AfterFormat

Check BitLocker before you format

Modern Windows 11 locks the disk without asking. If "Enter the recovery key" turns up after a reformat or a hardware swap, the data is gone unless you have that key. Checking takes five minutes.

Last updated

Contents
  1. 1 Why it suddenly asks for a recovery key
  2. 2 Check whether your PC is encrypted
  3. 3 Where the recovery key is
  4. 4 Before you format: one of three
  5. 5 Already reinstalled and D: is locked?
  6. 6 Frequently asked

Why it suddenly asks for a recovery key

BitLocker is the disk encryption built into Windows. It used to be something you switched on yourself, on Pro. Now it is in Home too, under the name "Device encryption", and when Windows 11 is set up with a Microsoft account it is frequently turned on without you doing anything. Most recent laptops ship in this state.

The key that unlocks the disk sits in the motherboard’s security chip (the TPM), and it is released automatically only when the PC can confirm it started up "the same way as usual". That is why you never notice it. The trouble starts the moment that check fails. In the situations below, Windows withholds the key and demands the 48-digit recovery key instead.

Opening the D: drive after a reinstall
Device encryption locks not only the Windows drive but the other internal drives too. Format C: and install fresh, and the new Windows does not know the key for D:. A padlock appears on D: in Explorer and it will not open without the recovery key. This is the most common accident around a reformat.
Changing BIOS or UEFI settings
Turning off Secure Boot, changing the boot order or touching TPM settings all count as "not the usual state". Even switching the boot order to start from an install USB can trigger it.
Updating the BIOS or firmware
After a vendor utility updates the firmware and reboots, the recovery screen sometimes appears. It has also happened after certain Windows updates.
Replacing the motherboard or CPU, or clearing the TPM
The chip holding the key has changed, so it cannot unlock automatically. Here the recovery key is the only way in.
Moving the disk to another PC
Pulling the drive from a dead PC to rescue the data runs straight into this wall. The disk is fine; the contents cannot be read.

Check whether your PC is encrypted

  1. Look at the drive icons in Explorer

    Open This PC. A padlock on the C: or D: icon means the drive is encrypted. An open padlock means it is currently unlocked; a closed one means it is locked.

  2. Check in Settings

    Home edition: Settings → Privacy & security → Device encryption. "On" means encrypted. Pro edition: Control Panel → BitLocker Drive Encryption shows "BitLocker on/off" per drive.

  3. To be certain, use the command

    In an administrator terminal run manage-bde -status. For each drive, "Protection Status: Protection On" means it is encrypted, and a "Conversion Status" short of 100% means encryption is still in progress.

Where the recovery key is

The recovery key is 48 digits. When Windows turns device encryption on it always backs the key up somewhere, and that somewhere is usually the first item below.

Your Microsoft account
Sign in at account.microsoft.com/devices/recoverykey to see the recovery keys for every PC set up with that account — it works from a phone. Match the first eight characters of the "Key ID" shown on the recovery screen. If the PC was set up with a different account from the one you use now, look in that one.
A work or school account
A PC set up with a work account keeps its key in the organisation’s management system (Entra ID, Intune). Sometimes it is visible under myaccount.microsoft.com → Devices; otherwise the IT department can retrieve it.
A file, printout or USB stick you saved yourself
If you turned BitLocker on manually on Pro, the "Back up your recovery key" step had you save a file or print it. The file is named "BitLocker Recovery Key [key ID].txt" — search other drives and cloud storage for that name.
Another drive on the same PC
While C: is still alive, Control Panel → BitLocker Drive Encryption → "Back up your recovery key" for the drive lets you pull the key out right now. Doing this before you format is the point of this guide.

Before you format: one of three

If encryption is on, do one of the following before formatting. Any of them takes between five minutes and an hour; skipping them cannot be undone.

  1. Back up the recovery key — the simplest

    Settings → Privacy & security → Device encryption → "Back up your BitLocker recovery key" (Home), or Control Panel → BitLocker Drive Encryption → Back up your recovery key (Pro). Save it to your Microsoft account and also to a file on a USB stick or another cloud service. Each drive has its own key, so do both C: and D:.

  2. Decrypt the data drive — the most certain

    If you plan to keep using D: as-is after the reformat, unlock it for good: Control Panel → BitLocker Drive Encryption → D: → "Turn off BitLocker". It takes anywhere from tens of minutes to hours depending on size, and the PC must not be switched off until it finishes. Afterwards, D: simply opens in the new Windows.

  3. Move the data out and wipe everything

    Copy everything to an external disk or the cloud, then delete all partitions during setup and the encryption goes with them. If you were going to rebuild D: anyway, this is the cleanest route.

Already reinstalled and D: is locked?

  1. Double-click the drive

    A BitLocker window asks for a password or recovery key. Choose "More options → Enter recovery key" and note the key ID it shows.

  2. Find the recovery key as above and enter it

    Type the 48 digits and the drive opens. It is only unlocked for this session; it locks again on reboot.

  3. While it is open, decide

    In Control Panel → BitLocker Drive Encryption either "Turn off BitLocker" for that drive, or, if you want to keep it encrypted, "Turn on auto-unlock" so the new Windows holds the key, and back up the recovery key afresh. Either way, copy the data somewhere else first.

If the recovery key truly does not exist

There is no way back. No recovery tool, no data recovery service, not Microsoft — if any of them could open it, it would not be encryption. That is why this guide has "before you format" in the title. And if the recovery screen appeared at boot: enter the key, get into Windows, then in Control Panel → BitLocker click "Suspend protection" and then "Resume protection", so the changed state is recorded and it does not ask again next boot.

Frequently asked

Will the freshly installed Windows lock the disk again?

Set up with a Microsoft account, it usually does, and the recovery key is saved to that account automatically. If you do not want it, turn it off under Settings → Privacy & security → Device encryption. Set up with a local account, there is nowhere to save the key, so it either stays off or waits.

Can I just leave encryption off?

On a desktop, turning it off causes no real harm. On a laptop it is what stops someone who steals or finds it from pulling the drive and reading your data, so it is better on. Either way, knowing where the recovery key is comes first.

Does it slow the PC down?

On a current SSD and CPU it is hard to notice. Storage performance can dip a little in some situations, but not to a degree that matters in everyday use.

Is a photo of the recovery key on my phone good enough?

The key is effectively the password to the whole disk. A password manager or a piece of paper in a drawer beats the camera roll. But a photo beats nothing at all.

What about when I sell the laptop?

It works in your favour. With encryption on, "Reset this PC → Remove everything → Clean the drive" leaves nothing readable even if fragments remain. Just remember to remove the PC from your Microsoft account before the reset.

Checked? On to the next step

BitLocker is not the only thing to sort out before a format. Two-factor apps, certificates and browser profiles — the things that cannot be recovered once lost — are listed in order.

Read what to sort out before you format

Contact us

Without it we cannot write back.