After Windows Updates, BitLocker may lock an endpoint and require a recovery key to unlock it. When an end-user contacts their administrator for assistance, they must provide the Key ID displayed on their screen. A Nebula Super Admin or Administrator can locate the recovery key in Nebula by searching with the Key ID.
To find the recovery key:
- Navigate to Monitor > Drive Encryption.
- Locate the search field in the top-right.
- Enter the Key ID into the search field.
- Locate the Recovery Key under the Recovery Key column for the endpoint. If the column is missing, click Add / Remove Columns and add it.
- Click the copy to clipboard icon
.
- Send the key to the end-user via a channel accessible on their mobile device, like email or a messaging app.
- If the end-user doesn't have access to any other communication channels, click the reveal key icon
and read it back to them.
- If the end-user doesn't have access to any other communication channels, click the reveal key icon
- After the user enters the recovery key, click the rotate key icon
to manually rotate the key. This is done automatically if configured in the policy settings.
Return to Drive Encryption guide.