What should a company do before activating BitLocker?

Before enabling BitLocker, confirm that each recovery key is associated with the correct device and backed up in a controlled administrative location, such as Microsoft Entra ID or Active Directory depending on the environment. The key must not exist only inside the encrypted device.

Risks to review

  • Lose permanent access to data because no valid recovery key exists.
  • Send complete keys by email or chat without validating the requester.
  • Suspend BitLocker for an update and forget to resume protection.
  • Use the key for the wrong device because its identifier was not verified.

Safe recommendations

  1. Register computer, user, key identifier and administrative location.
  2. Verify the key copy before encrypting, updating firmware, or changing hardware.
  3. When recovery appears, note the displayed ID and confirm the user's identity.
  4. Investigate what change caused the request before continuing normally.
  5. After using a key in an incident, consider rotating it and backing up the new one.
  6. Periodically review that all encrypted computers have a recoverable key.

When to seek specialized help

  • A key that matches the displayed identifier does not appear.
  • The computer contains critical information without backup and does not start.
  • Recovery started after an unauthorized change or possible tampering.

Reference sources

These public sources provide general good-practice guidance. They do not replace an assessment of your environment.