Your BitLocker recovery key is stored in your Microsoft account, on a USB drive you created during setup, or printed on paper — the location depends on how you turned on BitLocker
BitLocker is Windows's built-in encryption that locks your entire drive. If you forget your password or your computer won't recognize your fingerprint, Windows asks for a 48-character recovery key instead. That key is not stored on your encrypted drive — it lives somewhere else by design, so you can still get in even when the drive itself is inaccessible.
The three places BitLocker stores your recovery key are your Microsoft account online, a USB drive you saved during setup, or a printed page. Which one you have depends on what you chose when you first turned BitLocker on. If you set it up through Windows settings, it almost certainly went to your Microsoft account. If you used the BitLocker Drive Encryption tool (available on Windows Pro and Enterprise), you may have saved it to a USB drive or printed it instead.
Key Takeaways
- Your recovery key is stored in your Microsoft account if you turned on BitLocker through Windows Settings on a home or Pro machine.
- You can view your key by signing into account.microsoft.com, going to Device, and selecting the locked computer's name.
- If you set up BitLocker through the Drive Encryption tool, check for a USB drive or printed page you created at that time.
- You need the recovery key only if you cannot unlock your drive with your normal password or biometric login.
- If you cannot find your key anywhere, you will need to reinstall Windows, which erases the drive.
Checking your Microsoft account for the recovery key
If you turned on BitLocker through Windows Settings (the normal way for most people), your recovery key was automatically sent to your Microsoft account. To find it, sign into account.microsoft.com on any device with internet access — it does not have to be the locked computer.
Once you are signed in, look for a section called "Devices" or "Your devices" in the left menu. Click it, then find the name of the computer that is locked. Click on that computer's name, and you should see a "BitLocker recovery key" option. Click it to view your 48-character key. Write it down or take a screenshot before you leave the page.
If you do not see a BitLocker recovery key option, it means BitLocker was not set up through your Microsoft account. In that case, move to the next section to check for a USB drive or printed key.
Looking for a USB drive or printed recovery key
When you turn on BitLocker through the Drive Encryption tool (BitLocker Drive Encryption, available on Windows Pro and Enterprise editions), you are required to save your recovery key somewhere other than the drive itself. Most people choose to save it to a USB drive or print it on paper.
Check any USB drives you have, especially ones you used around the time you set up BitLocker. The file is usually named something like "BitLocker Recovery Key" and contains a text file with your 48-character key. If you printed your key, look through papers near your computer or in a filing system where you keep important documents.
The printed key looks like a standard page with the recovery key displayed prominently, usually with your computer's name and the date it was created. If you have the physical page, you can use that key when ready to unlock your drive.
Entering your recovery key to unlock your drive
When your computer asks for the recovery key, you will see a screen that says "Enter the recovery key" and shows a space for a 48-character code. The key is formatted as eight groups of six characters separated by hyphens, like this: XXXXXX-XXXXXX-XXXXXX-XXXXXX-XXXXXX-XXXXXX-XXXXXX-XXXXXX.
Type or paste your recovery key exactly as it appears, including the hyphens. Do not add spaces or change the order. Once you enter it correctly, your drive will unlock and you can log in normally. After that, you should change your password or set up a new login method so you do not lose access again.
What to do if you cannot find your recovery key anywhere
If your recovery key is not in your Microsoft account, not on a USB drive, and you did not print it, you have no way to unlock the drive without erasing it. BitLocker is designed this way on purpose — the encryption is strong enough that there is no backdoor, even for Microsoft.
Your only option is to reinstall Windows. You will need another computer to create a Windows installation USB drive, then boot from that drive on the locked computer and choose to reinstall Windows. This erases everything on the drive, so you will lose all your files. After reinstalling, you can restore files from a backup if you have one.
To avoid this situation in the future, write down your recovery key and store it somewhere safe — a password manager, a printed page in a safe place, or a cloud storage account separate from your Microsoft account. Do this as soon as BitLocker is turned on.
Why BitLocker asks for a recovery key instead of your password
BitLocker may ask for a recovery key instead of your password for several reasons. The most common is that you have entered your password wrong too many times, and Windows has temporarily locked you out. Another reason is that Windows detected a change to your hardware — a new graphics card, a different USB device, or a BIOS update — and is asking for the recovery key as a security check.
Sometimes BitLocker asks for the recovery key if your computer cannot read your fingerprint or face recognition data correctly. In all these cases, the recovery key is a way to prove you own the computer without relying on a password or biometric that might not be working.
Turning off BitLocker if you do not want encryption
If you want to remove BitLocker encryption entirely, you can turn it off through Windows Settings. Go to Settings, then System, then About, and look for "Device encryption" or "BitLocker." Click "Manage BitLocker" and choose "Turn off BitLocker." Your drive will decrypt, which can take a while depending on how much data is on it. You do not need your recovery key to turn BitLocker off — you just need to be logged in as an administrator.
Turning off BitLocker is useful if you are selling your computer, giving it away, or if the encryption is causing problems with software you need to use. Once it is off, your drive is no longer encrypted and you will not need a recovery key.
Frequently Asked Questions
Can I use my password instead of the recovery key?
No. When BitLocker asks for a recovery key, it will not accept your password. The recovery key is required at that moment. However, once you unlock the drive with the recovery key, you can log in with your password as usual.
What if I have multiple computers with BitLocker?
Each computer has its own recovery key. When you sign into account.microsoft.com, you will see a list of all your devices. Click on the specific computer that is locked to find its recovery key. Do not use one computer's key on another computer.
Is my recovery key the same as my password?
No. Your recovery key is a separate 48-character code that BitLocker generates when you turn on encryption. Your password is what you use to log into Windows normally. You need the recovery key only when BitLocker specifically asks for it.
Can I change my recovery key?
Yes, but only if you can currently unlock your drive. Go to Settings, then System, then About, find "Device encryption" or "BitLocker," and choose "Manage BitLocker." Select "Rotate recovery key" to generate a new one. The new key will be saved to your Microsoft account automatically.
What happens if someone else finds my recovery key?
They can unlock your drive and access all your files. Treat your recovery key like a password — keep it private and store it securely. Do not email it to yourself, post it online, or leave it where others can see it.