I got this option: save your secret key to Azure AD

jacky lau 0 Reputation points
2026-09-04T08:13:32.7766667+00:00

when i wanna enable bitlocker on disk D,After i set unlock password, the next step shows: How do you want to save your secret key ? There are some options below.

  1. save your key on Azure AD(A)
  2. save your key on U disk(U)
  3. save your key in File(F)
  4. print your key(P)

There is not Microsoft Account option but Azure AD, maybe my email address not quit from Azure AD 。

How can i quit the Azure AD?

Windows for business | Windows Client for IT Pros | Directory services | Active Directory
0 comments No comments

2 answers

Sort by: Most helpful
  1. Jason Nguyen Tran 25,120 Reputation points Independent Advisor
    2026-09-04T09:01:40.0566667+00:00

    Hi Jacky,

    This happens because your device is currently joined to Azure AD, so the system assumes that recovery keys should be stored in that directory rather than a personal Microsoft account.

    If you want to “quit” Azure AD and go back to a standalone or personal Microsoft account setup, you’ll need to disconnect the device from Azure AD. You can do this by going to Settings > Accounts > Access work or school, selecting your Azure AD account, and choosing Disconnect. After that, you can re‑join the device either to a local account or to a personal Microsoft account, which will then give you the option to store BitLocker keys in that account.

    Keep in mind that disconnecting from Azure AD may affect access to organizational resources, policies, and apps tied to your work account. If this is a corporate‑managed device, I recommend checking with your IT administrator before making changes, as they may have compliance requirements for key storage.

    Once the device is no longer Azure AD‑joined, BitLocker will offer the Microsoft account option for recovery key storage. Alternatively, you can always save the key to a file, USB drive, or print it for safekeeping.

    I hope the response provided some helpful insight. If you find this answer useful, please hit “accept answer” so I know it addressed your concern.

    Jason.

    Was this answer helpful?


  2. AI answer

    2026-09-04T08:13:50.1533333+00:00

    Yes. That behavior usually means the device is connected to a work or school identity rather than using a personal Microsoft account for BitLocker key backup.

    For BitLocker, the backup location depends on how the device is joined:

    • Microsoft Entra joined devices can save the recovery key to Microsoft Entra ID.
    • Active Directory joined devices can save the recovery key to AD DS.
    • Devices that aren’t domain-joined and are using a Microsoft account can save the recovery key to the Microsoft account.

    The BitLocker backup UI can show Save to your Azure AD account instead of Save to your Microsoft Account when signed in on a computer managed by work or school.

    So if the screen shows save your key to Azure AD, that indicates the recovery key is being backed up to the work or school account associated with the device.

    Available backup methods shown in that screen are valid alternatives as well:

    • USB flash drive
    • Save to a file
    • Print the recovery key

    Important precautions:

    • Do not keep the USB copy with the computer.
    • Do not store the text file on the same BitLocker-encrypted drive.
    • Keep printed copies somewhere separate and secure.

    If access to the key is needed later for a work or school account, it can be viewed from the My Account portal on another device by going to the Devices page and selecting View BitLocker Keys for the locked device.


    AI-generated content may be incorrect. Read our transparency notes for more information.

    Was this answer helpful?

Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.