Your computer is asking for a 48-digit recovery key. What that is, and where yours is.
There is a screen that has been catching people out all year. Blue, plain, no logos. It says the drive is locked, gives you a key ID, and asks you to type in a 48-digit recovery key.
Nobody remembers ever being given a 48-digit anything.
We have taken this call, so this is one of the few guides on this site written from the inside of the job rather than from reading about it. The mechanism is worth understanding, because the difference between a two-minute fix and losing everything on the machine comes down to something you can check tonight, from your phone, before anything has gone wrong at all.
First: what that screen actually is
It is not a virus. It is not ransomware. It is not somebody who has locked you out of your own computer, and it is not a scam page — those always carry a phone number, and this one does not. If you want the difference set out properly, how to spot a tech support scam covers it.
What has happened is this. The drive inside your computer is encrypted. Everything on it — photographs, documents, the lot — is stored scrambled, and it gets unscrambled on the fly every time the machine starts, using a key the computer normally holds for you and hands over automatically. You never see any of it. That is the design.
The automatic hand-over only happens while the computer is satisfied that it is still the same computer. When something about it changes in a way it did not expect, it stops trusting itself, refuses to hand the key over automatically, and asks a human for the key instead.
The machine is not accusing you of anything. It is asking you to prove you are the owner, and it has decided that the proof is 48 digits long.
Where your key almost certainly is
If the computer was set up while signed in with a Microsoft account — which is how the overwhelming majority of Windows machines are now set up, because Windows pushes hard for it — then the key was uploaded to that account automatically at the time.
Go to account.microsoft.com/devices/recoverykey on your phone or on any other computer. Sign in with the Microsoft account the locked machine uses. Your devices are listed, with a key against each one, and each key has an ID. Match the ID on the locked screen to the ID in the list, then type in the key it gives you. Microsoft’s own walkthrough for finding your BitLocker recovery key is the authority here and we will not restate it badly.
Two situations change that answer. If a workplace or a college handed you the machine, the key sits with their IT rather than in your personal account, so ring them. And if the machine was set up with a local account rather than a Microsoft one, there may be no copy anywhere except one you saved yourself at the time. That second case is the one that hurts.
Why it was on when nobody switched it on
This is the part that makes people angry, and reasonably so.
Encryption used to require particular hardware, so it turned itself on only for a minority of machines. Since Windows 11 version 24H2, Microsoft dropped those prerequisites. Automatic device encryption now applies far more widely, on Home editions as well as Pro, and it happens quietly during setup. You are not asked. There is no moment where a box appears saying this drive will be encrypted and here is the key, write it down. Microsoft documents the current behaviour in its BitLocker and device encryption reference on Microsoft Learn, checked on 29 August 2026.
For a stolen laptop this is genuinely good. A thief gets a paperweight and a scrambled drive rather than your bank statements and your passport scan. The cost of that protection is that a great many people are carrying an encrypted machine, and a key they have never seen, without knowing either fact.
Why a routine update sets it off
While it starts up, your computer measures its own start-up chain — the firmware, the boot settings, the security configuration — and compares the measurement against what it saw last time. The key is released automatically only when the measurement matches.
A firmware update from the manufacturer changes that chain. So does a Windows update that touches the boot components, and so does someone changing a setting in the BIOS, or in some cases a hardware change. The measurement no longer matches, the automatic release stops, and the machine falls back to asking for the key.
This has happened more than once during 2026, to people who did nothing at all except let their computer install the updates it was told to install. It is not a fault you caused, and we are not going to promise it will not happen again, because that is not ours to promise. What it means in practice is simple: your computer can decide to ask for that key on a Tuesday morning for no reason you can see. The only question that matters then is whether you can produce it.
The hard part, said early so nobody wastes a callout
If the key is genuinely gone — no Microsoft account, no printout, no IT department, nothing written down — then nobody gets in. Not Microsoft, not us, not a data recovery laboratory in a clean room.
There is no back door, no override code, no technician’s trick. Encryption that could be undone by the manufacturer would not be encryption; it would be a lock with a spare key hanging next to it. The protection that makes a stolen laptop worthless to a thief is the same protection standing between you and your own photographs, and it does not know the difference between you.
At that point the only route forward is wiping the drive and reinstalling Windows. The machine comes back. The files do not.
We would far rather tell you that on the phone, for nothing, than turn up and charge you to discover it. It is the answer that loses us the job, and it is still the right answer.
The bit nobody explains: the dead laptop
There is a guide on this site saying that a laptop which will not switch on usually still has your files intact, and that a drive does not need its laptop in order to be read. That is true, and it remains the honest answer for most dead machines. Your laptop will not turn on, can you still get your files off it sets it out.
Encryption is the exception that keeps that post honest, and it is worth understanding.
The chip that holds and releases your encryption key does not live on the drive. It lives on the mainboard — the big board that also carries the power circuitry, the very part that tends to be what killed the laptop. So when the board is dead, the drive can still be lifted out and read perfectly well, and what comes off it is scrambled. Not damaged. Not corrupted. Just an encrypted blob, complete and unreadable, because the thing that would have unlocked it died with the board.
That is recoverable if the key is in your Microsoft account. It is not recoverable in any way at all if it is not. Which is why, on any data recovery job involving a Windows machine, the first question we ask is not about the drive. It is whether you know the account the computer was set up with, because the answer to that decides whether there is a job here or not.
What to do tonight, while nothing is wrong
This takes about two minutes and it is the whole point of this guide.
- On your phone, go to account.microsoft.com/devices/recoverykey and sign in with the account your computer uses.
- Find your machine in the list and look at the key against it. That is your key. It exists whether you knew about it or not.
- Save it somewhere that is not the computer. A note in your password manager, an email to yourself, a photograph of the screen. Somewhere you could reach it from a phone while the computer sits there locked.
- Print it, or write it out, and put it with your passport and your birth certificate. Paper does not need a login.
- Do the same for every Windows machine in the house, including the one in the spare room that only gets used for the tax return.
If step one shows you nothing, that is worth knowing now rather than in a year. It means the machine is either not encrypted or was set up on a local account, and the second of those is the one to deal with before an update makes the decision for you.
While you are at it, this is a good moment to ask the other question: if that drive stopped tomorrow, what would you lose? Encryption protects your files from strangers; it does nothing whatsoever to protect them from a drive that fails. How to back up your files is the short version, and the warning signs of a failing drive is worth five minutes if the machine has started behaving oddly.
If you are locked out right now
Try the Microsoft account route first, from your phone, before you ring anybody. It is free, it takes a minute, and it solves this outright more often than not.
If that does not produce a key, ring us and say on the phone that the machine is asking for a recovery key. We will ask you a handful of questions about how the computer was set up and who set it up, and those answers usually tell us the outcome before anyone gets in a van. We will help you look in the places people forget to look, and we will not bill you for looking. Where there is a route back in, getting you back into your own machine is exactly the job. Where there is not, you will hear that plainly and early.
We come to you across Leeds, West Yorkshire and North Yorkshire. The diagnosis is free, you get one fixed quote before any work, and if we cannot fix it there is nothing to pay. On this particular fault, though, the most valuable thing on this page is not our phone number. It is step one, done tonight, before you need it.
Questions people ask
Is the recovery key screen a virus or a scam?
No. It is a genuine Windows screen and it is doing its job. Encryption on the drive has decided the machine can no longer be trusted to unlock itself automatically, usually after a firmware or Windows update, and it is asking for the key instead. The tell that separates it from a scam page is what it does not have: no phone number, no alarm sound, no company logo asking you to ring anyone. Any screen with a number to call is a different problem entirely.
Where do I find my BitLocker recovery key?
Almost always in the Microsoft account the computer was set up with. Go to account.microsoft.com/devices/recoverykey on your phone or another computer, sign in with that account, and the keys for your devices are listed against them. Match the key ID shown on the locked machine's screen to the one in the list. If a workplace set the machine up, the key will be held by their IT rather than by you, so ask them.
I never turned encryption on. Why is my drive encrypted?
Because nobody asked you. Since Windows 11 version 24H2 the old hardware prerequisites for automatic device encryption were dropped, so a great many machines now encrypt themselves during setup, on Home as well as Pro, without ever putting the question to the owner. It is a sensible default for a laptop that might get stolen. It is a nasty surprise when the key is wanted years later and you did not know there was one.
Can you get into an encrypted drive without the key?
No, and be wary of anyone who says otherwise. Without the key the data is unreadable to us exactly as it is to a thief, which is the entire purpose of it. Microsoft cannot recover it, we cannot recover it, and no data recovery laboratory can break it. If the key cannot be found, the only route forward is wiping the drive and reinstalling Windows, and the files that were on it are gone.
Does the same thing happen on a Mac?
Macs encrypt too, through FileVault, and modern ones are effectively encrypted from the moment they are set up. The recovery route is different, running through your Apple Account or a recovery key you were shown at setup, but the underlying rule is identical: no key and no account access means no way in, for anyone.
The diagnosis is always free
Not sure what your machine needs? Ask.
Tell us the fault and we will tell you straight: what is wrong, what it will cost, and whether it is worth doing. A fixed quote before any work, and no fix, no fee.