What is BitLocker?
BitLocker is the drive encryption built into Windows. On most modern PCs device encryption turns itself on once you sign in with a Microsoft account, and the 48-digit recovery key is saved to that account. With the key the data is readable; without it the data is out of reach, which is why the key is worth finding and saving today.

BitLocker is the encryption built into Windows that protects entire drives. Microsoft describes it as a Windows security feature that provides encryption for entire volumes, addressing data theft or exposure from lost, stolen, or inappropriately decommissioned devices. The protection is aimed at offline access: someone who pulls the drive out of a PC and connects it elsewhere cannot read any of its content. On most modern Windows PCs, some form of this is already running, usually without a deliberate choice on your part. That makes the recovery key the one part of BitLocker worth understanding before anything goes wrong.[1][2]
Device encryption: the version you did not choose
Windows ships two related features. BitLocker drive encryption is the full version, turned on deliberately. Device encryption is the consumer version, and the difference matters for anyone who never switched anything on: Microsoft's Learn documentation says device encryption is enabled automatically so that the device is always protected, and the consumer support page describes it as designed for simplicity of use and usually enabled automatically. Since Windows 11, version 24H2, more hardware qualifies, because Microsoft removed the DMA and HSTI/Modern Standby prerequisites that used to hold devices back.[2][1]
There is a condition buried in that automation. Automatic device encryption starts during initial setup, but Microsoft's OEM documentation states that protection is armed only after the user signs in with a Microsoft account or an Azure Active Directory account, and that until then protection is suspended and data is not protected. It is not enabled with local accounts at all. So a PC signed in with a local account may be running Windows with no encryption protecting it, while the one signed in with a Microsoft account has a recovery key stored somewhere most people have never looked.[3]
The recovery key
A BitLocker recovery key exists for one purpose: unlocking the volume when normal unlock fails. Microsoft documents it in two forms, a 48-digit recovery password and a recovery key file with a .bek name format that can be stored on removable media. When device encryption activated through a personal Microsoft account, the key was saved automatically to that account; Microsoft's support page says your BitLocker recovery key is automatically saved to your Microsoft account or work or school account. Across all cases, Microsoft's documented storage options are the Microsoft account, the default recommended method for devices not joined to a work or school directory, Microsoft Entra ID or Active Directory for managed devices, a plain text file, or a printout.[4][2]
Find and save your recovery key today
- On a device that still boots normally, sign in to your Microsoft account in a browser and open its recovery key section (search for "Microsoft recovery key" to reach it). If device encryption activated under your account, the 48-digit key for each device is listed there.
- Check your work or school account too if the PC is managed by an employer or school. Managed devices usually hold the key in the organization's directory, not in a personal account.
- Search your documents and printed papers for a text file or printout containing the words "BitLocker Recovery Key". Microsoft documents saving the key to a text file and printing it as storage options, so an old copy may already exist.
- Save a second copy somewhere the PC cannot take down with it: a printout in a drawer, a text file on a different drive, or the .bek key file copied to a USB stick.
- Do this while Windows still starts normally. Once the PC is asking for the key at startup, the only sources left are the copies saved beforehand.
Why BitLocker sometimes asks for the key
The recovery prompt is routine, not necessarily a sign that anything hostile happened. Microsoft lists common events that push a device into BitLocker recovery mode, and several are ordinary: entering the wrong PIN too many times, exceeding the maximum number of failed sign-in attempts, a firmware upgrade to critical early startup components such as BIOS or UEFI, and moving a BitLocker-protected drive into a new computer. Microsoft presents these as examples rather than a complete list. The practical reading: a PC that suddenly demands a 48-digit key at startup usually still holds all of its data, and the key in your Microsoft account unlocks it.[4]
What this means for data recovery
Encryption changes the recovery question from "is the data intact" to "who holds the key". Microsoft states that having access to the recovery password allows the holder to unlock a BitLocker-protected volume and access all of its data. With the key, a laptop that no longer boots is an ordinary recovery job: the data comes off the drive and opens normally. Without the key, the data is not merely difficult to reach, it is cryptographically out of reach, because properly implemented encryption has no shortcut around it. That is why any recovery service will ask for the 48-digit key before starting work on a Windows machine that will not turn on.[4]
BitLocker To Go and external drives
Encrypted removable and external drives are their own case, which Microsoft sells as BitLocker To Go. Microsoft documents that a recovery key can be used to gain access to fixed and removable drives encrypted with BitLocker, and automatic device encryption does not cover external or USB drives, because device encryption encrypts only the OS drive and fixed data drives. An encrypted external drive is therefore a choice someone made at some point, and the key for it is whatever was saved when it was encrypted, not necessarily the key tied to the PC.[4]
Macs and BitLocker
BitLocker is a Windows feature, and a Mac cannot read or write a BitLocker-encrypted drive on its own. Connect an encrypted Windows drive to a macOS machine and it appears as an unreadable volume until third-party software is added. The dependable path to the data is a Windows PC plus the key, which is one more reason the recovery key belongs somewhere you can reach it from any machine.[1]
Related reading
Not sure what state your drive is in? Use guided help
Sources
Facts on this page are cited to the publishers’ own documentation.
- [1] Microsoft — BitLocker Overview | Microsoft Learn. captured 2026-09-13.
- [2] Microsoft — BitLocker overview (consumer support article). captured 2026-09-13.
- [3] Microsoft — BitLocker drive encryption in Windows 11 for OEMs | Microsoft Learn. captured 2026-09-13.
- [4] Microsoft — BitLocker recovery overview. captured 2026-09-12.