A blue screen asking for 48 digits is BitLocker doing its job, not a failure. Understanding why it triggered tells you how quickly you will be back in — and where the drive itself has failed as well, the order of operations matters more than most people realise.
$ bdr triage /dev/sdb → Device: Dell XPS SSD · 512 GB → Status: BITLOCKER LOCKED — volume refuses to mount → Owner: verified · key supplied $ bdr engineer-working → Read-only image: taken · source untouched → BitLocker metadata: repaired → Unlock: key accepted $ bdr verify → ✓ documents — 41,900 files → ✓ mailbox — 1 PST rebuilt → ✓ data recovered — drive decrypted
No recovery firm can decrypt a BitLocker volume without the 48-digit recovery key or the account credentials it is tied to. Before spending anything, check your Microsoft account, Azure AD or Entra, Active Directory, a printout made at setup, a text file on a USB stick, and your password manager.
BitLocker seals the volume to the machine it lives in. Recovery mode is not a fault — it is the seal noticing that something changed.
The key is recorded automatically far more often than people expect — work through these before concluding it is lost.
A personal Windows device backs the key up automatically when BitLocker is enabled with a Microsoft account signed in. Check the recovery-keys page for that device.
On a work device the key is usually escrowed to the tenant, and your IT administrator can retrieve it directly.
Domain-joined machines often escrow keys to AD where policy was configured to do so.
Windows offers to print the key or save it to a file when encryption is switched on, and people frequently accepted.
Some setups store the key on removable media, particularly older or manually configured installs.
Managed estates hold keys centrally, and this is often overlooked because the user never saw it.
This is the case where a lab genuinely adds something, because the order of operations matters.
If the drive holding a BitLocker volume is also failing, unlocking it first is the wrong move — a decryption pass reads the entire volume, which is hours of sustained work on a disk that may not survive it. The drive is imaged read-only first, and the volume is then unlocked from that image rather than from failing hardware.
That order preserves every read the drive has left, and it means an unstable disk only has to hold together once. Where the drive has bad sectors, the image is taken past them with the gaps logged, and BitLocker’s own integrity checks then tell us precisely which regions could not be recovered rather than producing silently corrupt output.
Two quite different situations, priced differently.
Where the drive is healthy and you have the key, unlocking and extracting the data is a short job rather than a full recovery, and we will say so. Where the drive has failed, a single encrypted drive is from £300 +VAT, with the imaging setting the timescale — typically three to four working days.
Every job opens with a free 48-hour diagnostic and a written quote. Most are no fix, no fee; drive-level physical work carries a 50% deposit with the balance due only on success. Full write-ups: a BitLocker laptop with the key long gone.
Send us your device for a free diagnostic, and tell us a little about what happened — an engineer will review it and confirm your exact quote in writing before any work begins.
Getting your data back begins with getting the device to us. Pack it up safely, pop your contact details inside, and send it over — once we’ve run the free diagnostic, we’ll confirm your exact price in writing before any work starts.
Posting it? A tracked, insured service is what we’d recommend. Rather drop it in? You’re welcome Monday to Friday, 9am to 5:30pm — just package the device up as above first.
Want a bit more detail first? Fill in the form with more about your issue and an engineer will review it and send you a custom quote.
We’ll be in touch shortly. For anything urgent, call 01865 593000.
The questions we are asked most about recovering BitLocker and encrypted drives.
No, and neither can anyone else — including Microsoft. That is the entire purpose of full-disk encryption. Any firm claiming to break BitLocker should be treated with real caution. What we can do is recover the drive itself, and unlock the volume from the image once you supply the key.
Because something it trusted changed — commonly a firmware or BIOS update, a change to secure boot or boot order, the drive being moved to another machine, a failed Windows update, or repeated incorrect PIN entries. It is the seal working, not a fault.
Check your Microsoft account recovery-keys page first, then Azure AD or Entra and Active Directory on a work device, then any printout or file saved at setup, a USB stick, your password manager, and any Intune or MDM console. It is stored automatically more often than people realise.
With the key and a healthy drive, unlocking takes minutes. If the drive has also failed, the timescale is set by the imaging rather than the encryption — typically three to four working days. The free 48-hour diagnostic establishes which situation you are in.
Imaging, before any unlocking. A decryption pass reads the whole volume, and on a failing drive that is hours of stress it may not survive. We image read-only first and unlock from the copy, so the disk only has to hold together once.
From £300 plus VAT for a single encrypted drive where the hardware has failed, quoted in writing after a free 48-hour diagnostic. Where the drive is healthy and you have the key, it is a short job and we will price it as one.
A free diagnostic, a quick ownership check, and your encrypted drive opened and handed back decrypted — a failing disk included. Get in touch and we take it from there.