Hello, thank you for posting in the Microsoft Q&A community.
When Windows applies critical security updates that harden the boot chain, the Platform Configuration Register (PCR) values inside the Trusted Platform Module (TPM) change. BitLocker relies on PCR 7 and 11 to verify the boot environment's integrity. If the system's BIOS/firmware is incompatible with the new Secure Boot certificates pushed by KB5094126, the TPM will refuse to unseal the encryption key, triggering the BitLocker recovery lock. This behavior is currently being observed more frequently on specific OEM hardware (such as HP and Dell).
Since you mentioned these are local accounts, the recovery key might not be backed up to Microsoft Entra ID. We can attempt to bypass the recovery prompt by temporarily altering the boot trust chain:
- Restart the affected device and immediately enter the BIOS/UEFI Settings (usually by pressing F10, F2, Del, or Esc ).
- Navigate to the Security or Boot Options tab.
- Locate Secure Boot and temporarily Disable it.
- Save the changes and reboot. In many cases, Windows will now bypass the BitLocker prompt and boot normally.
- Once in Windows, apply the steps from the Standard Solution (Suspend BitLocker and update the BIOS).
- Restart the computer, re-enter the BIOS/UEFI, and Enable Secure Boot again.
Official Microsoft References: