Certified Phone Repair & Data Recovery Mail-In Service
Over 15 Years of Professional Experience and 600+
Reviews
PayPal 0% Financing
Locked out of intact data

BitLocker Asks for Recovery Key After Hotpatch KB5120994

After the August hotpatches KB5120994 and KB5123607, Windows 11 devices prompt for the BitLocker key on restart, and the Windows Hello PIN sometimes fails.

BitLocker recovery key after the August hotpatch KB5120994: when your PC suddenly locks you out

Since 21 August 2026, administrators have been reporting that Windows 11 devices unexpectedly demand the 48-digit BitLocker recovery key at the next restart after the hotpatches KB5120994 and KB5123607. In some cases the Windows Hello PIN is no longer available afterwards either. As things stand, the data on the drive is intact – but without the right key, nobody can get to it.

That is the crucial distinction in this incident: this is not a defective SSD or hard drive, and these are not deleted files. This is a cryptographic loss of access – the drive is encrypted, and the key that Windows normally uses to unlock it automatically at startup no longer works. Anyone who panics now and reinstalls the system or resets the TPM turns a solvable access problem into permanent data loss.

What exactly happened?

On 11 August 2026, Microsoft released the security hotpatch KB5120994 for Windows 11 24H2 and 25H2 (OS builds 26100.9106 and 26200.9106). The same day saw the release of KB5123607, a standalone security update exclusively for hotpatch-enrolled devices which, according to Microsoft, is designed to take effect without a restart. The release notes for both updates state explicitly:

“Microsoft is not currently aware of any issues with this update.” – Microsoft Support, KB5120994 and KB5123607

On 21 August 2026, a thread in the Intune forum on Reddit then documented a striking sequence of events on individual devices: hotpatch installed – restart later – unexpected BitLocker recovery prompt – after entering the correct key, Windows does start, but signing in with Windows Hello for Business (WHfB) via PIN no longer works in some cases. Several commenters reported similar isolated incidents. The original poster explicitly ruled out changed BIOS and TPM versions in his environment.

Important context: these are anecdotal user reports, not proof of causality. As of 22 August 2026 there is neither confirmation from Microsoft nor an entry in the Release Health dashboard for Windows 11 25H2 – the only issue documented there after the August update is a different, gaming-related one. There is no official number of affected users, no confirmed list of models and no failure rate. The Reddit thread mentions “some devices”, “a handful of devices” or “3 or 4” cases – figures that have not been independently verified and cannot be added up.

Why does BitLocker ask for the recovery key in the first place?

BitLocker encrypts the entire drive and unlocks it at startup using a key held in the TPM – a separate security chip on the motherboard. If the security measurements taken at startup deviate from the expected state, BitLocker refuses to unlock automatically. That is a protective function, not a fault and not a sign of damaged data.

“The following list provides examples of common events that cause a device to enter BitLocker recovery mode when starting Windows: Turning off, disabling, deactivating, or clearing the TPM; TPM self-test failure; upgrading critical early startup components, such as a BIOS or UEFI firmware upgrade; [and] modifying the Platform Configuration Registers (PCRs) used by the TPM validation profile.” – Microsoft Learn, BitLocker recovery overview

Nowhere does Microsoft state that KB5120994 or KB5123607 reset a TPM, break the BitLocker binding or damage the WHfB container. The causes discussed in the forum – TPM state, Secure Boot certificates, firmware state – remain unconfirmed hypotheses.

Is my device affected?

Based on the reports available so far, the following may be affected:

  • Windows 11 24H2 and 25H2 on hotpatch-enrolled enterprise devices
  • Installed updates KB5120994 (OS builds 26100.9106 / 26200.9106) and, subsequently, KB5123607
  • Devices with BitLocker and Windows Hello for Business enabled

No particular hardware or model range has been confirmed for this incident. Microsoft currently documents no affected firmware versions.

The separate HP case – please don’t confuse the two

In parallel, there is a separate, documented manufacturer case: on 11 May 2026, HP published a notice about BitLocker recovery loops following certain BIOS updates from early April 2026. According to HP, this affects all HP Commercial Notebooks, HP Commercial Desktops and HP Workstation Computers running Windows 11 23H2, 24H2 and 25H2.

“A BitLocker recovery screen may appear on next boot after updating a computer with BIOS updates released in early April 2026.” – HP Support

The cause there was failed Secure Boot 2023 certificate updates – not the August hotpatches. For checking, HP cites the registry values UEFICA2023Status and UEFICA2023Error as well as minimum BIOS versions. That should be checked exclusively by IT following HP’s instructions, not by the user in the BIOS. Also separate from this: on 14 April 2026, Microsoft had already addressed a different bug with KB5083769 in which devices ended up in BitLocker recovery after Secure Boot updates.

How do I recognise the BitLocker and Windows Hello lockout?

  • After the hotpatch is installed, the BitLocker recovery screen appears unexpectedly at the next restart or power-on.
  • After entering the correct 48-digit recovery key, Windows initially starts normally according to the original report.
  • Afterwards, Windows Hello for Business with PIN is partly unavailable; the interface reports, in effect, that a problem has occurred and the PIN is not available.
  • According to the user report, another restart only fixes the PIN issue on some of the devices.
  • The poster additionally reports that the devices remained visible in Microsoft Defender but could no longer be reached via Intune. This too has not been independently confirmed.

How to check safely whether you are affected

  1. Do not tamper with BIOS, UEFI or TPM. On the BitLocker screen, first note down or photograph the first eight characters of the recovery key ID displayed.
  2. Look for the matching key from another device: for privately managed devices at aka.ms/myrecoverykey, for work or school devices at aka.ms/aadrecoverykey or via the responsible IT department.
  3. Compare the key ID before you enter the 48-digit key.
  4. If Windows starts after correct entry, check whether the PIN is available under the sign-in options. If “I forgot my PIN” is visible, that may be the supported route for a Microsoft account; otherwise sign in with your password.
  5. For managed devices, IT should check whether the device is enrolled for hotpatching and whether KB5120994 / KB5123607 were installed or offered – and document BIOS, TPM and Secure Boot changes since the last trouble-free startup.

What you should do now

  1. Stay calm. A single recovery prompt does not mean your files are damaged or deleted.
  2. Only enter the matching recovery key. Look for it exclusively via your own Microsoft account, your work/school account, a printout, a secured USB stick or your IT department. Never pass the 48-digit key on to third parties – it unlocks the entire drive.
  3. For company, school or managed devices, contact IT first. Only they can retrieve the key from the organisation’s account and assess the update, TPM and Secure Boot situation.
  4. If Windows starts: back up immediately. Copy important data to a separate storage medium before anything else is changed. Only then have the PIN reset checked via the sign-in options.
  5. No further updates, no firmware updates, no configuration changes while the device is in this state.

If you cannot find the key, or the device no longer boots at all: leave the device alone from this point on and have the case assessed by professionals. Every further attempt makes the starting position worse.

What you must never do

This section is the most important part of the entire article. With an encrypted drive, it is almost always the well-intentioned “repair attempts” that turn a lockout into permanent loss.

  • “Reset this PC” or a fresh installation – never as a first step. In the Reddit thread, a complete reinstallation is named as the only measure that has reliably worked so far. It produces a working system – but Microsoft explicitly points out that a reset removes all files. Your data is gone afterwards. A usable notebook is no substitute for ten years of accounting records.
  • Clearing or resetting the TPM. Microsoft warns unambiguously: “Clearing the TPM causes you to lose all created keys associated with the TPM, and data protected by those keys, such as a virtual smart card or a sign-in PIN.” (Microsoft Learn, Troubleshoot the TPM). On work or school devices this must never be done without instructions from IT.
  • Deleting the Windows Hello container with certutil -deleteHelloContainer without having alternative sign-in methods ready first. Microsoft: “On the latest versions of Windows 11, running the certutil -deletehellocontainer command clears not only Windows Hello for Business, but also any passkeys stored on that Windows device.” While this does not demonstrably delete BitLocker data, it can cost you access to further accounts.
  • Random changes to BIOS, UEFI, Secure Boot, TPM or boot configuration. These are precisely the interventions Microsoft lists as typical triggers of a BitLocker recovery prompt. HP additionally warns of recovery errors if Secure Boot certificates are changed without suspending BitLocker. Doing so hampers root cause analysis and potentially your access.
  • Repeated boot attempts and “trying out” the wrong keys. Check the key ID first, then enter it.

And one point that cannot be repeated often enough: without the correct recovery key, nobody can open the drive – not even the manufacturer.

“Microsoft Support doesn't have the ability to retrieve, provide, or recreate a lost BitLocker recovery key.” – Microsoft Support, Find your BitLocker recovery key

Experience shows that it is precisely these hasty do-it-yourself attempts – resetting, clearing the TPM, “having a quick look” in the BIOS – that ultimately make data unrecoverable. In these cases the drive itself is perfectly healthy.

Is there a fix from Microsoft?

No. As of 22 August 2026, for the reported combination of BitLocker recovery followed by an unavailable Windows Hello PIN after KB5120994 / KB5123607, there is no official fix, no recall and no confirmation from the manufacturer. Neither KB page lists any known issues, and neither does the Release Health dashboard. A specific uninstallation, a firmware version or a universal workaround therefore cannot responsibly be recommended.

The officially documented route is: find the recovery key, unlock Windows, back up your data, then reset the PIN via the designated sign-in options. HP’s remedy for the Secure Boot case applies exclusively to the BIOS case described there and is not a fix for the hotpatch reports.

Why this case belongs in professional hands – and how RESQ specifically helps

A BitLocker lockout is fundamentally different from a defective hard drive. The electronics work, the SSD is healthy, the sectors are readable – and yet all you see is a wall of encryption. That is exactly why the approach has to be different, and exactly why self-help does so much damage here: one click on “Reset this PC” takes a second and is irreversible.

What professional data recovery does differently with this kind of damage:

  • Working on a copy, never on the original. The first step is a complete, write-protected sector image of the encrypted storage medium. All further attempts run exclusively on this copy. The original state remains untouched – even if one approach fails, nothing is lost.
  • Proper diagnosis instead of guesswork. Is the drive merely locked, or is there also a hardware defect? Is the recovery key stored in the Microsoft or Entra account, in a company backup, on an old printout, or in an Intune environment that is currently unreachable? This distinction determines the way forward.
  • Experience with exactly this failure pattern. Update-related loss of access on encrypted notebooks, TPM binding problems and locked system drives are a recurring pattern. Anyone who knows the difference between a locked and a damaged storage medium spares the customer the most expensive wrong decision.
  • Laboratory equipment. If interventions have already taken place in the panic, or if there is additionally a hardware problem with the SSD or hard drive, specialist tools, spare parts and a cleanroom environment are available – not every case needs this, but when it does, it cannot be improvised.

The process at RESQ is deliberately risk-free for you: you describe the case, and we carry out a free initial assessment and prepare a cost estimate. You get an honest statement about the prospects – even when those are poor or recovery is not possible. Only then do you decide whether we should go ahead. There are no blanket promises: every data recovery is assessed on a case-by-case basis, and without the matching recovery key even professional work can fail against mathematically strong encryption. That is exactly what we tell you up front, rather than raising expectations.

Details of our approach can be found at data recovery at RESQ. If you would like to hand the case over directly, you can also create an order straight away via your customer account. If it is a notebook that additionally no longer boots properly or shows a hardware defect, the route via repair at RESQ is the right one. And if you want to take this incident as an opportunity to be better protected in future: the backup assistant helps you set up a backup that reduces lockouts like this one to a footnote.

Conclusion: the data is there – the access is missing

Following the August hotpatches KB5120994 and KB5123607, administrators are reporting BitLocker recovery prompts and failed Windows Hello PINs on Windows 11 24H2 and 25H2. There is no confirmed official connection, no fix exists, and reliable figures are lacking. What is certain: as far as is currently known, the files on the drive are intact – only the access is missing.

To keep it that way: note the key ID, look for the key in your Microsoft or work account, involve IT with company devices, and if Windows starts, back up to a separate medium immediately. What you should not do: reset, reinstall, clear the TPM or experiment in the BIOS.

If you cannot find the recovery key, the device no longer starts, or you simply want to make sure that nothing irreversible happens: have your case assessed by RESQ free of charge now – before a well-meant click costs you your data for good.

Device or system How you notice it What you should do What you must not do
Windows 11 24H2/25H2 (OS builds 26100.9106 / 26200.9106) with hotpatch KB5120994 on hotpatch-enrolled enterprise devices On the next reboot the BitLocker recovery screen unexpectedly appears asking for the 48-digit key First note the first eight characters of the displayed key ID and retrieve the matching key from another device via aka.ms/myrecoverykey, aka.ms/aadrecoverykey or your IT team Do not reinstall Windows, clear the TPM or touch BIOS/UEFI settings - that turns a recoverable lockout into permanent data loss
Security update KB5123607 (hotpatch-enrolled devices only) Same unexpected BitLocker recovery prompt at the next start after the update On managed devices contact IT first; only they can pull the key from the organisational account and assess update, TPM and Secure Boot state Never share the 48-digit recovery key with third parties - it unlocks the entire drive
BitLocker-encrypted system drives (SSD/HDD) of affected Windows 11 machines Drive no longer unlocks automatically, although data is reportedly intact As soon as Windows boots, immediately copy important data to a separate storage medium No further updates, no firmware upgrades and no configuration changes before the backup is complete
Windows Hello for Business (PIN sign-in) on affected devices After the correct key is entered Windows starts, but the PIN is partly unavailable with an error in the sign-in options Sign in with your password and only check the PIN reset via 'I forgot my PIN' after backing up your data Do not experiment with repeated account or WHfB container resets before the data is secured
Intune-managed devices with the hotpatch installed Device stays visible in Microsoft Defender but is no longer reachable via Intune (unconfirmed report) Report the incident to IT and document BIOS, TPM and Secure Boot changes since the last clean boot Do not re-enrol or reset the device on your own while the recovery key is not secured
HP Commercial Notebooks, Commercial Desktops and Workstations on Windows 11 23H2/24H2/25H2 after early-April 2026 BIOS updates (separate case) BitLocker recovery loop on the next boot after the BIOS update, caused by failed Secure Boot 2023 certificate updates Have IT check the registry values UEFICA2023Status and UEFICA2023Error and the minimum BIOS levels per HP's guidance End users should not change BIOS settings themselves or flash another BIOS update
Windows 11 suddenly asks for my BitLocker recovery key after update KB5120994 – are my files gone?

Based on current reports, the data on the drive is intact. The prompt is a BitLocker protection mechanism: the drive is encrypted and simply no longer unlocks automatically. Without the matching 48-digit key, however, nobody can access the data – not even Microsoft can reconstruct it.

Am I affected by the BitLocker issue after KB5120994 / KB5123607?

Reports involve Windows 11 24H2 and 25H2 on hotpatch-enrolled enterprise devices with BitLocker and Windows Hello for Business enabled, after KB5120994 (builds 26100.9106/26200.9106) and KB5123607. No specific hardware or model line has been confirmed. Microsoft officially lists no known issues for either update; so far these are isolated user reports.

What should I do if my work laptop asks for the BitLocker key after the August update?

Stay calm and do not change anything in BIOS, UEFI or the TPM. For work or school devices, contact your IT department first – only they can retrieve the key stored in the organisation account. Never share the 48-digit key with third parties, as it unlocks the entire drive.

Can the data still be recovered if the BitLocker recovery key can't be found?

Without the correct key, a BitLocker drive cannot be opened normally, and Microsoft cannot restore it. Whether anything is still possible depends on where the key was stored and on the condition of the device and drive. RESQ reviews your individual case free of charge – but no one can guarantee a successful recovery.

Can I fix the BitLocker lockout myself by clearing the TPM or reinstalling Windows?

This is strongly discouraged. Clearing the TPM returns the chip to an unowned state and can invalidate all keys created there, while a reinstall or reset deletes your files. That turns a solvable access problem into permanent data loss – have RESQ assess the case first.

What does it cost if I can no longer access my data after the BitLocker lockout?

That depends entirely on the individual case: the condition of the drive, the encryption and whether the key is available all affect the effort involved. RESQ offers a free initial assessment of your specific case before anything is commissioned.

Is your data affected?

Switch the device off and leave it off. We assess your case up front and tell you honestly whether and how your data can be recovered.

Call us: +49 6842 70 81 529 WhatsApp advice

How data recovery works

Assessing your case is free and without obligation. Successful data recovery can never be guaranteed – we tell you up front what the chances are.

Storage failure
Storage Spaces Direct Pool Read-Only After NVMe Firmware Fault
Several NVMe SSDs fail at once, the S2D pool switches to read-only and degraded. Why a force mount now puts your data at risk.
Data loss caused by software
OneDrive Storage Sense Data Loss: 60 GB of Videos Gone After Sync
After automatic Storage Sense and sync, around 60 to 65 GB of videos vanished from OneDrive. Folders came back, files did not. What affected users should know.
Cloud outage
Exchange Online Outage: No Mailbox Access, Data Intact
The Microsoft 365 outage EX1464935 blocked access to Exchange Online worldwide. Why this is not data loss and which steps could do harm now.
Cloud outage
Google Drive Outage: No File Access in Australia and New Zealand
A Google Drive outage blocked file access for 12 hours in Australia, New Zealand and the Philippines. Cause, symptoms and what users should do now.
View all reports
Many Thanks!
We have received your estimate and you should have received a confirmation email. We will get back to you as soon as possible.
Phone support
Phone support

If you have any questions about repairs, prices or general questions, just contact us.

How to contact us:
Mo. - Fr. from 10.00 am - 5.00 pm

0 68 42 / 70 81 529