Where Windows stores your BitLocker recovery key
Your BitLocker recovery key is a 48-digit number that unlocks your drive if you forget your password or can't use your normal login method. Windows stores it in one of three places: your Microsoft account, a USB drive you created during setup, or printed on paper. The location depends on how you set up BitLocker originally.
If you set up BitLocker through Windows settings on a personal computer, the key almost always went to your Microsoft account automatically. If your organization set it up, the key is likely stored on their servers. If you created a USB recovery key during setup, that's your backup — but only if you still have that specific USB drive.
Key Takeaways
- Your BitLocker recovery key is stored in your Microsoft account if you encrypted a personal Windows device, and you can view it by signing in at account.microsoft.com.
- If your organization manages your computer, contact your IT department or help desk — they control where recovery keys are stored.
- A USB recovery key only works if you have the exact USB drive you created during BitLocker setup; a different USB drive will not work.
- If you cannot find your recovery key anywhere, you will lose access to all files on that drive permanently — there is no other way to unlock it.
Retrieving your key from your Microsoft account
Go to account.microsoft.com and sign in with the Microsoft account you use on the locked computer. Once you are logged in, look for "Security" or "Device security" in the left menu, then select "BitLocker" or "Encryption." You should see a list of your devices. Find the device that is locked and click on it.
The recovery key will display as a 48-digit number, usually shown in groups of six digits separated by hyphens. Write this number down or take a screenshot — you will need all 48 digits to unlock your drive. Do not share this number with anyone; it is as sensitive as your password.
If you do not see BitLocker listed in your account settings, your key was not saved there. This usually means either BitLocker was set up by your organization, or you chose to save the key to a USB drive instead during setup.
Checking a USB recovery key
If you created a USB recovery key during BitLocker setup, that key is stored only on that specific USB drive. Plug the USB drive into the locked computer and restart. When the BitLocker recovery screen appears, select "Enter recovery key" and then "I have a recovery key on a USB drive." Windows will read the key from the USB automatically.
The USB drive must be the original one you created during setup. A different USB drive, even if it contains a file named "recovery key," will not work. BitLocker uses encryption that ties the key to that specific drive.
If you have lost the USB drive, you cannot use this method. Check your other storage locations first before assuming the USB is your only option.
Getting your key from your organization
If your computer is managed by a workplace, school, or other organization, your BitLocker recovery key is stored on their servers, not in your personal Microsoft account. Contact your IT department, help desk, or system administrator and explain that you need your BitLocker recovery key. They will verify your identity and provide it to you.
Response time varies by organization. Some can provide the key within minutes; others may take a few hours or require you to visit in person. Have your employee ID or student ID ready when you contact them.
Do not attempt to bypass BitLocker on an organization-managed device. The encryption is there to protect company or school data, and circumventing it may violate your agreement with that organization.
What to do if you cannot find your recovery key
If you have checked your Microsoft account, you do not have the USB drive, and your organization cannot locate the key, your drive is permanently inaccessible. BitLocker is designed so that even Microsoft cannot unlock your drive without the recovery key. There is no master password, no back door, and no way to recover your files.
At this point, your only option is to erase the drive and start over. On a personal computer, you can use Windows installation media to wipe the drive and reinstall Windows. This will delete all files on that drive. On an organization-managed device, contact your IT department to handle the wipe and reinstall.
Before you reach this point, write down your recovery key and store it somewhere safe — a locked drawer, a safe, or a password manager. Do not store it only on the encrypted drive itself.
Preventing this problem in the future
After you unlock your drive, take steps to make sure you can find your recovery key next time. Sign in to your Microsoft account and verify that your BitLocker recovery key is there. If it is not, you can manually save it by opening Settings, going to System, then About, and selecting "BitLocker settings." Look for an option to back up your recovery key to your Microsoft account.
You can also print your recovery key and store the printout in a safe place away from your computer. Some people keep a copy in a safe deposit box or with important documents. The goal is to have at least two ways to access the key: your Microsoft account and one physical backup.
If you use a password manager like Bitwarden, 1Password, or LastPass, you can store your recovery key there as well. This gives you a third backup location and keeps the key encrypted.
Frequently Asked Questions
Can I use someone else's recovery key to unlock my drive?
No. Each BitLocker recovery key is tied to a specific drive. A recovery key from a different computer will not unlock your drive, even if it is the same model. You must use the key that was created for your specific device.
What if I see a recovery key on my USB drive but I am not sure if it is the right one?
Try it. If it is the correct key for your drive, BitLocker will accept it and unlock. If it is not, BitLocker will reject it and ask for another key. There is no penalty for trying the wrong key.
Can I change my BitLocker recovery key to something easier to remember?
No. BitLocker recovery keys are always 48-digit random numbers generated by Windows. You cannot change them to a password or shorter code. You can only save the number you have in a safe place.
If I reset my Microsoft account password, will I still be able to see my BitLocker recovery key?
Yes. Your BitLocker recovery key is stored separately from your password. Resetting your Microsoft account password does not affect your ability to view the recovery key once you sign back in.
Does BitLocker recovery key expire?
No. Your recovery key does not expire and will work indefinitely. As long as you have the correct 48-digit number, you can use it to unlock your drive at any time in the future.