BitLocker is working as designed here. Physically changing drives (removing/re‑inserting, changing slots, cloning, etc.) can be interpreted as a security or hardware change, which can force the secondary drive into recovery mode and require the BitLocker recovery key.
Key points from the documentation and Q&A content:
- A BitLocker‑protected drive cannot be unlocked without its recovery key if it enters recovery mode. This is by design to protect the data.
- Microsoft Support cannot retrieve, provide, or recreate a lost BitLocker recovery key.
- If the key is not in any of the expected backup locations, the data on that drive cannot be recovered; the only option is to wipe/repartition and reuse the drive (data loss).
Actions to take to try to locate the key:
- Note the Recovery Key ID
- On the BitLocker recovery screen for the secondary drive, write down the first 8 digits of the recovery key ID. This helps match the correct key if multiple keys exist.
- Check common locations for the recovery key
Depending on how BitLocker was originally enabled on that secondary drive, the recovery key may be stored in one or more of these places:
- Microsoft account (for a home device set up with a Microsoft account)
- From another device, go to
https://aka.ms/myrecoverykey(which openshttps://account.microsoft.com/devices/recoverykey). - Sign in with the Microsoft account that was used when BitLocker was turned on or when the device was first set up.
- Look for an entry whose Key ID matches the first 8 digits shown on the locked drive.
- From another device, go to
- Microsoft Entra ID / work or school account (if the device is or was joined to an organization)
- If the device is managed by a company or school, the recovery key may be stored in Microsoft Entra ID or Active Directory.
- Contact the organization’s IT/helpdesk and provide the Recovery Key ID so they can retrieve the key from their management tools.
- Printed or saved copy
- Check for a printed page labeled “BitLocker recovery key” or a text file/USB where the key might have been saved when BitLocker was enabled.
- Microsoft account (for a home device set up with a Microsoft account)
- If managed by MBAM (enterprise scenario)
- If the environment uses Microsoft BitLocker Administration and Monitoring (MBAM), the helpdesk can:
- Open the MBAM Administration and Monitoring Website.
- Go to Drive Recovery.
- Enter the user’s domain and username (if required) and the first 8 digits of the Recovery Key ID.
- Retrieve the matching recovery password and provide it to unlock the drive.
- If the environment uses Microsoft BitLocker Administration and Monitoring (MBAM), the helpdesk can:
- If no key can be found anywhere
- If the key is not in a Microsoft account, not in a work/school directory (Entra ID/AD/MBAM), and there is no printed/saved copy, then the data on the BitLocker‑protected drive cannot be decrypted.
- In that case, the only remaining option is to delete the partitions on that secondary drive and reinitialize it for use, which will erase all data on it.
There is no supported method to bypass BitLocker or “rebuild” the key. All recovery options depend on successfully locating the original recovery key that was created when BitLocker was turned on.
References:
- Find your BitLocker recovery key
- BitLocker overview
- BitLocker recovery process
- Windows devices for home users, businesses, and schools with Microsoft-managed updates
- Recover a drive in recovery mode
- Surface Pro 3 blocked - Microsoft Q&A
- Request for Assistance with BitLocker Recovery – Surface Pro 2 - Microsoft Q&A