A company laptop belonging to an executive suffered a Windows failure and now stops at the BitLocker recovery screen requesting the 48-digit recovery key. The drive was encrypted before a merger and before the organization migrated from its legacy email system to Microsoft 365. No BitLocker key repository was documented during the handover, and the key is not present in the current Entra ID tenant. The executive also checked likely personal and legacy email accounts, without finding anything. Removing the drive and connecting it to another computer still results in the BitLocker prompt. The main question is whether there are any legitimate recovery avenues left, or whether the drive should be preserved, the data treated as unrecoverable, and the laptop replaced or reimaged.
4 Answers
BitLocker is doing exactly what it was designed to do: without the recovery key, there is no supported way to decrypt the volume. Before giving up, get written approval and search every authorized location from the old environment—legacy Active Directory, file shares, archived documentation, old email, printed records, and any backup or management system that might have escrowed the key. Do not wipe the original drive while that search is happening.
If the machine was joined to the old domain, an archived domain controller or system backup may contain a BitLocker recovery object. If it was only using a local account, that makes escrow less likely, but it is still worth checking old administrative records and any decommissioned systems through the proper owners. A reputable data-recovery provider can advise, but they cannot magically bypass sound BitLocker encryption without a key.
The practical plan is to preserve the original disk, document the incident, and obtain management or security sign-off before any destructive action. Replace the drive or laptop, provision it correctly, and restore whatever data exists from approved backups. Avoid random 'BitLocker crack' tools or supposed exploits—they may be scams, damage evidence, or create a serious security and accountability problem.
Check whether the user's files were already syncing to OneDrive or included in another backup. Files created before synchronization was configured may not be there, so verify rather than assuming everything is backed up. In parallel, issue the executive a replacement device so the recovery investigation does not block their work.

OneDrive only protects files that were actually uploaded or included in the configured folders; older files left elsewhere on the laptop may not have been copied.