Windows 11 Home: BitLocker-encrypted D: partition remains locked after reinstall, recovery key in Microsoft account does not match

Mourad Mankou 0 Reputation points
2026-05-30T22:39:20.3566667+00:00

Environment

Windows 11 Home

Personal Microsoft account

HP laptop

Single SSD with two partitions:

C: (Windows)

  D: (personal data)
  

What happened

I reinstalled Windows 11 and formatted only the C: partition. The D: partition was left untouched.

After reinstalling Windows, the D: partition is shown as BitLocker encrypted and locked. I do not recall manually enabling BitLocker or Device Encryption on the D: partition.

Disk Management shows:

D: = "Unknown (BitLocker Encrypted)"

Partition status = Healthy

Information collected

Running:

manage-bde -protectors -get D:

returns:

Numerical Password ID: D2C607C9-AFE5-423E-906C-62DF8F418179

Backup type: Microsoft account backup

The only BitLocker recovery key available in my Microsoft account has Key ID:

C71F20A0-4355-4358-ABE1-DB5B19590D4E

The IDs do not match.

What I have already checked

Verified that only C: was formatted.

Verified that D: still exists and is healthy.

Checked all recovery keys visible in my Microsoft account.

Compared the BitLocker protector ID with the Key ID shown in my account.

Confirmed that no matching recovery key is available.

Questions

If BitLocker reports "Microsoft account backup", does that guarantee the recovery key was successfully uploaded to a Microsoft account?

Is there a way to determine which Microsoft account received the backup for protector ID D2C607C9-AFE5-423E-906C-62DF8F418179?

Has anyone encountered a situation where the recovery key stored in the Microsoft account does not match the recovery protector ID of the encrypted volume?

Are there any additional Microsoft-supported methods to locate the recovery key for a BitLocker volume that reports "Microsoft account backup"?

Any guidance would be appreciated because the D: partition contains important personal data and was not formatted during the Windows reinstall.

Thank you

Windows for home | Windows 11 | Security and privacy
0 comments No comments

1 answer

Sort by: Most helpful
  1. AI answer

    2026-05-30T22:39:45.9166667+00:00

    BitLocker “Microsoft account backup” on a protector indicates that BitLocker was configured to back up the recovery key to a Microsoft account, but it does not guarantee that the upload actually completed or that the key is still available.

    From the available information:

    • The D: volume’s protector shows a Numerical Password with backup type “Microsoft account backup” and ID D2C607C9-AFE5-423E-906C-62DF8F418179.
    • The only recovery key visible in the Microsoft account has a different Key ID.
    • There is no matching key for that protector.

    Based on the provided context:

    1. If the recovery key is not available in the Microsoft account (or any other backup location), Microsoft-supported options to unlock the BitLocker volume are effectively exhausted. BitLocker is designed so that without a valid recovery key (or other valid protector such as a Data Recovery Agent certificate), the data cannot be decrypted.
    2. The context explicitly notes that if the recovery key cannot be found, access to the encrypted data is not possible and the only remaining option is to remove/reformat the encrypted volume and reinstall or reuse the drive:
      • “Unfortunately, if the recovery key is not available, it won’t be possible to access the system because of BitLocker encryption. In this case, the only option is to format the hard drive and reinstall Windows.”
      • A similar answer for a Surface device states that if none of the documented options to find the key work and BitLocker prompts before sign-in, “the only option is the recovery image (and data loss).”
    3. The context does not provide any Microsoft-supported mechanism to:
      • Discover which specific Microsoft account received a given protector’s backup.
      • Recover or regenerate a BitLocker recovery key when it is not present in any of the documented backup locations.
    4. The context also does not describe any supported scenario where a recovery key stored in a Microsoft account would intentionally have a different Key ID than the protector on the volume. The documented guidance is that the Key ID must match; if it does not, that key cannot unlock that volume.
    5. Additional Microsoft-supported methods to locate a recovery key are limited to the standard guidance (checking Microsoft account, work/school account, printed copies, USB/file backups, organizational backups such as Active Directory or Intune). When those are exhausted and no matching key is found, Microsoft’s own troubleshooting guidance concludes that the encrypted data cannot be recovered and the drive must be reformatted.

    Given the constraints in the context, there is no further Microsoft-supported method to unlock the D: volume or to identify another account that might hold the key. If no matching recovery key can be found via the documented methods, the only supported option is to delete/format the BitLocker-encrypted D: partition and accept data loss.


    References:

    AI-generated content may be incorrect. Read our transparency notes for more information.

    Was this answer helpful?

Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.