Call us — 01865 593000
Mon–Fri · 9am–5:30pm · No fix, no fee
Start a free diagnostic →
/ home / services / bitlocker
Specialist recovery · BitLocker

BitLocker recovery, and where the key actually lives.

A blue screen asking for 48 digits is BitLocker doing its job, not a failure. Understanding why it triggered tells you how quickly you will be back in — and where the drive itself has failed as well, the order of operations matters more than most people realise.

From £800 + VAT
Ownership checked first
Failing drives too
~ bitlocker_2026-014 — live RECOVERED
$ bdr triage /dev/sdb
 Device: Dell XPS SSD · 512 GB
 Status: BITLOCKER LOCKED — volume refuses to mount
 Owner: verified · key supplied

$ bdr engineer-working
 Read-only image: taken · source untouched
 BitLocker metadata: repaired
 Unlock: key accepted

$ bdr verify
 ✓ documents — 41,900 files
 ✓ mailbox — 1 PST rebuilt
 ✓ data recovered — drive decrypted
!

BitLocker cannot be broken — find the key first.

No recovery firm can decrypt a BitLocker volume without the 48-digit recovery key or the account credentials it is tied to. Before spending anything, check your Microsoft account, Azure AD or Entra, Active Directory, a printout made at setup, a text file on a USB stick, and your password manager.

// why it triggers

Why Windows is asking for a key at all.

BitLocker seals the volume to the machine it lives in. Recovery mode is not a fault — it is the seal noticing that something changed.

// where the key lives

Six places it is probably stored.

The key is recorded automatically far more often than people expect — work through these before concluding it is lost.

01

Your Microsoft account

A personal Windows device backs the key up automatically when BitLocker is enabled with a Microsoft account signed in. Check the recovery-keys page for that device.

02

Azure AD or Entra

On a work device the key is usually escrowed to the tenant, and your IT administrator can retrieve it directly.

03

Active Directory

Domain-joined machines often escrow keys to AD where policy was configured to do so.

04

A printout or saved file

Windows offers to print the key or save it to a file when encryption is switched on, and people frequently accepted.

05

A USB stick

Some setups store the key on removable media, particularly older or manually configured installs.

06

Intune or an MDM console

Managed estates hold keys centrally, and this is often overlooked because the user never saw it.

// when the drive has failed too

Encrypted and physically damaged.

This is the case where a lab genuinely adds something, because the order of operations matters.

If the drive holding a BitLocker volume is also failing, unlocking it first is the wrong move — a decryption pass reads the entire volume, which is hours of sustained work on a disk that may not survive it. The drive is imaged read-only first, and the volume is then unlocked from that image rather than from failing hardware.

That order preserves every read the drive has left, and it means an unstable disk only has to hold together once. Where the drive has bad sectors, the image is taken past them with the gaps logged, and BitLocker’s own integrity checks then tell us precisely which regions could not be recovered rather than producing silently corrupt output.

// pricing

Fixed pricing, agreed in writing.

Two quite different situations, priced differently.

Where the drive is healthy and you have the key, unlocking and extracting the data is a short job rather than a full recovery, and we will say so. Where the drive has failed, a single encrypted drive is from £300 +VAT, with the imaging setting the timescale — typically three to four working days.

Every job opens with a free 48-hour diagnostic and a written quote. Most are no fix, no fee; drive-level physical work carries a 50% deposit with the balance due only on success. Full write-ups: a BitLocker laptop with the key long gone.

// sending your device in

Two simple steps.

Send us your device for a free diagnostic, and tell us a little about what happened — an engineer will review it and confirm your exact quote in writing before any work begins.

1

Send us your device

Getting your data back begins with getting the device to us. Pack it up safely, pop your contact details inside, and send it over — once we’ve run the free diagnostic, we’ll confirm your exact price in writing before any work starts.

How to pack it
  • Box the device up in a small, sturdy carton or a padded envelope.
  • You can leave out caddies, cables and power supplies — none of them are needed for the recovery.
  • Pop your details inside — name, address, phone and email, on a slip of paper or via our shipping form — and seal it up.
Post toOxford Data Recovery
John Eccles House, Oxford Science Park
Oxford OX2
Shipping formPDF · print & include with your devicePDF ↓

Posting it? A tracked, insured service is what we’d recommend. Rather drop it in? You’re welcome Monday to Friday, 9am to 5:30pm — just package the device up as above first.

2

Need more information?

Want a bit more detail first? Fill in the form with more about your issue and an engineer will review it and send you a custom quote.

An engineer reviews every enquiry personally — we usually reply within 30 minutes during the day. Prefer to call? 01865 593000.

Thanks — your message is in.

We’ll be in touch shortly. For anything urgent, call 01865 593000.

// frequently asked questions

BitLocker recovery, answered.

The questions we are asked most about recovering BitLocker and encrypted drives.

No, and neither can anyone else — including Microsoft. That is the entire purpose of full-disk encryption. Any firm claiming to break BitLocker should be treated with real caution. What we can do is recover the drive itself, and unlock the volume from the image once you supply the key.

Because something it trusted changed — commonly a firmware or BIOS update, a change to secure boot or boot order, the drive being moved to another machine, a failed Windows update, or repeated incorrect PIN entries. It is the seal working, not a fault.

Check your Microsoft account recovery-keys page first, then Azure AD or Entra and Active Directory on a work device, then any printout or file saved at setup, a USB stick, your password manager, and any Intune or MDM console. It is stored automatically more often than people realise.

With the key and a healthy drive, unlocking takes minutes. If the drive has also failed, the timescale is set by the imaging rather than the encryption — typically three to four working days. The free 48-hour diagnostic establishes which situation you are in.

Imaging, before any unlocking. A decryption pass reads the whole volume, and on a failing drive that is hours of stress it may not survive. We image read-only first and unlock from the copy, so the disk only has to hold together once.

From £300 plus VAT for a single encrypted drive where the hardware has failed, quoted in writing after a free 48-hour diagnostic. Where the drive is healthy and you have the key, it is a short job and we will price it as one.

// locked out?

Got the key? Let’s get in.

A free diagnostic, a quick ownership check, and your encrypted drive opened and handed back decrypted — a failing disk included. Get in touch and we take it from there.