How to Find a Missing BitLocker Recovery Key on an Intune-Managed Windows Device
Question details
The user is unable to access an Intune-managed Windows device because the BitLocker recovery key is missing and cannot be easily bypassed.

- Product
- Windows / Microsoft Intune
- Device & OS
- Windows
- Scenario
- A Windows device managed by Microsoft Intune is locked by BitLocker, and the user needs to recover the key to access the data or format the drive.
- Observed behavior
- The device halts at the BitLocker recovery screen, prompting for a 48-digit key that the user does not currently have on hand.
Make note of the Recovery Key ID displayed on your locked BitLocker screen, as you will need this identifier to search for the correct matching key in your organization's directory.
Search for the Key in Microsoft Entra ID or Intune
Since the device is managed by Intune, the most likely location for the escrowed BitLocker recovery key is within your organization's admin portals.
Your organization's IT department should perform this check, as it requires administrative privileges to access Microsoft Entra ID or the Intune Admin Center.
Have an administrator log into the Microsoft Entra admin center or Microsoft Intune admin center using their organizational credentials.
Navigate to the 'Devices' section and search for the locked Windows device using its hostname, serial number, or the Recovery Key ID.
Select the device, open its properties or recovery keys section, and copy the 48-digit BitLocker recovery key that matches the ID on the locked screen.

Check Associated Microsoft Accounts
If the device was ever linked to a personal, school, or secondary work account, the recovery key might be stored in that specific Microsoft account.
Wipe the Drive and Reinstall Windows
If the recovery key is completely missing from all escrow locations and accounts, the encrypted data cannot be recovered. You must wipe the drive to use the device again.
Need an Office Suite After Reinstalling Windows?
If you had to wipe your Intune-managed device due to a permanently lost BitLocker key, you will need to reinstall your essential software. WPS Office is a lightweight, free alternative to Microsoft Office that helps you get back to work instantly.
- 1. Download the Installer: Visit the official WPS Office website and click the free download button.
- 2. Install WPS Office: Run the downloaded executable file and follow the on-screen prompts to install the suite on your fresh Windows system.
- 3. Open Your Files: Launch WPS Office to instantly open and edit any recovered documents, spreadsheets, or presentations.

Frequently Asked Questions
Can Microsoft Support recover my missing BitLocker key?
No. BitLocker is designed so that encrypted data cannot be accessed without the recovery key. Microsoft Support does not have backdoors and cannot generate or bypass a missing key for you.
Can I use third-party software to bypass the BitLocker screen?
You should avoid using third-party tools that claim to bypass BitLocker. These tools cannot decrypt the drive without the correct key and attempting to use them may permanently damage your encrypted data.
How do I know which BitLocker recovery key is the right one?
The BitLocker recovery screen on your locked device will display a Recovery Key ID. You must compare this ID with the records stored in Microsoft Entra ID, Intune, or your Microsoft account; the correct 48-digit key will share the exact same ID.
Will formatting my drive remove the BitLocker encryption?
Yes. Reinstalling Windows and deleting the existing drive partitions will completely remove the BitLocker encryption, allowing you to use the PC again. However, this process permanently erases all files currently on the drive.




