Skip to content

TechDirectArchive

Hands-on IT, Cloud, Security & DevOps Insights

  • Home
  • About
  • Advertise With US
  • Reviews
  • Contact
  • Toggle search form
Home » Windows » Resolve Invalid Key ID when requesting BitLocker Recovery Key

Resolve Invalid Key ID when requesting BitLocker Recovery Key

Posted on 28/03/202320/11/2024 Christian By Christian No Comments on Resolve Invalid Key ID when requesting BitLocker Recovery Key
Perform-slfservice-rBitLocker-recovery

In this guide, I will show you how to Regain Access to a PC via the Self-Service Portal: Resolve Invalid Key ID when requesting BitLocker Recovery Key. MBAM is an administrator interface used to manage BitLocker drive encryption. It allows you to configure your enterprise with the correct BitLocker encryption policy options. As well as monitor compliance with these policies. Please see how to backup existing and new BitLocker recovery keys to Active Directory, and BitLocker Drive Encryption architecture and implementation types on Windows.

Kindly refer to the following similar guides on BitLocker. how to fix missing BitLocker Recovery Tab in Active Directory Users and Computers, how to enable or disable BitLocker Drive Encryption on Windows 10 and Virtual Machines, how to view BitLocker disk encryption status in Windows,

Why Would the BitLocker Recovery Key Window be prompted?

There are multiple reasons for this. You will have to troubleshoot specifically to pinpoint what could have happened in your case. We have outlined them in this guide “Reasons for BitLocker Recovery Mode Prompt“.

BitLocker Recovery Key restores access to a BitLocker-protected device when locked. Since I administer BitLocker via MBAM, I can save the recovery keys to the MBAM Database and Active Directory.

EnterRecoveryKeyID scaled
EnterRecoveryKeyID scaled

Note: You will only be able to perform the self-service recovery or recovery via the MBAM helpdesk. If the keys have been successfully escrowed in the MBAM database.

If this does not happen, and you do not have the recovery keys saved to Active Directory. In this case, you have to re-install your device.

Why was this “error “Invalid Key ID, Unable to get BitLocker Recovery Key” Prompted?

If you are experiencing errors due to invalid key ID, please take a look at the FAQs section for other possible reasons.

The Invalid Key ID was prompted because the user requesting the key isn’t an end-user on the device! Below are the prerequisites for recovery BitLocker Recovery Key via the SelfService Portal.

  • You must be the end user of the system to recover the key through the Self-Service Portal*
  • You must use your usual login credentials for that PC when logging into the Self-Service Portal. Else you will not be able to perform the recovery.

Note: If the device is also non-complaint in MBAM, the user will not be able to perform self-service recovery.

Unable-to-grt-Bitlocker-recvery-key-via-the-selfservice-portal-2

Note:  If the IT administrator configured an IIS Session State time-out. A message is displayed in the Self-Service Portal 5 Minutes prior to the time-out etc.

Resolve Invalid Key ID by Requesting BitLocker Recovery Key in AD

Lastly, if you have BitLocker Recovery Keys saved to Active Directory. You can log in Active Directory and get the recovery key.

You may need to fix the missing BitLocker Recovery Tab in Active Directory Users and Computers before being able to view the recovery key in AD. Here is how Backup existing and new BitLocker recovery keys to Windows Active Directory if you are not using GPO.

I really do not recommend AD, if you are using MBAM. As there will not be any form of auditing in place when keys are accessed by the Active Directory.

BitLocker RecoveryinAD
BitLocker RecoveryinAD

See Enterprise Compliance, Computer Compliance, and Recovery Audit Report: Understanding the Microsoft BitLocker Administration and Monitoring (MBAM) reports fields, and how to query MBAM to display the BitLocker Recovery report.

Resolve Invalid Key ID when requesting BitLocker Recovery Key

This section covers how to unlock your PC that is encrypted using the MBAM (Microsoft BitLocker Administration and Monitoring) client.  It is assumed that the MBAM client is installed on your device.

And that the drive has already been encrypted by the MBAM client. Else, you should look at this guide how and where to find your BitLocker recovery key in Windows

Important   An end user must have physically logged on to the computer (not remotely) at least one time successfully to be able to recover their key using the Self-Service Portal. Otherwise, they must use the Helpdesk Portal for key recovery.

Regain Access to a PC via the Self-Service Portal

The Self-Service Portal is a website that IT administrators configure as part of Microsoft BitLocker Administration and Monitoring (MBAM) deployment.

The portal allows end users to individually regain access to their PCs without bothering the helpdesk or System (AD) Administrators if they get locked out of Windows. Learn about how to deploy MBAM for Bitlocker Administration.

To use the Self-Service Portal to regain access to a computer, kindly access the Self Srvice Portal URL of your Company.

Login with domain credentials

Enter the Recovery Key ID as displayed on your PC and select a reason.

Get-a-BitLocker-Recovery-Key

In the Recovery KeyId field, enter a minimum of eight of the 32-digit BitLocker Key ID that is displayed on the BitLocker recovery screen of your computer.

If the first eight digits match multiple keys, a message displays that requires you to enter all 32 digits of the recovery key ID.

In the Reason field, select a reason for your request for the recovery key. Next, click on Get Key. Your BitLocker recovery key is displayed in the Your BitLocker Recovery Key field.

Enter the 48-digit code into the BitLocker recovery screen on your computer to regain access to the computer

Regain Access via the Help Desk Portal

Since the “HelpDesk” Portal does not have this explicit requirements as discussed above. We could contact the Helpdesk office to help retrieve theBitLocker Recovery Key.

What could cause Invalid Key ID when requesting BitLocker Recovery Key?

One of the reasons could be that the User profile has been deleted from the device and you are trying to use this user to perform BitLocker self-service recovery.

Another reason could be due to last contact date my the device. You can take a look on the Computer or Enterprise Reporting services for more information about the device.

Last contact

To fix this issue and ensure the agent is able to communicate with the database correctly, I will run the command “gpupdate /force” in order to have the policies reapplied. With this, the device will be recognized with the Recovery key ID and was you should be able to perform the self-service recovery. As you can see below, recovery via self-service is now possible.

device recognised
Even with this issue, you could retrieve the BitLocker recovery key with the helpdesk and from AD when configured to save to AD.

FAQs

What happens if the computer is turned off during encryption or decryption?

If the computer is turned off or goes into hibernation, the BitLocker encryption and decryption process will resume where it stopped the next time Windows starts. Resuming encryption or decryption is true even if the power is suddenly unavailable.

Does BitLocker encrypt and decrypt the entire drive all at once when reading and writing data?

No, BitLocker doesn’t encrypt and decrypt the entire drive when reading and writing data. The encrypted sectors in the BitLocker-protected drive are decrypted only as they’re requested from system read operations. Blocks that are written to the drive are encrypted before the system writes them to the physical disk. No unencrypted data is ever stored on a BitLocker-protected drive.

I hope you found this blog post helpful on how to Regain Access to a PC via the Self-Service Portal: Resolve Invalid Key ID when requesting BitLocker Recovery Key. If you have any questions, please let me know in the comment session.

5/5 - (1 vote)

Thank you for reading this post. Kindly share it with others.

  • Share on X (Opens in new window) X
  • Share on Reddit (Opens in new window) Reddit
  • Share on LinkedIn (Opens in new window) LinkedIn
  • Share on Facebook (Opens in new window) Facebook
  • Share on Pinterest (Opens in new window) Pinterest
  • Share on Tumblr (Opens in new window) Tumblr
  • Share on Telegram (Opens in new window) Telegram
  • Share on WhatsApp (Opens in new window) WhatsApp
  • Share on Mastodon (Opens in new window) Mastodon
  • Share on Bluesky (Opens in new window) Bluesky
  • Share on Threads (Opens in new window) Threads
  • Share on Nextdoor (Opens in new window) Nextdoor
Windows Tags:Bitlocker, BitLocker Drive Encryption Administration Utilities, bitlocker key, BitLocker Key Recovery, Encryption, MBAM, Microsoft BitLocker Administration and Monitoring, Microsoft BitLocker Administration and Monitoring (MBAM), Microsoft Windows, Windows 10, Windows 11

Post navigation

Previous Post: How to Remove Remote Desktop Services Role on Windows Server
Next Post: Change Visual Studio Code UI language

Related Posts

  • Featured image multi monitor
    Enhanced Multi-Monitor Experience with Windows 11 Windows
  • image 43
    Configure GPS location “Google Map” on your Android Studio Emulator Windows
  • wmic4
    How to find User Security Identifier (SID) in Windows [Part 1] Windows
  • How to Remove Language Pack
    How to forcefully remove Language Pack on Windows 10 and 11 Windows
  • image 8
    Enable or disable Core Isolation Memory Integrity in Windows 10 and 11 Windows
  • Blog inside@2x
    How to block automatic delivery of Microsoft Edge Chromium-based Windows

More Related Articles

Featured image multi monitor Enhanced Multi-Monitor Experience with Windows 11 Windows
image 43 Configure GPS location “Google Map” on your Android Studio Emulator Windows
wmic4 How to find User Security Identifier (SID) in Windows [Part 1] Windows
How to Remove Language Pack How to forcefully remove Language Pack on Windows 10 and 11 Windows
image 8 Enable or disable Core Isolation Memory Integrity in Windows 10 and 11 Windows
Blog inside@2x How to block automatic delivery of Microsoft Edge Chromium-based Windows

Leave a Reply Cancel reply

You must be logged in to post a comment.

Microsoft MVP

VEEAMLEGEND

vexpert-badge-stars-5

Virtual Background

GoogleNews

Categories

veeaam100

sysadmin top30a

  • image 41
    How to Quickly Fix Windows Search Bar Not Working Windows
  • UEFI vs BIOS What's the Difference
    What are the Differences between UEFI and BIOS Windows
  • computefeature
    How to use Azure Compute Gallery AWS/Azure/OpenShift
  • featurekube
    How to Install and Use Minikube on a Linux System Containers
  • Screenshot 2020 11 09 at 11.26.54
    The logon attempt failed for the remote desktop connection Windows Server
  • How To Remove Takeprize50.life Redirect From Mac unboxhow
    Remove unwanted site redirects or pop-ups from Google Chrome Mac
  • S3 Bucket
    Access AWS Management Console and Create Resources with AWS CLI on Windows AWS/Azure/OpenShift
  • images 2
    How to configure and use Pleasant Password RDP SSO Password Manager

Subscribe to Blog via Email

Enter your email address to subscribe to this blog and receive notifications of new posts by email.

Join 1,824 other subscribers
  • RSS - Posts
  • RSS - Comments
  • About
  • Authors
  • Write for us
  • Advertise with us
  • General Terms and Conditions
  • Privacy policy
  • Feedly
  • Telegram
  • Youtube
  • Facebook
  • Instagram
  • LinkedIn
  • Tumblr
  • Pinterest
  • Twitter
  • mastodon

Tags

Active Directory AWS Azure Bitlocker Microsoft Windows PowerShell WDS Windows 10 Windows 11 Windows Server 2016

Copyright © 2025 TechDirectArchive

 

Loading Comments...
 

You must be logged in to post a comment.