BitLocker recovery key after the August hotpatch KB5120994: when your PC suddenly locks you out
Since 21 August 2026, administrators have been reporting that Windows 11 devices unexpectedly demand the 48-digit BitLocker recovery key at the next restart after the hotpatches KB5120994 and KB5123607. In some cases the Windows Hello PIN is no longer available afterwards either. As things stand, the data on the drive is intact – but without the right key, nobody can get to it.
That is the crucial distinction in this incident: this is not a defective SSD or hard drive, and these are not deleted files. This is a cryptographic loss of access – the drive is encrypted, and the key that Windows normally uses to unlock it automatically at startup no longer works. Anyone who panics now and reinstalls the system or resets the TPM turns a solvable access problem into permanent data loss.
What exactly happened?
On 11 August 2026, Microsoft released the security hotpatch KB5120994 for Windows 11 24H2 and 25H2 (OS builds 26100.9106 and 26200.9106). The same day saw the release of KB5123607, a standalone security update exclusively for hotpatch-enrolled devices which, according to Microsoft, is designed to take effect without a restart. The release notes for both updates state explicitly:
“Microsoft is not currently aware of any issues with this update.” – Microsoft Support, KB5120994 and KB5123607
On 21 August 2026, a thread in the Intune forum on Reddit then documented a striking sequence of events on individual devices: hotpatch installed – restart later – unexpected BitLocker recovery prompt – after entering the correct key, Windows does start, but signing in with Windows Hello for Business (WHfB) via PIN no longer works in some cases. Several commenters reported similar isolated incidents. The original poster explicitly ruled out changed BIOS and TPM versions in his environment.
Important context: these are anecdotal user reports, not proof of causality. As of 22 August 2026 there is neither confirmation from Microsoft nor an entry in the Release Health dashboard for Windows 11 25H2 – the only issue documented there after the August update is a different, gaming-related one. There is no official number of affected users, no confirmed list of models and no failure rate. The Reddit thread mentions “some devices”, “a handful of devices” or “3 or 4” cases – figures that have not been independently verified and cannot be added up.
Why does BitLocker ask for the recovery key in the first place?
BitLocker encrypts the entire drive and unlocks it at startup using a key held in the TPM – a separate security chip on the motherboard. If the security measurements taken at startup deviate from the expected state, BitLocker refuses to unlock automatically. That is a protective function, not a fault and not a sign of damaged data.
“The following list provides examples of common events that cause a device to enter BitLocker recovery mode when starting Windows: Turning off, disabling, deactivating, or clearing the TPM; TPM self-test failure; upgrading critical early startup components, such as a BIOS or UEFI firmware upgrade; [and] modifying the Platform Configuration Registers (PCRs) used by the TPM validation profile.” – Microsoft Learn, BitLocker recovery overview
Nowhere does Microsoft state that KB5120994 or KB5123607 reset a TPM, break the BitLocker binding or damage the WHfB container. The causes discussed in the forum – TPM state, Secure Boot certificates, firmware state – remain unconfirmed hypotheses.
Is my device affected?
Based on the reports available so far, the following may be affected:
- Windows 11 24H2 and 25H2 on hotpatch-enrolled enterprise devices
- Installed updates KB5120994 (OS builds 26100.9106 / 26200.9106) and, subsequently, KB5123607
- Devices with BitLocker and Windows Hello for Business enabled
No particular hardware or model range has been confirmed for this incident. Microsoft currently documents no affected firmware versions.
The separate HP case – please don’t confuse the two
In parallel, there is a separate, documented manufacturer case: on 11 May 2026, HP published a notice about BitLocker recovery loops following certain BIOS updates from early April 2026. According to HP, this affects all HP Commercial Notebooks, HP Commercial Desktops and HP Workstation Computers running Windows 11 23H2, 24H2 and 25H2.
“A BitLocker recovery screen may appear on next boot after updating a computer with BIOS updates released in early April 2026.” – HP Support
The cause there was failed Secure Boot 2023 certificate updates – not the August hotpatches. For checking, HP cites the registry values UEFICA2023Status and UEFICA2023Error as well as minimum BIOS versions. That should be checked exclusively by IT following HP’s instructions, not by the user in the BIOS. Also separate from this: on 14 April 2026, Microsoft had already addressed a different bug with KB5083769 in which devices ended up in BitLocker recovery after Secure Boot updates.
How do I recognise the BitLocker and Windows Hello lockout?
- After the hotpatch is installed, the BitLocker recovery screen appears unexpectedly at the next restart or power-on.
- After entering the correct 48-digit recovery key, Windows initially starts normally according to the original report.
- Afterwards, Windows Hello for Business with PIN is partly unavailable; the interface reports, in effect, that a problem has occurred and the PIN is not available.
- According to the user report, another restart only fixes the PIN issue on some of the devices.
- The poster additionally reports that the devices remained visible in Microsoft Defender but could no longer be reached via Intune. This too has not been independently confirmed.
How to check safely whether you are affected
- Do not tamper with BIOS, UEFI or TPM. On the BitLocker screen, first note down or photograph the first eight characters of the recovery key ID displayed.
- Look for the matching key from another device: for privately managed devices at aka.ms/myrecoverykey, for work or school devices at aka.ms/aadrecoverykey or via the responsible IT department.
- Compare the key ID before you enter the 48-digit key.
- If Windows starts after correct entry, check whether the PIN is available under the sign-in options. If “I forgot my PIN” is visible, that may be the supported route for a Microsoft account; otherwise sign in with your password.
- For managed devices, IT should check whether the device is enrolled for hotpatching and whether KB5120994 / KB5123607 were installed or offered – and document BIOS, TPM and Secure Boot changes since the last trouble-free startup.
What you should do now
- Stay calm. A single recovery prompt does not mean your files are damaged or deleted.
- Only enter the matching recovery key. Look for it exclusively via your own Microsoft account, your work/school account, a printout, a secured USB stick or your IT department. Never pass the 48-digit key on to third parties – it unlocks the entire drive.
- For company, school or managed devices, contact IT first. Only they can retrieve the key from the organisation’s account and assess the update, TPM and Secure Boot situation.
- If Windows starts: back up immediately. Copy important data to a separate storage medium before anything else is changed. Only then have the PIN reset checked via the sign-in options.
- No further updates, no firmware updates, no configuration changes while the device is in this state.
If you cannot find the key, or the device no longer boots at all: leave the device alone from this point on and have the case assessed by professionals. Every further attempt makes the starting position worse.
What you must never do
This section is the most important part of the entire article. With an encrypted drive, it is almost always the well-intentioned “repair attempts” that turn a lockout into permanent loss.
- “Reset this PC” or a fresh installation – never as a first step. In the Reddit thread, a complete reinstallation is named as the only measure that has reliably worked so far. It produces a working system – but Microsoft explicitly points out that a reset removes all files. Your data is gone afterwards. A usable notebook is no substitute for ten years of accounting records.
- Clearing or resetting the TPM. Microsoft warns unambiguously: “Clearing the TPM causes you to lose all created keys associated with the TPM, and data protected by those keys, such as a virtual smart card or a sign-in PIN.” (Microsoft Learn, Troubleshoot the TPM). On work or school devices this must never be done without instructions from IT.
- Deleting the Windows Hello container with certutil -deleteHelloContainer without having alternative sign-in methods ready first. Microsoft: “On the latest versions of Windows 11, running the certutil -deletehellocontainer command clears not only Windows Hello for Business, but also any passkeys stored on that Windows device.” While this does not demonstrably delete BitLocker data, it can cost you access to further accounts.
- Random changes to BIOS, UEFI, Secure Boot, TPM or boot configuration. These are precisely the interventions Microsoft lists as typical triggers of a BitLocker recovery prompt. HP additionally warns of recovery errors if Secure Boot certificates are changed without suspending BitLocker. Doing so hampers root cause analysis and potentially your access.
- Repeated boot attempts and “trying out” the wrong keys. Check the key ID first, then enter it.
And one point that cannot be repeated often enough: without the correct recovery key, nobody can open the drive – not even the manufacturer.
“Microsoft Support doesn't have the ability to retrieve, provide, or recreate a lost BitLocker recovery key.” – Microsoft Support, Find your BitLocker recovery key
Experience shows that it is precisely these hasty do-it-yourself attempts – resetting, clearing the TPM, “having a quick look” in the BIOS – that ultimately make data unrecoverable. In these cases the drive itself is perfectly healthy.
Is there a fix from Microsoft?
No. As of 22 August 2026, for the reported combination of BitLocker recovery followed by an unavailable Windows Hello PIN after KB5120994 / KB5123607, there is no official fix, no recall and no confirmation from the manufacturer. Neither KB page lists any known issues, and neither does the Release Health dashboard. A specific uninstallation, a firmware version or a universal workaround therefore cannot responsibly be recommended.
The officially documented route is: find the recovery key, unlock Windows, back up your data, then reset the PIN via the designated sign-in options. HP’s remedy for the Secure Boot case applies exclusively to the BIOS case described there and is not a fix for the hotpatch reports.
Why this case belongs in professional hands – and how RESQ specifically helps
A BitLocker lockout is fundamentally different from a defective hard drive. The electronics work, the SSD is healthy, the sectors are readable – and yet all you see is a wall of encryption. That is exactly why the approach has to be different, and exactly why self-help does so much damage here: one click on “Reset this PC” takes a second and is irreversible.
What professional data recovery does differently with this kind of damage:
- Working on a copy, never on the original. The first step is a complete, write-protected sector image of the encrypted storage medium. All further attempts run exclusively on this copy. The original state remains untouched – even if one approach fails, nothing is lost.
- Proper diagnosis instead of guesswork. Is the drive merely locked, or is there also a hardware defect? Is the recovery key stored in the Microsoft or Entra account, in a company backup, on an old printout, or in an Intune environment that is currently unreachable? This distinction determines the way forward.
- Experience with exactly this failure pattern. Update-related loss of access on encrypted notebooks, TPM binding problems and locked system drives are a recurring pattern. Anyone who knows the difference between a locked and a damaged storage medium spares the customer the most expensive wrong decision.
- Laboratory equipment. If interventions have already taken place in the panic, or if there is additionally a hardware problem with the SSD or hard drive, specialist tools, spare parts and a cleanroom environment are available – not every case needs this, but when it does, it cannot be improvised.
The process at RESQ is deliberately risk-free for you: you describe the case, and we carry out a free initial assessment and prepare a cost estimate. You get an honest statement about the prospects – even when those are poor or recovery is not possible. Only then do you decide whether we should go ahead. There are no blanket promises: every data recovery is assessed on a case-by-case basis, and without the matching recovery key even professional work can fail against mathematically strong encryption. That is exactly what we tell you up front, rather than raising expectations.
Details of our approach can be found at data recovery at RESQ. If you would like to hand the case over directly, you can also create an order straight away via your customer account. If it is a notebook that additionally no longer boots properly or shows a hardware defect, the route via repair at RESQ is the right one. And if you want to take this incident as an opportunity to be better protected in future: the backup assistant helps you set up a backup that reduces lockouts like this one to a footnote.
Conclusion: the data is there – the access is missing
Following the August hotpatches KB5120994 and KB5123607, administrators are reporting BitLocker recovery prompts and failed Windows Hello PINs on Windows 11 24H2 and 25H2. There is no confirmed official connection, no fix exists, and reliable figures are lacking. What is certain: as far as is currently known, the files on the drive are intact – only the access is missing.
To keep it that way: note the key ID, look for the key in your Microsoft or work account, involve IT with company devices, and if Windows starts, back up to a separate medium immediately. What you should not do: reset, reinstall, clear the TPM or experiment in the BIOS.
If you cannot find the recovery key, the device no longer starts, or you simply want to make sure that nothing irreversible happens: have your case assessed by RESQ free of charge now – before a well-meant click costs you your data for good.