BitLocker is working as designed and there is no supported way to obtain or bypass a missing recovery key.
On consumer Surface devices, BitLocker (or device encryption) can be enabled automatically without an explicit setup step. The recovery key is then stored in one of the supported locations (for example, a Microsoft account, an organization’s management system, or printed/saved by the user). If the key is not present in any of those locations, it cannot be recovered by anyone, including Microsoft Support.
The only available options are:
- Continue using Windows normally without performing the Troubleshoot/Reset path that asks for the BitLocker key (so the drive remains unlocked by the existing protectors), or
- If the device becomes unbootable and the recovery key still cannot be found, reset/reimage the device using a Surface recovery image, understanding that this will result in data loss on the encrypted drive.
For Surface devices that are stuck in recovery or repeatedly prompt for a BitLocker key after firmware/UEFI/TPM changes, the documented recovery paths require the existing BitLocker recovery password (for example, using manage-bde.exe -unlock -recoverypassword <Password> <DriveLetter>:). Without that password, those procedures cannot be completed.
If the device was ever managed by an organization (work/school), the only remaining possibility is to contact that organization’s IT to see if they have the key in MBAM, Configuration Manager BitLocker Management, Intune, or another management system. If it has always been a private, unmanaged device and the key is not in the Microsoft account or any saved/printed record, the key is not recoverable.
References: