How to Recover your BitLocker Key
What is BitLocker? BitLocker is Microsoft’s encryption program for Windows and provides devices with an added layer of security. It is used to encrypt hard drives to help protect a user’s data from unauthorized access or changes. All IST managed devices (aka machines) are encrypted before they are provided to users however BitLocker encryption is optional for personal devices.
How does BitLocker work? In the background, BitLocker checks the computer during startup for any conditions that could represent a security risk (for example, a change to the BIOS or changes to any startup files). If a potential security risk is detected, BitLocker will lock the operating system drive and require a special BitLocker recovery key to unlock it. The unlocking of BitLocker will allow the device to become usable again
BitLocker recovery keys are self-serve (see instructions below for SCCM or Intune) or users can contact the IST Service Desk.
If a potential security risk is detected, BitLocker will lock the operating system drive and require a special BitLocker recovery key to unlock it. If you have access to another computer or mobile device, you can obtain the recovery key yourself. If not, please contact the IST Service Desk.
You must have logged in to your encrypted laptop at least once with your 8-character UWaterloo username (e.g. j25rober).
SCCM managed computers - From an unlocked computer or mobile device:
In a web browser, navigate to https://spartacus.nexus.uwaterloo.ca/selfservice/. Note that this requires a VPN connection if you are not connected to the campus network. (Please see https://uwaterloo.atlassian.net/wiki/spaces/ISTKB/pages/262012980 for more information about VPN. )
Log on with your UWaterloo credentials (your 8-character UWaterloo username and password)
After reading the Security Notice, click the checkbox beside ‘I have read and understand the above notice‘
Select Continue
Enter the first 8 characters of the 32-digit code into the Recovery Key ID field. (This code should be displayed on the BitLocker recovery screen on your locked computer.)
Select the Reason for needing to recover the key
Select Get Key
You should receive a 48-digit Bitlocker Recovery Key
Enter this key into the Recovery Key field on the locked computer
Unable to enter the recover code? The Recovery key may need to be entered using the “F” keys at the top of the keyboard (e.g. F1, F2, etc.) instead of the usual number keys. The hyphens/dashes between every group of 6-digits will appear automatically.
Intune managed computers - From an unlocked computer or mobile device:
User Self-Service Recovery (Preferred Method)
Recover via Microsoft Account or Entra ID
On another device, go to:
🔗My Account
Sign in with the same work or school account used on the encrypted device.
Select the device name in the list.
Click View BitLocker keys — this displays the recovery key ID and the 48-digit recovery key.
💡 Tip: Users should match the Key ID shown on the BitLocker recovery screen with the one shown online to ensure they select the correct key.
IT Admin Recovery (If user cannot access their key)
Admins can retrieve the BitLocker recovery key via:
🔹 Microsoft Intune admin center:
Go to Intune admin center → Devices → All devices.
Select the affected device.
Under Monitor, select Recovery keys.
The BitLocker recovery key will be displayed (if backup succeeded).
🔹 Microsoft Entra admin center:
Go to Entra admin center → Devices → All devices.
Select the device → BitLocker keys → view or copy the recovery key.
🔸 You must have at least Cloud Device Administrator or Helpdesk Administrator permissions to view BitLocker keys in Entra.
During Recovery on the Device
When prompted for the recovery key on the locked system:
Type or paste the 48-digit numeric recovery key into the recovery screen.
Once verified, Windows will unlock the drive and continue booting.
Related articles
Need help?
Contact the IST Service Desk online or 519-888-4567 ext. 44357.
Article feedback
If you’d like to share any feedback about this article, please let us know.