Solved Undone by Bitlocker


Catnip

Forum Nitwit
Power User
VIP
Local time
4:08 PM
Posts
798
OS
Win 11 Pro 25H2
I have an issue. The IT department where I work decided to install Bitlocker on my PC without telling me. I went ahead and did a BIOS upgrade. Guess what? Bitlocker locked me out. No big deal, except that IT didn't give me the key and someone screwed up and didn't record it anywhere.

I know I am screwed.

I had a thought. Can I boot from a Linux live disk and get at the drive that way? I just need some vital files off of it. The rest is just a Windows 11 installation that I have already reinstalled to a new drive.

I know of no other way. I heard that I could get the information from my Microsoft account, but guess what else IT didn't record? I can't find my user name and I can't find the notation where I at least wrote it down.

Like I said, I am profoundly screwed, and not in the way I like to be. I hope someone can help.
 
Windows Build/Version
Win 11 Pro 25H2

My Computer

System One

  • OS
    Win 11 Pro 25H2
    Computer type
    PC/Desktop
    Manufacturer/Model
    Self build
    CPU
    Intel i7 13700KF
    Motherboard
    Gigabyte Z790 UD AC
    Memory
    32 GB Team Group DDR5 - 6000 CL 30
    Graphics Card(s)
    ASUS TUF GAMING RTX 3070 Ti
    Sound Card
    On board Realtek
    Monitor(s) Displays
    ACER 34 inch
    Screen Resolution
    4K
    Hard Drives
    1 TB Samsung 980 Pro Nvme, 1 TB Samsung 970 EVO Nvme, 2 x Samsung 970 2TB SSD SATA
    PSU
    EVGA 1000Q
    Case
    Rosewill something or other
    Cooling
    Noctua NH-D15. A whole schwak of Noctua case fans. $$$
    Keyboard
    Logitech G815
    Mouse
    Logitech G502 Hero
    Internet Speed
    700 up, 600 down
    Browser
    Firefox
    Antivirus
    MalwareBytes
I can't help you but it sounds like your IT department needs to be taken out back behind the barn. My condolences.
 

My Computer

System One

  • OS
    Windows 11 Professional 25H2
    Computer type
    PC/Desktop
    Manufacturer/Model
    Digital Storm VELOX
    CPU
    Intel Core i9 11900K
    Motherboard
    ASUS PRIME Z590-P
    Memory
    64GB
    Graphics Card(s)
    NVIDIA GeForce GTX 1650
    Sound Card
    Realtek onboard
    Monitor(s) Displays
    Acer R221Q 21.5"
    Screen Resolution
    1920 x 1080
    Hard Drives
    2 x Samsung SSD 990 EVO Plus (1 TB)
    2 x Seagate ST4000NE001 (4 TB)
    PSU
    None
    Case
    VELOX
    Cooling
    Cooler Master
    Keyboard
    Logitech
    Mouse
    Kensington trackball
    Browser
    Firefox, Chrome
    Antivirus
    Windows Defender, Malwarebytes
Depending upon how it was configured (if it was done correctly) it will be stored in Active Directory or in Azure. This assumes they used proper tooling (MBAM, MECM or Intune). Less common they stored in a network share. if they did indeed not back it up then you are SOL.

If you can downgrade the BIOS perhaps there's a chance.
 

My Computer

System One

  • OS
    Linux Mint
    Computer type
    Laptop
    Manufacturer/Model
    System76 Lemur Pro
A competent IT staff would have warned you to temporarily suspend BitLocker, before attempting any BIOS updates.

BitLocker checks some of the BIOS markers to determine if you've "moved" the drive to a different PC. By suspending BitLocker, you could reboot even if the BIOS update changed those markers. This sounds like a tragedy.
 

My Computer

System One

  • OS
    Windows 7
So IT takes responsibility for whether or not Bitlocker is on, but not if you should update your BIOS?

Sounds like someones Nephew got a job as Uncles IT dept.
 
Last edited:

My Computers

System One System Two

  • OS
    Windows 11 Pro 25H2 Build 26200.8655
    Computer type
    PC/Desktop
    Manufacturer/Model
    Sin-built 2013
    CPU
    Intel(R) Core(TM) i7-4770K CPU @ 3.50GHz
    Motherboard
    ASUS ROG Maximus VI Formula
    Memory
    32.0 GB of I forget and the box is in storage.
    Graphics Card(s)
    Gigabyte nVidia GeForce GTX 1660 Super OC 6GB
    Sound Card
    Onboard thingy
    Monitor(s) Displays
    5 x LG 25MS500-B - 1 x 24MK430H-B - 1 x Wacom Pro 22" Touch Screen Tablet
    Screen Resolution
    All over the place
    Hard Drives
    Too many to list.
    OS on Samsung 1TB 870 QVO SATA
    PSU
    Silverstone 1500
    Case
    NZXT Phantom 820 Full-Tower Case
    Cooling
    Noctua NH-D15 Elite Class Dual Tower CPU Cooler / 6 x EziDIY 120mm / 2 x Corsair 140mm somethings / 1 x 140mm Thermaltake something / 2 x 200mm Corsair.
    Keyboard
    Corsair K95 / Logitech diNovo Edge Wireless
    Mouse
    Logitech: G402 / G502 / Mx Masters / Mx Air Cordless
    Internet Speed
    2000/500Mbps
    Browser
    All sorts
    Antivirus
    Kaspersky Premium
    Other Info
    ㅤㅤㅤㅤㅤㅤㅤㅤㅤㅤㅤㅤㅤㅤㅤㅤㅤㅤㅤㅤㅤㅤㅤㅤㅤㅤㅤㅤㅤㅤㅤㅤㅤㅤㅤㅤㅤㅤㅤㅤ⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀
    TP-Link BE9300 WiFi 7 Bluetooth 5.4 (Archer TBE550E)
    TP-Link TX201 V1 2.5GB Lan

    Grandstream HT812 - VoIP
    ASUS DSL-AX82U - Mesh
    ASUS RT-AC68U - Mesh
    ASUS RT-BE88U Router

    Brother MFC-L2880DW Printer

    I’m on a horse.
  • Operating System
    Windows 11 Pro 25H2 Build 26200.8655
    Computer type
    Laptop
    Manufacturer/Model
    LENOVO Yoga 7 14IRL8 - 7i EVO OLED 14" Touchscreen i5 12 Core 16GB/512GB
    CPU
    Intel Core 12th Gen i5-1240P Processor (1.7 - 4.4GHz)
    Memory
    16GB LPDDR5 RAM
    Graphics card(s)
    Intel Iris Xe Graphics Processor
    Sound Card
    Optimized with Dolby Atmos®
    Screen Resolution
    QHD 2880 x 1800 OLED
    Hard Drives
    M.2 512GB
    Antivirus
    Defender / Malwarebytes
    Other Info
    …still on a horse.
If a user where I work took it upon themselves to do this, we'd be like, "well, here's a replacement laptop," and we'd take the old one.

We had an instructor, years ago, who taught PC repair classes. He somehow had a recovery CD or DVD from the manufacturer and left it in the drive. Some time later, he rebooted his PC, it booted off the optical disc, and he wiped his drive and re-installed Windows. Good times were had by all, well except him.
 

My Computer

System One

  • OS
    Windows 11 Pro 25H2
    Computer type
    PC/Desktop
    Manufacturer/Model
    Intel NUC12WSHi7
    CPU
    12th Gen Core i7-1260P
    Motherboard
    NUC12WSBi7
    Memory
    64 GB Micron PC4-25600
    Graphics Card(s)
    Intel Iris Xe Graphics
    Sound Card
    on-board Realtek HD Audio
    Monitor(s) Displays
    Dell U3219Q
    Screen Resolution
    3840 x 2160
    Hard Drives
    Samsung SSD 990 PRO 1TB
    Crucial MX500 2 TB
    Antivirus
    Microsoft Defender
No big deal, except that IT didn't give me the key and someone screwed up and didn't record it anywhere.
Your IT sucks. If it is managed by active directory or intune or entra there are a lot of ways to retrieve it.

Try holding down the power for 30 full seconds at the bitlocker screen and then turn it back on. See if it suddenly doesn't ask for the bitlocker key. I have seen this before when it asks and then it randomly decides it doesnt need to anymore.

A competent IT staff would have warned you to temporarily suspend BitLocker, before attempting any BIOS updates.

BitLocker checks some of the BIOS markers to determine if you've "moved" the drive to a different PC. By suspending BitLocker, you could reboot even if the BIOS update changed those markers. This sounds like a tragedy.

Bios updates could be allowed by corporate IT and the local IT has no say in the matter. Ask me how I know. In any case, every known mainstream brand that I know of suspends bitlocker before updating the bios automatically so that this does not happen.
 

My Computers

System One System Two

  • OS
    Windows 11 Pro
    Computer type
    PC/Desktop
    Manufacturer/Model
    Custom Built
    CPU
    Ryzen 7 5700 X3D
    Motherboard
    MSI MPG B550 GAMING PLUS
    Memory
    64 GB DDR4 3600mhz Gskill Ripjaws V
    Graphics Card(s)
    RTX 4070 Super , 12GB VRAM Asus EVO Overclock
    Monitor(s) Displays
    Gigabyte M27Q (rev. 2.0) 2560 x 1440 @ 170hz HDR
    Hard Drives
    2TB Samsung nvme ssd
    4TB Western Digital nvme ssd
    PSU
    CORSAIR RMx SHIFT Series™ RM750x 80 PLUS Gold Fully Modular ATX Power Supply
    Case
    CORSAIR 3500X ARGB Mid-Tower ATX PC Case – Black
    Cooling
    ID-COOLING FROSTFLOW X 240 CPU Water Cooler
    Keyboard
    Logitech G213
    Mouse
    Logitech G203
    Internet Speed
    1.2gbps Fiber 😎
  • Operating System
    Chrome OS
    Computer type
    Laptop
    Manufacturer/Model
    HP Chromebook
    CPU
    Intel Pentium Quad Core
    Memory
    4GB LPDDR4
    Monitor(s) Displays
    14 Inch HD SVA anti glare micro edge display
    Hard Drives
    64 GB emmc
In any case, every known mainstream brand that I know of suspends bitlocker before updating the bios automatically so that this does not happen.
Yep but typically if it’s done through the OEM tools, like Dell Command | Update. If the user goes off half-cocked and does it incorrectly, not so much.
 

My Computer

System One

  • OS
    Windows 11 Pro 25H2
    Computer type
    PC/Desktop
    Manufacturer/Model
    Intel NUC12WSHi7
    CPU
    12th Gen Core i7-1260P
    Motherboard
    NUC12WSBi7
    Memory
    64 GB Micron PC4-25600
    Graphics Card(s)
    Intel Iris Xe Graphics
    Sound Card
    on-board Realtek HD Audio
    Monitor(s) Displays
    Dell U3219Q
    Screen Resolution
    3840 x 2160
    Hard Drives
    Samsung SSD 990 PRO 1TB
    Crucial MX500 2 TB
    Antivirus
    Microsoft Defender
Yep but typically if it’s done through the OEM tools, like Dell Command | Update. If the user goes off half-cocked and does it incorrectly, not so much.
Gotcha, ours are done through windows update. And any oem ones I have tried so far, (dell and hp) suspend correctly so you can't screw it up. I never used dell command update though. Just either bios update from windows update or via support website manually
 

My Computers

System One System Two

  • OS
    Windows 11 Pro
    Computer type
    PC/Desktop
    Manufacturer/Model
    Custom Built
    CPU
    Ryzen 7 5700 X3D
    Motherboard
    MSI MPG B550 GAMING PLUS
    Memory
    64 GB DDR4 3600mhz Gskill Ripjaws V
    Graphics Card(s)
    RTX 4070 Super , 12GB VRAM Asus EVO Overclock
    Monitor(s) Displays
    Gigabyte M27Q (rev. 2.0) 2560 x 1440 @ 170hz HDR
    Hard Drives
    2TB Samsung nvme ssd
    4TB Western Digital nvme ssd
    PSU
    CORSAIR RMx SHIFT Series™ RM750x 80 PLUS Gold Fully Modular ATX Power Supply
    Case
    CORSAIR 3500X ARGB Mid-Tower ATX PC Case – Black
    Cooling
    ID-COOLING FROSTFLOW X 240 CPU Water Cooler
    Keyboard
    Logitech G213
    Mouse
    Logitech G203
    Internet Speed
    1.2gbps Fiber 😎
  • Operating System
    Chrome OS
    Computer type
    Laptop
    Manufacturer/Model
    HP Chromebook
    CPU
    Intel Pentium Quad Core
    Memory
    4GB LPDDR4
    Monitor(s) Displays
    14 Inch HD SVA anti glare micro edge display
    Hard Drives
    64 GB emmc
Who does the computer belong to?
 

My Computers

System One System Two

  • OS
    Windows 11 Pro 25H2 26200.8655
    Computer type
    Laptop
    Manufacturer/Model
    Acemagic LX15PRO
    CPU
    AMD Ryzen 7 5825U with Radeon Graphics
    Memory
    16GB
    Screen Resolution
    1920 x 1080
    Hard Drives
    SSD 2TB
    Internet Speed
    30 Mbps
    Browser
    Brave
    Antivirus
    Webroot Secure Anywhere
    Other Info
    System 3

    Acer Swift SF114-34 laptop
    OS Windows 11 Pro 26200.8524
    CPU Pentium Silver N6000
    RAM 4GB
    SSD Samsung 970 EVO Plus SSD 2TB (an upgrade)
  • Operating System
    Windows 11 Pro 23H2 22631.2506
    Computer type
    Laptop
    Manufacturer/Model
    HP Mini 210-1090NR PC (bought in late 2009!)
    CPU
    Atom N450 1.66GHz
    Memory
    2GB
    Browser
    Brave
    Antivirus
    Webroot
I tried everything that people suggested in this thread with no success, however, IT found my key in a filing cabinet after I screamed bloody murder at them, so horribleness avoided. I have unlocked the drive and cloned it like I wanted to in the first place.

So all is well.

Thank you to all who replied with suggestions. I really appreciate the help.

Who does the computer belong to?

It belongs to work, but the responsibility for its upkeep belongs to me for most things. If I had known they were putting Bitlocker on my PC, I would have prevented it. I keep a pretty good lockdown on my PC as far as IT goes, but I guess one of the junior guys decided to "improve" my PC. :confused:

He won't do that again. I am a nasty lady when I want to be.
 

My Computer

System One

  • OS
    Win 11 Pro 25H2
    Computer type
    PC/Desktop
    Manufacturer/Model
    Self build
    CPU
    Intel i7 13700KF
    Motherboard
    Gigabyte Z790 UD AC
    Memory
    32 GB Team Group DDR5 - 6000 CL 30
    Graphics Card(s)
    ASUS TUF GAMING RTX 3070 Ti
    Sound Card
    On board Realtek
    Monitor(s) Displays
    ACER 34 inch
    Screen Resolution
    4K
    Hard Drives
    1 TB Samsung 980 Pro Nvme, 1 TB Samsung 970 EVO Nvme, 2 x Samsung 970 2TB SSD SATA
    PSU
    EVGA 1000Q
    Case
    Rosewill something or other
    Cooling
    Noctua NH-D15. A whole schwak of Noctua case fans. $$$
    Keyboard
    Logitech G815
    Mouse
    Logitech G502 Hero
    Internet Speed
    700 up, 600 down
    Browser
    Firefox
    Antivirus
    MalwareBytes
A company may have legitimate concerns about data privacy, which results in BitLocker as a standard policy.

But at a minimum, they should have sent you the standard "please make a BitLocker USB recovery drive, or print out the recovery key" instructions. That's the norm when IT follows a service model where they don't control a PC 100% of the time.
 

My Computer

System One

  • OS
    Windows 7
It belongs to work, but the responsibility for its upkeep belongs to me for most things

That's a mighty weird IT department that delegates the upkeep of work-owned computers to the users but just happens to implement Bitlocker without telling you. I work for a bank and our laptops are locked down tighter than a drum. Nothing happens to them that isn't initiated by desktop support.
 

My Computer

System One

  • OS
    Windows 11 Professional 25H2
    Computer type
    PC/Desktop
    Manufacturer/Model
    Digital Storm VELOX
    CPU
    Intel Core i9 11900K
    Motherboard
    ASUS PRIME Z590-P
    Memory
    64GB
    Graphics Card(s)
    NVIDIA GeForce GTX 1650
    Sound Card
    Realtek onboard
    Monitor(s) Displays
    Acer R221Q 21.5"
    Screen Resolution
    1920 x 1080
    Hard Drives
    2 x Samsung SSD 990 EVO Plus (1 TB)
    2 x Seagate ST4000NE001 (4 TB)
    PSU
    None
    Case
    VELOX
    Cooling
    Cooler Master
    Keyboard
    Logitech
    Mouse
    Kensington trackball
    Browser
    Firefox, Chrome
    Antivirus
    Windows Defender, Malwarebytes

My Computers

System One System Two

  • OS
    Debian 13 KDE .. Windows 11 Home
    Computer type
    PC/Desktop
    Manufacturer/Model
    HP 24" AiO
    CPU
    Ryzen 7 5825u
    Motherboard
    HP
    Memory
    64GB DDR4 3200
    Graphics Card(s)
    Ryzen 7 5825u
    Sound Card
    RealTek
    Monitor(s) Displays
    24" HP AiO
    Screen Resolution
    1920 x 1080 @60 Hz
    Hard Drives
    1TB WD Blue SN580 M2 SSD Partitioned.
    2x 1TB USB HDD External Backup/Storage.
    PSU
    90W external power brick
    Case
    24" All in One
    Cooling
    Default Air Cooling
    Keyboard
    HP WiFi UK extended
    Mouse
    HP WiFi 3 Button
    Internet Speed
    1GB full fibre
    Browser
    Edge & Firefox
    Antivirus
    AVG Internet Security/Windows Defender
    Other Info
    Mainly Open Source Software
  • Operating System
    Ubuntu 22.04.5 LTS
    Computer type
    Laptop
    Manufacturer/Model
    Dell 13" Latitude 2017
    CPU
    i5 7200u
    Motherboard
    Dell
    Memory
    16GB DDR4
    Graphics card(s)
    Intel
    Sound Card
    Intel
    Monitor(s) Displays
    13" Dell Laptop
    Hard Drives
    250GB Crucial 2.5" SSD
    Mouse
    Generic WiFi 3 button
    Internet Speed
    WiFi only
    Browser
    Firefox
    Antivirus
    ClamAV TK
    Other Info
    Mainly Open Source Software
That's a mighty weird IT department that delegates the upkeep of work-owned computers to the users but just happens to implement Bitlocker without telling you. I work for a bank and our laptops are locked down tighter than a drum. Nothing happens to them that isn't initiated by desktop support.
I work for a mighty weird company. I finally had to put my foot down and prevent IT from touching my computer because the junior guys keep messing up my machine and the experienced guys won't touch it because that's a junior level job. I handle almost everything for it except networking and some hard to implement security. Occaisonally, I run into an issue. I come here first before I ask IT for anything. It's easier and i usually don't have to yell at anyone.
 

My Computer

System One

  • OS
    Win 11 Pro 25H2
    Computer type
    PC/Desktop
    Manufacturer/Model
    Self build
    CPU
    Intel i7 13700KF
    Motherboard
    Gigabyte Z790 UD AC
    Memory
    32 GB Team Group DDR5 - 6000 CL 30
    Graphics Card(s)
    ASUS TUF GAMING RTX 3070 Ti
    Sound Card
    On board Realtek
    Monitor(s) Displays
    ACER 34 inch
    Screen Resolution
    4K
    Hard Drives
    1 TB Samsung 980 Pro Nvme, 1 TB Samsung 970 EVO Nvme, 2 x Samsung 970 2TB SSD SATA
    PSU
    EVGA 1000Q
    Case
    Rosewill something or other
    Cooling
    Noctua NH-D15. A whole schwak of Noctua case fans. $$$
    Keyboard
    Logitech G815
    Mouse
    Logitech G502 Hero
    Internet Speed
    700 up, 600 down
    Browser
    Firefox
    Antivirus
    MalwareBytes
It sure is a mystery why the experienced staff wouldn't work on your machine.
 

My Computer

System One

  • OS
    Windows 11 Pro 25H2
    Computer type
    PC/Desktop
    Manufacturer/Model
    Intel NUC12WSHi7
    CPU
    12th Gen Core i7-1260P
    Motherboard
    NUC12WSBi7
    Memory
    64 GB Micron PC4-25600
    Graphics Card(s)
    Intel Iris Xe Graphics
    Sound Card
    on-board Realtek HD Audio
    Monitor(s) Displays
    Dell U3219Q
    Screen Resolution
    3840 x 2160
    Hard Drives
    Samsung SSD 990 PRO 1TB
    Crucial MX500 2 TB
    Antivirus
    Microsoft Defender
Back
Top Bottom