Additional Microsoft Entra services and features related to identity, access, and network security
If the BitLocker recovery key is not shown for that device in the Microsoft account or Microsoft Entra ID, it cannot be retrieved from the SSD itself.
Supported recovery locations are:
- Microsoft account:
https://aka.ms/myrecoverykey - Work or school account / Microsoft Entra ID:
https://aka.ms/aadrecoverykeyorhttps://myaccount.microsoft.com→ Devices → select the device → View BitLocker Keys - A printed copy
- A USB flash drive where the key was saved
Important points for the scenario described:
- A recovery key cannot be stored on the drive being encrypted.
- Cloning the SSD does not recover or recreate the BitLocker key. The cloned drive still requires the same recovery key.
- If the device was ever signed into an organization account, the key might be in that organization’s account, or IT support for that organization may need to retrieve it.
- If the device is managed by an organization, helpdesk or admins can retrieve the key from Microsoft Entra ID, Intune, or Active Directory only if the key was backed up there.
- Backup of the BitLocker recovery password to Microsoft Entra ID or AD DS may not happen automatically unless policy was configured to do so.
If the key is not present in any of those locations, there is no supported way to extract it from the failed computer or SSD. The remaining option is to reset or erase the device, which removes all files.