In a fresh development, this doesn't affect our editorial independence. When you purchase through links in our articles, we may earn a small commission.

Industry observers note that under the name Device Encryption, it also became part of the Home editions with Windows 10, and since Windows 11 24H2 it has even been enabled by default. In the Pro editions of Windows, the BitLocker hard drive encryption capability has been included since Windows Vista.

Industry observers note that however, without this 48-digit code, you will no longer have any access to your data on the hard drive! This is problematic because not all users are aware of this, and the system may suddenly demand the recovery key — for example, following a UEFI patch.

As part of the ongoing story, to ensure that this worst-case scenario does not happen to you under any circumstances, you should make sure to back up the recovery key in good time. You will then be locked out, regardless of whether you try to boot the computer from the hard drive or via an alternative system from an external storage device.

The report highlights that if you’re signed in with a Microsoft account, you can still retrieve the code via that account at a later date. Here’s how: In the Home editions of Windows 10 and 11, the hard drive may be encrypted even if you haven’t enabled the capability yourself. This is particularly important if you’re using device encryption on a computer with a local user account!

In a fresh development, you can check this by clicking on ‘Privacy and security > Device encryption’ in the Settings app. If the ‘Device encryption’ option is enabled, open the address https://aka.ms/myrecoverykey in your browser and sign in with your Microsoft account. Specifically, this happens whenever you use a Microsoft account as intended during the initial setup.

The report highlights that this will allow you to access the code later on another computer. Tip: If you use different computers with the same Microsoft account, or have done so in the past, all of these devices will appear in the online list. Now make a note of the key ID and the recovery key.

As part of the ongoing story, please note that the individual partitions are encrypted separately and therefore require different recovery keys to decrypt them. The abbreviation OSV (Operating System Volume) refers to the system drive, while FDV (Fixed Data Volume) refers to other data drives. This makes it more difficult to find the correct key; in some cases, the only solution is to try them out one by one!

Industry observers note that first, without an online account, there is no automatic backup. Second, the Home Edition of Windows offers no obvious option for saving the key: The ability to print it out or transfer it to a USB stick, as is possible with BitLocker in the Pro version, is missing here. It becomes risky if you are suddenly asked for the recovery key without a Microsoft account.

According to the latest update, this is because the system then suggests, in a message highlighted in yellow, that an online account is required to encrypt the hard drive. But that’s not true; in fact, encryption starts automatically in the background as soon as the device is switched on! Furthermore, users of local accounts are effectively misled when enabling device encryption.

Industry observers note that do not be lulled into a false sense of security by the entry under ‘Protection status’, which suggests that (hard drive) protection is disabled — this is definitely incorrect. You can see this by launching the Command Prompt (cmd) with administrator rights, typing the command manage-bde.exe -status C: and pressing the Enter key.

The report highlights that to save it, type the command manage-bde.exe -protectors -get C: into the open Command Prompt and press the Enter key again. It is therefore absolutely vital to back up the key you are using in case you ever need it to decrypt the volume and regain access to your stored data.

The report highlights that select this with the mouse, copy it to the clipboard, and then print it out and/or save it to a USB stick. Please keep the printout and the USB stick in a secure yet easy-to-remember place. The 48-character key — referred to here as the ‘password’ — will then appear below the ID mentioned earlier.

In a fresh development, this article originally appeared on our sister publication PC-WELT and was translated and localized from German.

The report highlights that he is also very knowledgeable about energy, photovoltaics and the like. Peter Stelzel-Morawietz enjoys tinkering and writes on all topics related to Windows, programs, internet, telecommunications, consumer protection and DIY.