Skip to content

BitLocker Drive Encryption and Recovery Key Backup

BitLocker protects data at rest, but encryption alone does not guarantee recoverability. Before changing a protector or starting encryption, confirm the recovery key is escrowed in a location your authorized support team can access. Never paste a recovery password into a ticket, chat, screenshot, or source-controlled file.

This walkthrough checks existing drive status, reviews TPM and recovery protectors without printing the 48-digit recovery password, and backs up the recovery key using the Control Panel or your organization’s approved directory escrow. Run administrative commands in an elevated PowerShell session. BitLocker management options vary by Windows edition, device configuration, and organization policy.


Step 1: Check the Edition, TPM, and Existing Encryption State

01

Inventory BitLocker Readiness and Drive Status

Read-only Check

Start with a read-only check. Confirm the installed Windows edition, whether a TPM is present and ready, and each volume’s current conversion and protection state. A volume can be fully encrypted while protection is suspended, so check both status fields.

Terminal window
Get-ComputerInfo -Property WindowsProductName, WindowsEditionId
Get-Tpm | Select-Object TpmPresent, TpmReady, TpmEnabled, TpmActivated
Get-BitLockerVolume |
Select-Object MountPoint, VolumeType, VolumeStatus, ProtectionStatus,
EncryptionPercentage
❯ View Expected Console Output
MountPoint VolumeType VolumeStatus ProtectionStatus EncryptionPercentage
---------- ---------- ------------ ---------------- --------------------
C: OperatingSystem FullyEncrypted On 100
D: FixedData FullyEncrypted On 100
Windows Control Panel BitLocker Drive Encryption page showing operating system and data drive states and actions

Figure 1: BitLocker Drive Encryption Control Panel showing the operating system and data drive states.


Step 2: Review Protector Types Without Exposing the Recovery Password

02

Confirm TPM and Recovery Password Protectors

Protector Review

List protector types and IDs for the operating system volume. These identifiers are not the recovery password and can be used to match an escrow record. For a typical TPM-protected OS volume, expect a TPM protector and a RecoveryPassword protector; exact combinations depend on policy.

Terminal window
$MountPoint = 'C:'
$Volume = Get-BitLockerVolume -MountPoint $MountPoint
$Volume.KeyProtector |
Select-Object KeyProtectorType, KeyProtectorId
❯ View Expected Console Output
KeyProtectorType KeyProtectorId
---------------- --------------
Tpm {protector-guid}
RecoveryPassword {recovery-protector-guid}
Windows PowerShell listing TPM and RecoveryPassword protector types without displaying recovery secrets

Figure 2: Confirm the TPM and recovery password protector types without exposing the recovery password.


Step 3: Back Up the Recovery Key Using the Windows Interface

03

Open Manage BitLocker and Choose a Backup Destination

Recovery Backup

Open the BitLocker Control Panel applet and use Back up your recovery key for the intended volume. The applet may offer a Microsoft account, a work or school (Microsoft Entra) account, USB, file, or print options depending on device and policy. Do not assume that an Active Directory Domain Services (AD DS) destination appears in this UI; use the approved AD DS escrow policy or cmdlet when that is the required destination.

Terminal window
# Open the BitLocker Drive Encryption Control Panel applet
control.exe /name Microsoft.BitLockerDriveEncryption
❯ View Expected Console Output
In the applet:
1. Expand the intended drive.
2. Select Back up your recovery key.
3. Choose an approved destination shown by this device and finish the wizard.
4. Confirm the backup is accessible to the authorized recovery team.
Windows BitLocker recovery key backup options dialog with Microsoft account, USB drive, file, and print destinations

Figure 3: BitLocker recovery key backup destinations.


Step 4: Verify the Escrow Record and Record Only Safe Metadata

04

Verify Recovery Readiness Without Copying the Secret

Validation

Verify the recovery record from the authorized management system or approved recovery procedure. Record the device identity, volume, protector type, protector ID, backup location, and verification date. Do not put the recovery password in the asset record. For domain-managed Windows devices, IT staff can use the approved Active Directory recovery workflow; for Entra-joined devices, use the organization’s Entra recovery process.

Terminal window
# Safe inventory: protector types and IDs only
$Volume = Get-BitLockerVolume -MountPoint 'C:'
$Volume.KeyProtector |
Select-Object KeyProtectorType, KeyProtectorId
# Recheck overall volume state
Get-BitLockerVolume -MountPoint 'C:' |
Select-Object MountPoint, VolumeStatus, ProtectionStatus, EncryptionPercentage
❯ View Expected Console Output
Confirm in your approved recovery system:
- The expected device and volume are listed.
- A recovery record matches the protector ID.
- An authorized operator can retrieve it through the documented process.

For implementation and platform-specific details, see Microsoft’s BitLocker operations guide, recovery overview, and recovery key backup instructions.

Comments