What should a company do before activating BitLocker?
Before enabling BitLocker, confirm that each recovery key is associated with the correct device and backed up in a controlled administrative location, such as Microsoft Entra ID or Active Directory depending on the environment. The key must not exist only inside the encrypted device.
Risks to review
- Lose permanent access to data because no valid recovery key exists.
- Send complete keys by email or chat without validating the requester.
- Suspend BitLocker for an update and forget to resume protection.
- Use the key for the wrong device because its identifier was not verified.
Safe recommendations
- Register computer, user, key identifier and administrative location.
- Verify the key copy before encrypting, updating firmware, or changing hardware.
- When recovery appears, note the displayed ID and confirm the user's identity.
- Investigate what change caused the request before continuing normally.
- After using a key in an incident, consider rotating it and backing up the new one.
- Periodically review that all encrypted computers have a recoverable key.
When to seek specialized help
- A key that matches the displayed identifier does not appear.
- The computer contains critical information without backup and does not start.
- Recovery started after an unauthorized change or possible tampering.
Reference sources
These public sources provide general good-practice guidance. They do not replace an assessment of your environment.

