A set of tools and technologies that enable developers to build, optimize, and deploy applications and services within the Windows ecosystem.
Yes, but only in specific scopes.
- The Recovery Key ID shown on the BitLocker recovery screen can be used to help locate the corresponding recovery password in Microsoft Entra ID or Active Directory Domain Services (AD DS).
- In helpdesk recovery guidance, the recovery key ID from the preboot screen is specifically recorded so the recovery password can be located in Microsoft Entra ID or AD DS.
- For organizationally managed devices, the administrator should also record the device name. The device name can be used to locate the recovery password in Microsoft Entra ID or AD DS.
What the Recovery Key ID does not do:
- There is no supported method in the provided documentation to use the Recovery Key ID by itself to determine which Microsoft account contains the recovery key.
- The recovery screen may show only a hint about where the key was saved, such as Microsoft account, Microsoft Entra ID, or a generic help desk message. The metadata used for those hints is not exposed through the UI or any public API.
- Microsoft Support cannot retrieve, provide, or recreate a lost BitLocker recovery key.
If the device is Microsoft Entra joined or organization-managed:
- Provide the administrator with the Recovery Key ID shown on the recovery screen.
- Provide the device name if available.
- The administrator can use the device name or Recovery Key ID to locate the recovery password in Microsoft Entra ID or AD DS.
- If the organization manages the device, the recovery key is typically backed up and managed by the organization’s IT department.
What to provide to an administrator:
- Recovery Key ID from the BitLocker recovery screen
- Device name
- Confirmation that the device is a work or school managed device, if applicable
Supported recovery locations described in the documentation include:
- Microsoft Entra ID for Microsoft Entra joined devices
- AD DS for Active Directory joined devices
- Microsoft account for devices that are not domain-joined and use a Microsoft account
- A text file or printed copy, depending on how BitLocker was configured
If only the Recovery Key ID is available:
- It is supported for admins to use that ID to find the recovery password in Microsoft Entra ID or AD DS.
- It is not supported in the provided documentation as a way to identify the exact Microsoft account or exact organizational account that holds the key.