BitLocker Drive Encryption and Recovery Key Backup
BitLocker protects data at rest, but encryption alone does not guarantee recoverability. Before changing a protector or starting encryption, confirm the recovery key is escrowed in a location your authorized support team can access. Never paste a recovery password into a ticket, chat, screenshot, or source-controlled file.
This walkthrough checks existing drive status, reviews TPM and recovery protectors without printing the 48-digit recovery password, and backs up the recovery key using the Control Panel or your organization’s approved directory escrow. Run administrative commands in an elevated PowerShell session. BitLocker management options vary by Windows edition, device configuration, and organization policy.
Step 1: Check the Edition, TPM, and Existing Encryption State
Inventory BitLocker Readiness and Drive Status
Read-only CheckStart with a read-only check. Confirm the installed Windows edition, whether a TPM is present and ready, and each volume’s current conversion and protection state. A volume can be fully encrypted while protection is suspended, so check both status fields.
Get-ComputerInfo -Property WindowsProductName, WindowsEditionIdGet-Tpm | Select-Object TpmPresent, TpmReady, TpmEnabled, TpmActivated
Get-BitLockerVolume | Select-Object MountPoint, VolumeType, VolumeStatus, ProtectionStatus, EncryptionPercentage❯ View Expected Console Output
MountPoint VolumeType VolumeStatus ProtectionStatus EncryptionPercentage---------- ---------- ------------ ---------------- --------------------C: OperatingSystem FullyEncrypted On 100D: FixedData FullyEncrypted On 100
Figure 1: BitLocker Drive Encryption Control Panel showing the operating system and data drive states.
Step 2: Review Protector Types Without Exposing the Recovery Password
Confirm TPM and Recovery Password Protectors
Protector ReviewList protector types and IDs for the operating system volume. These identifiers are not the recovery password and can be used to match an escrow record. For a typical TPM-protected OS volume, expect a TPM protector and a RecoveryPassword protector; exact combinations depend on policy.
$MountPoint = 'C:'$Volume = Get-BitLockerVolume -MountPoint $MountPoint
$Volume.KeyProtector | Select-Object KeyProtectorType, KeyProtectorId❯ View Expected Console Output
KeyProtectorType KeyProtectorId---------------- --------------Tpm {protector-guid}RecoveryPassword {recovery-protector-guid}
Figure 2: Confirm the TPM and recovery password protector types without exposing the recovery password.
Step 3: Back Up the Recovery Key Using the Windows Interface
Open Manage BitLocker and Choose a Backup Destination
Recovery BackupOpen the BitLocker Control Panel applet and use Back up your recovery key for the intended volume. The applet may offer a Microsoft account, a work or school (Microsoft Entra) account, USB, file, or print options depending on device and policy. Do not assume that an Active Directory Domain Services (AD DS) destination appears in this UI; use the approved AD DS escrow policy or cmdlet when that is the required destination.
# Open the BitLocker Drive Encryption Control Panel appletcontrol.exe /name Microsoft.BitLockerDriveEncryption# Use only when AD DS is the approved escrow destination.$Volume = Get-BitLockerVolume -MountPoint 'C:'$RecoveryProtector = $Volume.KeyProtector | Where-Object KeyProtectorType -eq 'RecoveryPassword' | Select-Object -First 1if (-not $RecoveryProtector) { throw 'No RecoveryPassword protector exists for this volume.'}Backup-BitLockerKeyProtector -MountPoint 'C:' -KeyProtectorId $RecoveryProtector.KeyProtectorId# Use only when Entra ID is the approved escrow destination.$Volume = Get-BitLockerVolume -MountPoint 'C:'$RecoveryProtector = $Volume.KeyProtector | Where-Object KeyProtectorType -eq 'RecoveryPassword' | Select-Object -First 1if (-not $RecoveryProtector) { throw 'No RecoveryPassword protector exists for this volume.'}BackupToAAD-BitLockerKeyProtector -MountPoint 'C:' -KeyProtectorId $RecoveryProtector.KeyProtectorId❯ View Expected Console Output
In the applet:1. Expand the intended drive.2. Select Back up your recovery key.3. Choose an approved destination shown by this device and finish the wizard.4. Confirm the backup is accessible to the authorized recovery team.
Figure 3: BitLocker recovery key backup destinations.
Step 4: Verify the Escrow Record and Record Only Safe Metadata
Verify Recovery Readiness Without Copying the Secret
ValidationVerify the recovery record from the authorized management system or approved recovery procedure. Record the device identity, volume, protector type, protector ID, backup location, and verification date. Do not put the recovery password in the asset record. For domain-managed Windows devices, IT staff can use the approved Active Directory recovery workflow; for Entra-joined devices, use the organization’s Entra recovery process.
# Safe inventory: protector types and IDs only$Volume = Get-BitLockerVolume -MountPoint 'C:'$Volume.KeyProtector | Select-Object KeyProtectorType, KeyProtectorId
# Recheck overall volume stateGet-BitLockerVolume -MountPoint 'C:' | Select-Object MountPoint, VolumeStatus, ProtectionStatus, EncryptionPercentage❯ View Expected Console Output
Confirm in your approved recovery system:- The expected device and volume are listed.- A recovery record matches the protector ID.- An authorized operator can retrieve it through the documented process.For implementation and platform-specific details, see Microsoft’s BitLocker operations guide, recovery overview, and recovery key backup instructions.