A Surface Pro 4 has halted at the blue recovery screen — "bitlocker has engaged on it". The same thing happened once before, when "by following some simple online instructions I was able to bypass it"; the difference this time is that "I am not able to use the keyboard". Held on the device are "all the photos on from my previous phones", "my photography portfolio" and years of college work. What he remembers as a bypass was almost certainly the recovery key being located and entered — so the key exists, it is stored somewhere within his reach, and today's obstacle is an input problem wearing an encryption costume.
| Media | Microsoft Surface Pro 4 with soldered internal SSD, BitLocker recovery prompt at boot, detachable keyboard non-functional |
| Reported situation | BitLocker recovery screen on startup · same prompt resolved once before by the owner using online guidance · Type Cover keyboard now unresponsive · no external backup taken since · phone photo archives, a photography portfolio and academic work on the internal drive |
| Fault class | Encrypted volume awaiting its escrowed recovery key, compounded by failed pre-boot input — an administrative recovery with a hardware workaround, not a code-breaking exercise |
| Equipment used | External USB keyboard at the pre-boot prompt, where the on-screen keyboard is unavailable · Surface UEFI diagnostics to rule the storage and boot path in or out · recovery key located through the Microsoft account that set the device up · once unlocked, the volume imaged under a hardware write-blocker · hash-verified copy before any repair to the machine itself |
The recovery screen is not a fault and not an attack. BitLocker asks for its recovery key when the boot environment no longer matches what the security chip measured — a firmware update, a battery-flat clock, a hardware hiccup. On an aging Surface this is common, and the machine is doing exactly what it was designed to do.
"Bypass" is the wrong memory of the right event. There is no side door around BitLocker, so the simple online instructions that worked last time will have led him to his recovery key — typically sitting in the Microsoft account the device was set up with, or for a student, in an institution's account portal. That key still exists. Nothing about the current situation has consumed it.
The keyboard is this year's actual problem. The pre-boot prompt offers no on-screen keyboard, so a dead Type Cover makes the screen unanswerable rather than the volume unrecoverable. The Surface's full-size USB port accepts an ordinary wired keyboard at that prompt — a one-cable fix for what feels like a locked door.
The honest limit sits underneath, and it should be said plainly. The SSD is soldered to the board and the encryption is bound to the machine's security chip. If the key were genuinely gone — deleted from every account, never printed — no laboratory could open the volume, and anyone claiming otherwise for money should be walked away from. The entire recovery rests on the key existing, which in escrowed setups like his it almost always does.
Once the volume unlocks, the priority is a copy before anything else. A machine that has thrown recovery prompts twice is telling you something about its reliability. The first act after entry is a complete image under a write-blocker — portfolio, phone archives, coursework — so the next prompt, whenever it comes, is an inconvenience instead of a crisis.
An external USB keyboard was connected at the recovery prompt and the device confirmed to accept input, with Surface UEFI diagnostics run to check the storage and boot path. The recovery key was located through the Microsoft account that set the device up and entered at the prompt. With the volume unlocked, the drive was imaged in full under a hardware write-blocker and the copy hash-verified before any further work on the machine.
Input restored with a wired keyboard, the escrowed key retrieved and entered, and the full volume imaged and verified. Free assessment, one fixed written figure including VAT; where recovery is not possible, nothing is charged. The decode: you answered this question once before, which proves the key exists. This time the keyboard failed, not the encryption — and the right response to a machine that asks twice is a verified copy that makes the third time irrelevant.
Don't reset, reinstall, or accept any option that offers to wipe and start again — the data survives only as long as the encrypted volume does. Check the Microsoft account the device was set up with for the recovery key, and if a school or employer provided the machine, their portal. If the keyboard won't respond at the prompt, a basic wired USB keyboard usually will. And treat a recovery prompt as a warning shot: once you are back in, make the backup that turns the next one into nothing.
Our case files are written up from genuine enquiries our lab has handled for customers across Sheffield and South Yorkshire, anonymised to protect client confidentiality. Each one describes the diagnostic and recovery approach our engineers apply to that fault, using the equipment listed.
Free diagnostic, fixed quote, no fix no fee — start now or call the freephone.