Firmware or motherboard changes can cause an encrypted Windows 11 PC to request its BitLocker recovery key because the measured boot state changed. Microsoft says Device Encryption may have saved the key to a Microsoft, work or school account, while manually enabled BitLocker can have a different storage choice. The safe time to learn where the 48-digit key is stored is before hardware service, when the PC still signs in normally.
Before you start
Back up important files separately; encryption is not backup. Identify the Windows device name and whether the recovery key belongs to your personal account or an organization. Keep key records private and accessible even if this PC will not boot. For business hardware, follow IT's servicing and key-escrow process. Record the current firmware version and repair plan.Do it step by step
- Open Settings > Privacy & security > Device encryption or the BitLocker management panel available on your edition. Confirm which volumes are encrypted and whether protection is active.
- Find the key in the account or storage method that originally enabled encryption. Match its Key ID to the device and verify you can access it from another trusted device.
- Make a separate file backup and test opening sample files. Do not put the only recovery-key copy on the encrypted drive that may become inaccessible.
- Ask the manufacturer or IT whether the planned firmware procedure requires temporarily suspending BitLocker protection. Follow only their supported, time-limited steps.
- Carry out the firmware or hardware work with stable power and documented recovery information. Do not clear the TPM as a casual troubleshooting step.
- After service, boot Windows, check encryption protection is active, and confirm the recovery key or escrow record remains correct. If a prompt appears, compare Key ID before entering the private key.