- BitLocker recovery keys that are backed up to a Microsoft account are accessed through the account’s device/recovery pages. If the 30‑day security hold is blocking access to “security‑sensitive” areas of the account, that can also block access to the BitLocker recovery keys during that period. In that case, the keys can’t be retrieved from the Microsoft account until the hold is lifted.
- Microsoft Support cannot retrieve, provide, or recreate a lost BitLocker recovery key, and cannot bypass account security restrictions to expose the key earlier. If the key is not accessible via the account or another backup location, Support has no way to supply it.
- If the only copy of the BitLocker recovery key is in the Microsoft account that is under a 30‑day security hold, and there is no backup in any other location (printed, saved to file/USB, backed up to work/school/Entra ID/AD DS, or held by an organization’s IT), then access to that key must wait until the security hold expires and the account again allows access to the BitLocker recovery information. Without a usable recovery key from some location, the encrypted drive cannot be unlocked and the only remaining option is to delete/reformat the drive and reinstall Windows.
To double‑check for other possible key locations, review:
- Microsoft account device recovery keys from another device when the hold ends.
- Any printed copies or files/USB drives where the key may have been saved.
- If the device is work/school‑managed, contact the organization’s IT department, as they may have the key backed up centrally.
References: