Unsolved

3 Posts

614

December 23rd, 2021 10:00

XPS13 9360 require bitlocker recover key

Hi,

My Dell XPS13 9360 automatically update firmware on Dec 21 and then ask for bitlocker recover key to boot. I never set up bitlocker and can't find it in my microsoft account either. Now my C drive is locked and how can I recover my data on C drive. 

Thanks for any suggestions!

xiang

3 Posts

December 23rd, 2021 11:00

Actually I can't find my laptop in my Microsoft account. I believe it is not linked and I don't know where can I find the key? Is it possible on the locked C drive? Can I get recover key by the recover key ID? Thanks, Xiang

2 Intern

 • 

415 Posts

December 23rd, 2021 11:00

did you have your microsoft  account  linked to your laptop before the firmware update?

11 Legend

 • 

14K Posts

 • 

79.9K Points

December 23rd, 2021 22:00

@gaoxhe73  You can’t get a Recovery Key from a locked drive. And the Recovery Key ID just helps you identify which Recovery Key is correct for that drive if you have multiple keys for multiple drives stored somewhere. You can’t calculate the Recovery Key from the Recovery Key ID, otherwise it would be possible for other people to decrypt your data.

If you can’t find your key anywhere, your only option would be to use the BIOS Update Utility built into the firmware to downgrade back to whatever BIOS you were running before. You can access that utility by pressing F12 at startup, and you’ll have to use some other PC to get to the Dell Support site to download previous BIOS update files and copy them into a FAT32 flash drive. If you aren’t sure which BIOS version you were running before, you’ll have to try multiple previous releases. But when you get the right one, you’ll be ok (as long as you haven’t cleared the TPM) because the reason you’re seeing this prompt is that the BIOS update changed the hardware/firmware state from the known trusted state. That causes the TPM’s “platform integrity check” to fail, which means it doesn’t release the decryption key like it normally does, which is why you see the Recovery Prompt. If you enter the key, then it will begin trusting the new state, but if you can’t do that, then you can instead return the system to its trusted state, in which case the TPM will release the key again.

To avoid this next time, if you temporarily suspend BitLocker (not the same as disabling it) just before updating your BIOS, then the TPM will automatically trust the new state without prompting for a key. If you update your BIOS through Dell Update, it will automatically suspend BitLocker before rebooting by default in order to avoid this exact problem. Or you can of course immediately back up your Recovery Key when you get back into your system so you can enter it if ever needed on the future. In fact you should do anyway, since there are several cases where a Recovery Key might be the only option, such as after a motherboard replacement where the new motherboard’s TPM won’t have the decryption key at all.

3 Posts

December 24th, 2021 06:00

Thanks for your detailed explain and instruction. I really appreciate it! Luckly after two day's struggle. I find my recover key in my son's microsoft account. I finaly can backup my data. Thanks! Xiang

No Events found!

Top