#Requires -Version 5.1 <# JbTecWiz Support Centre -- generated fix script Fault : BitLocker asks for the recovery key at every boot Fix : Find the recovery key Source: https://jbtecwiz.com/support/win-sec-bitlocker-prompt Run as : Another device Expect : 20 minutes Risk : low Reversible : yes WHEN THIS IS THE RIGHT FIX You are locked out. Work through every place it could have been escrowed before considering the data lost. HOW TO UNDO IT Not applicable. This script walks the fix one step at a time and asks before each one. Steps with no command are things you do yourself -- it prints those and waits. Run with -DryRun to print without executing. -------------------------------------------------------------------- NO WARRANTY - USE AT YOUR OWN RISK This script is provided by JbTecWiz as-is and with no warranty of any kind, express or implied. You run it entirely at your own risk. JbTecWiz accepts no liability for any loss or damage arising from its use, including but not limited to data loss, downtime, or configuration changes that turn out to be wrong for your system. You are responsible for reading this script before running it, for satisfying yourself that it suits the machine in front of you, and for having a working backup first. Some steps cannot be undone. -------------------------------------------------------------------- #> [CmdletBinding()] param( # Print every step and command without running anything. [switch]$DryRun, # Do not ask before each step. Read the script first if you use this. [switch]$Unattended ) $ErrorActionPreference = 'Stop' $script:Failed = 0 function Write-Rule { param([string]$Text) Write-Host '' Write-Host ('-' * 70) -ForegroundColor DarkGray if ($Text) { Write-Host $Text -ForegroundColor Cyan } } function Show-Prose { param([string]$Text, [string]$Colour = "Gray") if (-not $Text) { return } $words = $Text -split "\s+"; $line = " " foreach ($w in $words) { if (($line.Length + $w.Length) -gt 74) { Write-Host $line -ForegroundColor $Colour; $line = " " } $line += "$w " } if ($line.Trim()) { Write-Host $line -ForegroundColor $Colour } } function Invoke-Step { param( [int]$Number, [string]$Do, [string]$Why, [scriptblock]$Command, [switch]$Manual, [string]$Shell = "powershell" ) Write-Rule " Step $Number of 5" Show-Prose $Do "White" if ($Why) { Write-Host ""; Show-Prose $Why "DarkGray" } if ($Manual) { Write-Host '' Write-Host ' -> Do this yourself, then press Enter to carry on.' -ForegroundColor Yellow if (-not $Unattended -and -not $DryRun) { [void](Read-Host) } return } Write-Host '' foreach ($l in ($Command.ToString().Trim() -split "`n")) { Write-Host (" " + $l.Trim()) -ForegroundColor Green } Write-Host '' if ($DryRun) { Write-Host " (dry run -- not executed)" -ForegroundColor DarkGray; return } if (-not $Unattended) { $a = Read-Host " Run this step? [Y]es / [S]kip / [Q]uit" if ($a -match "^[Qq]") { Write-Host " Stopped at your request."; exit 0 } if ($a -match "^[Ss]") { Write-Host " Skipped." -ForegroundColor DarkGray; return } } try { & $Command } catch { $script:Failed++ Write-Host (" Step $Number failed: " + $_.Exception.Message) -ForegroundColor Red Show-Prose "The rest of the fix may depend on this. Read the write-up before carrying on." "Red" if (-not $Unattended) { $c = Read-Host " Carry on anyway? [y/N]" if ($c -notmatch "^[Yy]") { exit 1 } } } } Write-Rule Write-Host ' BitLocker asks for the recovery key at every boot' -ForegroundColor White Write-Host ' Find the recovery key' -ForegroundColor Cyan Write-Host '' Write-Host ' Risk: low Reversible 20 minutes' Write-Host '' Show-Prose 'No warranty. Use at your own risk - JbTecWiz accepts no liability. Read it before you run it, and have a backup.' 'DarkYellow' Write-Rule if (-not $Unattended -and -not $DryRun) { $go = Read-Host ' Ready? [y/N]' if ($go -notmatch "^[Yy]") { Write-Host " Nothing was changed."; exit 0 } } Invoke-Step -Number 1 -Do 'Check the Microsoft account it may have been saved to, at account.microsoft.com/devices/recoverykey -- this is where a consumer machine with a Microsoft account sign-in stores it automatically.' -Manual Invoke-Step -Number 2 -Do 'On a work machine, check Entra ID: the device''s page in the admin centre, or the user''s My Account -> Devices page.' -Manual Invoke-Step -Number 3 -Do 'In an on-premises domain, check Active Directory if escrow was configured.' -Command { Get-ADObject -Filter { objectClass -eq 'msFVE-RecoveryInformation' } -SearchBase (Get-ADComputer LAPTOP01).DistinguishedName -Properties msFVE-RecoveryPassword | Format-List Name,msFVE-RecoveryPassword } Invoke-Step -Number 4 -Do 'Check for a printed copy or a saved .txt on a USB stick, which is where the setup wizard offers to put it.' -Manual Invoke-Step -Number 5 -Do 'If none of these have it, the data is not recoverable. That is the design of the feature and there is no bypass -- the honest answer at this point is restore from backup and rebuild.' -Why 'It is worth saying plainly rather than sending someone round a loop of hopeful tools. Encryption without an escrowed key and without the key is exactly as strong as it claims to be.' -Manual Write-Rule " Confirm it worked" Show-Prose 'The 48-digit key unlocks the volume and Windows boots.' 'White' Write-Rule if ($script:Failed -gt 0) { Write-Host (" Finished with " + $script:Failed + " failed step(s).") -ForegroundColor Yellow Show-Prose 'Read the full write-up at https://jbtecwiz.com/support/win-sec-bitlocker-prompt' 'Yellow' } else { Write-Host ' Finished.' -ForegroundColor Green } Write-Host '' Show-Prose 'To undo: Not applicable.' 'DarkGray' Write-Rule