He came to us on a recommendation from someone who had run into precisely the same fault — a small but telling detail. In his words, "Bitlocker was deployed to my work PC and it encrypted my external SSD", yet "The encryption process did not complete properly, as a result, I was not provided with a password or recovery key". Encryption that started, handed back no key, and halted midway is a wholly different proposition from a finished, properly-keyed volume — and a colleague meeting the identical failure suggests a policy misfiring across machines, which in turn shapes where the key, if it exists at all, might still be recoverable.
| Media | External SSD caught by a work PC's BitLocker policy — encryption started but not completed, no password or recovery key issued to the owner |
| Reported situation | Corporate BitLocker deployment applied to a personal external drive · process interrupted or failed before completion · no key or password presented at any point · a colleague reporting the identical failure · access to the drive's contents required |
| Fault class | Interrupted full-disk encryption — a volume in a partially-converted state where unencrypted regions may remain readable and key material may survive on the initiating system, distinct from a cleanly finished encrypted disk |
| Equipment used | Drive imaged under a hardware write-blocker before any interpretation · BitLocker metadata parsed from the image to read the conversion state and how far encryption progressed · unencrypted regions identified and recovered directly where conversion did not reach them · conversion state and unencrypted regions confirmed at hex level in X-Ways Forensics · the initiating PC's escrow examined — Active Directory, Azure AD or a recovery key backup where corporate policy stored one · dislocker and native tooling applied against the image where valid key material is located |
Full-disk encryption converts a drive gradually, and an interrupted conversion is caught in the act. BitLocker works through a volume sector by sector; a process that failed partway leaves the drive genuinely half-and-half — some regions encrypted, others still in the clear exactly as they were. Reading the metadata reveals how far it got, and everything it never reached is recoverable without any key at all.
"No key was provided" has two meanings, and they must be separated carefully. Either the key exists but was never shown to him — held in the corporate escrow that deployed the policy — or the failure was severe enough that no usable key was ever generated. The first is an administrative retrieval; the second makes the encrypted portion unrecoverable. Which one applies is established before anything is promised, never assumed hopefully.
The colleague with the identical fault is a substantive clue, not small talk. A policy misfiring the same way across multiple machines points at a systemic deployment problem — and organisations that push BitLocker almost always configure it to escrow recovery keys centrally, in Active Directory or Azure AD. The key he was "not provided" may be sitting in his employer's directory, one IT request away, which is the first and cheapest avenue to exhaust.
The partial state is the technical gift here. A cleanly completed BitLocker volume with a truly lost key is beyond reach, full stop. This drive is not that: the incomplete conversion means a meaningful fraction of the data is readable directly, and whatever sat in the unencrypted regions comes back regardless of how the key question resolves.
Imaging protects a fragile intermediate state. A partially-converted volume is delicate — a mounting attempt or a resumed conversion could push encryption further across the still-readable regions, destroying the very data that is currently accessible. Working only from a write-blocked image freezes the drive exactly where the failure left it, and every extraction and key attempt happens on copies.
The honest split is laid out up front. The unencrypted portion is recoverable now; the encrypted portion depends entirely on whether valid key material surfaces from the corporate escrow. Best case, the key is in the directory and the whole drive opens. Realistic case, the readable regions come back and the rest waits on IT. Worst case, no key was ever made and the encrypted part is sealed — each stated plainly before work, not after.
The drive was imaged under a hardware write-blocker, and its BitLocker metadata parsed from the image to establish the conversion state and progress. Unencrypted regions were identified and recovered directly. The employer's escrow — Active Directory, Azure AD, or a policy key backup — was examined for recovery material, and dislocker with native tooling was applied against the image wherever a valid key was located, all extractions verified.
Conversion state read, the readable portion recovered directly, and the encrypted remainder resolved against the corporate escrow where the key survived. Free assessment, one fixed written figure including VAT; where recovery is not possible, nothing is charged. The decode: a completed BitLocker volume with a lost key is sealed — yours never finished. The half it never reached is readable now, and the key you were never handed is most likely in your employer's directory, not gone.
Stop mounting or retrying the drive — resuming an interrupted conversion can encrypt the regions still readable, destroying data you can currently reach. Ask your IT department for the BitLocker recovery key from Active Directory or Azure AD before assuming it is lost; corporate deployments almost always escrow keys centrally, and a colleague with the same fault suggests a policy issue they need to know about anyway. Preserve the drive as-is so the partially-encrypted state, and everything readable in it, is not disturbed.
Our case files are written up from genuine enquiries our lab has handled for customers across Sheffield and South Yorkshire, anonymised to protect client confidentiality. Each one describes the diagnostic and recovery approach our engineers apply to that fault, using the equipment listed.
Free diagnostic, fixed quote, no fix no fee — start now or call the freephone.