Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Some links on this page are affiliate links: if you buy through them we may earn a commission, at no extra cost to you.

Microsoft confirmed that the April 14, 2026 Windows 11 update KB5083769 could send some PCs to the BitLocker recovery screen after a restart. The issue required a specific TPM/PCR7 and Secure Boot configuration, so it was not a universal Windows 11 failure. In Microsoft’s documented case, the 48-digit recovery password was generally needed once. Microsoft addressed the principal 24H2 and 25H2 scenario in the May 12, 2026 update, KB5089549.

If the screen is in front of you, record its Key ID, retrieve the matching recovery key, and do not reset or wipe the device before checking whether the data can be unlocked.

Which Windows update caused the prompt?

The specifically documented incident involved the April 14, 2026 Patch Tuesday release KB5083769 for Windows 11 24H2 and 25H2, building 26100.8246 and 26200.8246. Microsoft’s release listing identifies KB5083768 for the April 14 baseline on 26H1 and KB5082052 for 23H2, but its detailed BitLocker bulletin is tied to KB5083769. Do not assume every Windows 11 edition or April package had the same behavior; check the version-specific release entry at Microsoft’s Windows 11 release information.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

What users saw—and what it means

An affected computer could boot directly to BitLocker recovery and request its 48-digit recovery password. Microsoft says the key normally had to be entered only on the first affected restart. That is a security response to a changed measured-boot state, not evidence that BitLocker encrypted the disk again, destroyed files, or necessarily failed.

#1 Best Overall
Sale
Microsoft Windows 11 (USB)
  • Less chaos, more calm. The refreshed design of Windows 11 enables you to do what you want effortlessly.
  • Biometric logins. Encrypted authentication. And, of course, advanced antivirus defenses. Everything you need, plus more, to protect you against the latest cyberthreats.
  • Make the most of your screen space with snap layouts, desktops, and seamless redocking.
  • Widgets makes staying up-to-date with the content you love and the news you care about, simple.
  • Stay in touch with friends and family with Microsoft Teams, which can be seamlessly integrated into your taskbar. (1)

BitLocker measures components such as firmware, Secure Boot state and boot files through the TPM. The April servicing process could prepare Secure Boot certificate and boot-manager changes. On a machine whose policy explicitly required PCR7 even though Windows reported that PCR7 binding was unavailable, the changed boot state could no longer satisfy the existing protector measurements.

A prompt on every boot, a rejected key, or a recovery loop is not the normal one-time scenario. Firmware changes, altered boot order, TPM problems, a damaged or full EFI System Partition, and unrelated OEM issues can produce similar symptoms. Microsoft’s general trigger list is covered in its BitLocker recovery overview and BitLocker FAQ.

Who was actually at risk?

Microsoft said all of these conditions had to be present:

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
  • BitLocker protected the Windows operating-system volume.
  • The policy Configure TPM platform validation profile for native UEFI firmware configurations was configured.
  • PCR7 was explicitly included in that profile, or set through the equivalent registry configuration.
  • msinfo32.exe reported Secure Boot State PCR7 Binding: Not Possible.
  • The device’s Secure Boot signature database contained the Windows UEFI CA 2023 certificate.
  • The device was not already using the 2023-signed Windows Boot Manager.

That combination is uncommon on ordinary unmanaged personal PCs, but it is not accurate to call the incident enterprise-only. Managed policies, firmware state and servicing history determine exposure.

How to find the correct recovery key

Use the Key ID displayed on the recovery screen to select the matching record. A device name or a familiar-looking label alone is not enough.

Personal Microsoft account

  1. On another device, open https://account.microsoft.com/devices/recoverykey.
  2. Sign in with the Microsoft account associated with the Windows installation.
  3. Compare the recovery screen’s Key ID with the listed keys, then enter the matching 48-digit password.

Work or school device

Ask your administrator or help desk to retrieve the key from Microsoft Entra ID, Active Directory Domain Services, an approved delegated recovery system, or the organization’s managed-device portal. Microsoft documents these storage options in its recovery overview.

If no key is available

Do not start with Reset this PC, a disk wipe, TPM clearing, or decryption. A BitLocker-protected operating-system volume generally cannot be unlocked without its recovery password, a recovery agent, or another valid recovery method; resetting can eliminate access to local data.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

How administrators can check exposure

Review the policy

In Group Policy Management or gpedit.msc, open:

Computer Configuration
  > Administrative Templates
  > Windows Components
  > BitLocker Drive Encryption
  > Operating System Drives

Inspect Configure TPM platform validation profile for native UEFI firmware configurations. The documented risk is an explicit PCR7 selection on systems where PCR7 binding is unavailable.

Rank #2

Check Secure Boot and PCR7

  1. Press Win+R, enter msinfo32.exe, and press Enter.
  2. In System Information, check Secure Boot State and Secure Boot State PCR7 Binding.
  3. The documented risk indicator is Secure Boot State PCR7 Binding: Not Possible.

Inspect servicing events

Open Event Viewer > Windows Logs > System and filter for BitLocker, Secure Boot, boot-manager and TPM events. Microsoft describes Event ID 1032 in connection with protective behavior that prevents installation of the 2023-signed Windows Boot Manager; it is not guaranteed to appear on every affected machine. See the April 30 servicing note at KB5083631.

Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

Microsoft’s policy workaround

Before changing protectors, verify that a recovery key is escrowed and confirm the correct operating-system volume. Microsoft’s documented workaround is:

  1. Set the TPM platform validation policy to Not Configured at the Group Policy path above.
  2. Refresh policy from an elevated Command Prompt:
gpupdate /force
  1. Suspend protection on the OS volume:
manage-bde -protectors -disable C:
  1. Resume protection so Windows recreates bindings using its selected default PCR profile:
manage-bde -protectors -enable C:

These commands change protection state; they do not decrypt the drive. Keep suspension as brief as possible, test on representative hardware, and reboot only when the recovery key is available.

Free tools Windows power users keep installed

One-click scans. No signup required.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

What fixed the issue?

For the principal Windows 11 24H2 and 25H2 path, Microsoft says the May 12, 2026 cumulative update KB5089549 fixed the problem. It improves startup reliability after boot-file updates, addresses BitLocker Recovery after boot-file changes with certain TPM validation settings, and prevents the incompatible configuration from installing the 2023-signed Windows Boot Manager in the problematic scenario.

Install the current cumulative update for the device’s Windows release rather than confusing KB5083769 with the later fix. Secure Boot certificate servicing continues to evolve, so organizations should follow current Microsoft guidance instead of freezing certificate updates.

If recovery repeats after every restart

Repeated prompts require separate investigation. Confirm that the policy change actually applied, check whether boot-manager servicing is failing, and review BIOS/UEFI firmware, boot order, TPM status and EFI System Partition capacity. Verify that protection was resumed and that the entered password matches the displayed Key ID. A persistent loop is not explained by Microsoft’s normal one-time description of this incident.

Should you uninstall KB5083769?

Usually no. Removing a security update can restore vulnerabilities, while the documented issue is configuration-specific and has a later fix. Consider rollback only through an organization’s incident-response process, after confirming the update is the cause and checking for a newer cumulative update. Do not disable BitLocker permanently or suspend it before every update as a blanket policy.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

The Bottom Line

The April 2026 BitLocker prompt was real but narrowly conditional: KB5083769 could expose systems with an explicit PCR7 policy and unavailable PCR7 binding. Match the recovery Key ID, correct the policy and protector binding where necessary, and bring 24H2 or 25H2 devices to KB5089549 or a later supported cumulative update.

Quick Recap

SaleBestseller No. 1
Microsoft Windows 11 (USB)
Microsoft Windows 11 (USB)
Make the most of your screen space with snap layouts, desktops, and seamless redocking.; FPP is boxed product that ships with USB for installation
$124.00
SaleBestseller No. 2

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.