Table of Contents

A clean Windows installation erases the selected drive. If the old drive uses BitLocker or Device Encryption, locate its recovery key and copy your files before you start setup. The recovery key protects access to the old encrypted data. A new Windows installation does not restore files erased from the drive.

Key Takeaways

  • Find the right key: Match the recovery key ID shown by Windows to the key stored in your account, printout, or USB backup.
  • Test access: Inspect the backup, match the recovery key ID, and unlock a locked drive before erasing partitions.
  • Protect the backup: Keep the 48-digit key separate from the computer and installer USB.
  • Choose the path: Use recovery options when you need the old installation. Use a clean install only after you verify a separate copy of your files.

Before You Begin

You need access to the affected computer, a second device for checking your account or backup, and an external drive or trusted cloud storage for important files. Time: Key lookup depends on account access. File copying depends on data size. Difficulty: Basic for account lookup, intermediate for recovery tools. This guide covers Windows 10 and Windows 11 preparation and recovery decisions. The Windows clean installation guide covers installation media and setup.

Standard Windows 10 support ended on October 14, 2025. Plan a supported Windows 11 installation when your device meets its requirements. Microsoft lists Windows 10 lifecycle and extended support options .

Warning: Do not delete a partition to fix a BitLocker recovery prompt when you still need files from the old installation. Microsoft states that a reset without the recovery key removes those files. See Microsoft’s recovery-key guidance .

Check Whether Encryption Is Active

Device Encryption and BitLocker encrypt a drive so someone without the proper credentials cannot read its contents. If Windows still starts, open Settings > Privacy & security > Device encryption on Windows 11. On editions with BitLocker management, search Start for Manage BitLocker. Record the encrypted drive letter and the account used to set up the device. Your organization often holds the key for a managed work or school device.

For an optional command-line check, search Start for Command Prompt, select Run as administrator, and enter the following commands. Replace C: if Windows uses a different drive letter. A protector is a method Windows uses to unlock an encrypted drive.

manage-bde.exe -status C:
manage-bde.exe -protectors -get C:

The first command reports encryption, protection, and lock status. The second lists protector types and IDs and might expose the recovery password. Microsoft documents both checks in its BitLocker operations guide and status command reference . Do not paste the output into a help request or screenshot. If the device is already locked, use the key ID displayed on the recovery screen instead. Microsoft says the first eight digits of the ID help you select the matching key.

Where to Find Your BitLocker Recovery Key

The recovery key ID identifies a stored key. The recovery key is the separate 48-digit number entered to unlock the drive. Do not enter the ID in the recovery password field.

Device or backupWhere to look
Personal Microsoft accountOn a second device, sign in through Microsoft’s recovery-key route . Match the ID before using the 48-digit key.
Work or school deviceCheck the organization account through Microsoft’s work or school recovery route , or ask your IT team.
Printed or USB backupFind the printout or text file created when encryption was enabled. Match its key ID to the screen.

Microsoft lists these locations in Find your BitLocker recovery key . Start with the key whose ID matches the prompt. A key from another device or a removed protector might not unlock this volume. If another person set up the device, Microsoft notes that their account might hold the key.

Make a Separate Key Backup

If Windows still starts on a Pro, Enterprise, or Education edition, search for Manage BitLocker. Select Back up your recovery key beside the encrypted drive. Microsoft offers an account backup, a USB drive, a text file on another unencrypted location, or a printout. Read Back Up Your BitLocker Recovery Key for the current interface and options.

On Windows Home, Manage BitLocker is absent. Check Settings > Privacy & security > Device encryption on Windows 11, then verify the key in the Microsoft account used during setup. Microsoft explains that Device Encryption stores the key in the linked Microsoft or work account when it activates. Save a separate protected copy if your setup offers an export method.

Open a digital backup from a second device. For a printed backup, compare the paper with the stored account entry or recovery screen. Match its recovery key ID to the ID shown on the recovery screen or in your protector list. Confirm the backup includes all 48 digits of the associated key. Store a printed or removable copy away from the encrypted computer. A thief with both the computer and recovery key would bypass the drive’s protection, as Microsoft warns in its backup guidance . Avoid attaching the key to a support ticket.

Expected Result: You have a matching recovery key available outside the computer.

Unlock a Computer That Will Not Start

If the BitLocker recovery screen appears, enter the 48-digit key matching its ID. If Windows starts, copy your files before changing partitions. If the key unlocks the drive but Windows still fails to start, use Windows Recovery Environment and try Startup Repair before a reset. Certain recovery tools require the key while the drive is encrypted.

For a file backup from recovery tools, open Troubleshoot > Advanced options > Command Prompt in Windows Recovery Environment. Use manage-bde -status and dir to identify the encrypted Windows volume and a separate external backup drive. Drive letters might differ from normal Windows. Do not copy files to the installer USB or to the encrypted source drive.

manage-bde.exe -status
dir D:\Users
dir E:\

The letters above are examples. After you identify the correct volumes, unlock the Windows volume with the matching key. Replace the example drive letter and placeholder with your own values. Type the actual 48-digit key locally. Do not publish or share the command output.

manage-bde.exe -unlock D: -recoverypassword <48-digit-key>

Microsoft documents the unlock command . Its recovery guidance also describes copying user files to another drive after unlocking. For an illustrative Documents copy, confirm the Windows account name and external-drive letter first, then replace both paths:

xcopy "D:\Users\Name\Documents" "E:\Backup\Documents" /S /E /I /H /V

The /S /E flags include subfolders, including empty ones. /I treats the destination as a folder, /H includes hidden files, and /V checks each written file. Microsoft documents these flags in its xcopy reference . Repeat for other folders you need. Open copied files on another device before erasing the Windows drive. If you cannot identify the volumes or the copy fails, stop and use a trusted recovery specialist.

Decide Whether to Reinstall

A key backup is not a file backup. Follow this order before you choose a reinstall path:

  1. Identify the encrypted drive and its recovery key ID.
  2. Retrieve the matching 48-digit key from your account, printout, or USB backup.
  3. If the drive is locked, unlock it through the recovery screen or recovery tools.
  4. Copy Desktop, Documents, Pictures, and other local folders to an external drive or trusted cloud storage. Include browser exports, application data, and license records as needed.
  5. Open several copied files from a second device.
  6. Choose a repair, reset, or reinstall method only after the backup check.

Expected Result: Your matching key and important files are accessible outside the old Windows installation.

Microsoft lists Windows recovery options with different effects on your files and apps. Many options in Windows Recovery Environment require the recovery key when BitLocker protects the drive. If the volume is locked in Windows Recovery Environment, Keep my files does not unlock the drive without the key.

Startup Repair and System Restore aim to repair the existing installation. Reset this PC has a Keep my files option, but removes apps and settings. Its Remove everything option erases personal files. Starting setup.exe from a running Windows session offers an in-place reinstall with options to keep data. Choosing Install Windows after booting from installation USB starts a clean installation path that removes files, apps, and settings from the selected Windows installation. The same media also offers a repair route. Read the displayed option and target disk before confirming any reset or installation. Microsoft’s reinstall guidance explains both paths.

SituationNext action
Windows starts and you need the filesBack up the files, verify the recovery key, then choose a repair or reinstall method.
Windows asks for the keyMatch the on-screen ID to a stored key before changing the drive.
No matching key and no file backupStop before erasing the drive. Check each account, printout, USB backup, and your IT team.
Files are backed up and you want a clean startFollow Microsoft’s reinstall instructions , then choose the intended target disk with care.

Microsoft states that support staff cannot recreate a lost recovery key. If you cannot find the key, stop changing firmware settings and check all backup locations. Ask your device administrator for help on a managed device. A reset without the needed key removes the old files. A clean install also removes personal files, apps, device customizations, and settings from the selected installation. Treat those outcomes as a deliberate decision after your backup check.

Troubleshooting

  • The key does not work: Recheck the key ID and the account. A device can have more than one stored recovery key.
  • Manage BitLocker is unavailable: Windows Home uses Device Encryption on eligible devices. Check Settings and the Microsoft account used for setup.
  • Several keys appear in one account: Match the first eight digits of the recovery screen’s key ID to the stored entries. Do not try keys based only on a device name.
  • The key unlocks the drive but Windows fails to start: Try Startup Repair from Windows Recovery Environment. Back up accessible files before a reset or clean install.
  • The key is held by work or school: Contact the device administrator before resetting or reinstalling it.
  • The key file is on the locked computer: Look for a separate account, printout, or removable backup. A copy stored only on the encrypted drive does not help while it is locked.
  • The recovery prompt appeared after a firmware change: Record the change and stop making firmware changes. Find the matching key or contact your device administrator.

Next Steps

After you verify the key and files, follow the Windows clean installation guide if a clean install fits your goal. Once Windows starts, check Settings > Privacy & security > Device encryption or search for Manage BitLocker. On Pro, Enterprise, or Education, select Back up your recovery key in Manage BitLocker. On Home, verify the linked account contains the current key and save a separate copy if Windows offers an export option. Do not assume the old key applies to a newly encrypted installation.