with a local account, this is where Windows quietly put it. Work through every address you have ever used, including the one from two jobs ago.
Company machines normally escrow to Microsoft Entra ID, which most people still call Azure AD. Sign in at myaccount.microsoft.com, open Devices, and the key sits behind the entry for that laptop. Plenty of tenants hide it from staff, in which case the service desk can read it out in under a minute. Ring them before you ring anybody else.
Estates running their own Active Directory escrow the key against the computer object, and a domain administrator reads it from the BitLocker Recovery tab in Active Directory Users and Computers. Nobody outside that domain can see it, which is precisely the point of escrow rather than a shortcoming of it.
Setup offers to print the key or save it to a USB stick, and more people took that offer than remember taking it. Look in the folder where the laptop paperwork lives, in the box the machine arrived in, and on every unlabelled stick in the drawer. The saved file is plain text and opens with the words BitLocker Drive Encryption recovery key.
Where a second drive is locked but Windows itself starts normally, open a command prompt as administrator and run manage-bde with the protectors switch against the locked drive letter. The numerical password it prints is the key. This only works while something on that machine can still read the volume, so do it before anything else changes.
Some volumes were encrypted by hand with the save-a-copy step clicked past, and some machines have been rebuilt since. If no account, no domain, no printout and no stick holds a copy, the key does not exist. No laboratory can work one out, and any firm that says otherwise is selling you something it cannot deliver.
The recovery screen shows an identifier as well as a box to type into. That identifier is how you tell one stored key from another when several devices sit under the same account, and it is the first thing to check once a list of keys is on screen. Match the opening characters of the identifier on the laptop to the identifier printed beside the key in the list. A key that belongs to a different machine will be rejected, so a mismatch is worth spotting before you type forty-eight digits with a queue of people waiting.
If nothing in the list matches, the key belongs somewhere you have not looked yet. On a home machine that is usually a second Microsoft account, often an old address used when the laptop was first switched on. On a work machine it is almost always the company tenant rather than a personal account, and the answer is a phone call to IT.
Nothing is corrupt. BitLocker hands its key to the TPM chip and asks the TPM to release it only when the machine boots in the same state it was sealed against. The TPM measures firmware, the boot configuration and the components that load early. Change any of those and the measurement no longer matches, the TPM refuses to hand the key back, and Windows falls through to the recovery prompt. That is the design working, not failing.
The changes that trigger it are mundane. A UEFI or BIOS update, which is the single most common cause. Secure Boot switched on or off, or the boot order edited. The TPM cleared during a repair. Memory, a graphics card or a docking station added or removed. A feature update that stopped partway. A drive lifted out of one machine and plugged into another, which is a guaranteed prompt because the sealing machine is gone. If you know a firmware update is coming, suspend BitLocker first from the Windows settings page or from manage-bde, install it, and let protection resume afterwards. That one step prevents most of these.
Once you are back into Windows, spend five minutes closing this off properly. Open the BitLocker settings page for the drive and choose to back up the recovery key again. Take two copies to different places: one into a Microsoft account, so it can be reached from a phone in a hotel room, and one printed and filed with the rest of the household paperwork. A copy on the encrypted drive itself is no copy at all, and neither is one in a password manager whose vault lives on the same machine.
It is also worth knowing which of your drives are encrypted before something asks. On a home machine, look at Device encryption in the Windows settings, and on anything with the Pro edition installed, at BitLocker Drive Encryption in the control panel. From an administrator command prompt, manage-bde with the status switch lists every volume and its protection state in one go. People are far more relaxed about a blue screen at seven in the morning when they already know the key is in a drawer downstairs.
A fair number of callers are certain they never enabled anything. On most laptops sold in the last few years, that is true and beside the point. Windows 11 turns Device Encryption on automatically once someone signs in with a Microsoft account during setup, and the key goes to that account without a dialogue box. Nobody chose it. It is still BitLocker, the recovery key still exists, and it is still sitting in the account used on day one.
This is the narrow case worth posting. The key is available, but the drive it belongs to is clicking, dropping off the bus halfway through a copy, or taking thirty seconds to return a sector. Encryption does not make that situation hopeless, though it does change the order of work. The disk is imaged first, sector by sector, on hardware built for drives that argue back, with the weak regions left until last so the healthy majority is safely captured. Only then is the key applied, to the copy, never to the original.
Two details help more than people expect. BitLocker keeps three copies of its own metadata on the volume, so one unreadable header does not end the job. And the encryption is applied in a way that keeps each sector self-contained, so a handful of unreadable sectors costs those sectors rather than the whole volume. What it does mean is that a partial image cannot be browsed until it has been decrypted. There is no picking a few urgent files out early and stopping; the copy has to reach a state where the key can be applied to it.
Decrypting a BitLocker volume where you supply a valid key is £400 + VAT. The free diagnostic comes first and closes two working days after the drive reaches the bench, never sooner, and the figure that follows it is fixed and in writing before any work starts. Where the drive is healthy and the job is purely logical, no fix, no fee applies. The full rule reads: No fix, no fee all jobs except electronic and mechanical failures, chip level work, DVR and Forensic jobs. A drive that has failed mechanically or electronically takes 50% of the quoted figure upfront before the invasive stage begins. Firmware work sits inside the guarantee; board repair does not.
If the key cannot be produced and no escrow copy exists, the volume stays encrypted. Not slowly, not expensively, not with enough computing time. The recovery password carries far too much randomness to guess at, and there is no maintenance hatch built into it for laboratories or for anybody else. That is the same answer at every bench in the country, and it is the reason the encryption was worth switching on. Being told that plainly on a Tuesday afternoon is cheaper than paying somebody to discover it slowly.
Work laptops make up a large share of these calls, which is unsurprising in a town where the offices along the A329M and the commuter platforms to Waterloo do most of the heavy lifting. If the laptop belongs to an employer, the key is the employer property and their IT team can nearly always produce it from Entra or from the domain. Ask them first. It is faster than anything a laboratory can do and it does not cost anybody £400 + VAT. Where you own the machine outright and the drive is failing as well, the bench is 40 minutes down the A322 and the A3, or one tracked parcel away.
Two minutes in a Microsoft account settles most of these. If the drive underneath is failing as well, that is when the bench earns its money.
Post is how almost every job here starts. A tracked, insured parcel is far gentler on a struggling drive than a car boot and a day of errands, and something handed to Royal Mail in Bracknell today is normally booked in at the Guildford bench tomorrow.
If the storage is still bolted into a laptop, a tower, an iMac, a server or a CCTV box, unbolt it. The bare drive is what the bench needs, and no machines are dismantled at this end. Any repair shop will pull one out in a few minutes if you would rather not. The exception, and it is a hard one, is storage soldered directly to the logic board — Apple Silicon Macs, a few very thin Windows laptops, most tablets. If it does not come out, there is nothing that can be posted.
↓ Print the shipping & booking-in form (PDF)
Write Guildford Data Recovery on the label. Driving it down from Bracknell is roughly 40 minutes on the A322 and the A3; posting it costs you an envelope and a day. Either way you get a call once it is booked in, and the free diagnostic closes two working days later.
Not sure what should go in the box? Ring 0800 689 0668 before you seal it, or work through the free online diagnostic and let it ask the questions.