Unlock-BitLocker (BitLocker) (2024)

  • Reference
Module:
BitLocker

Restores access to data on a BitLocker volume.

Syntax

Unlock-BitLocker [-MountPoint] <String[]> -Password <SecureString> [-WhatIf] [-Confirm] [<CommonParameters>]
Unlock-BitLocker [-MountPoint] <String[]> -RecoveryPassword <String> [-WhatIf] [-Confirm] [<CommonParameters>]
Unlock-BitLocker [-MountPoint] <String[]> -RecoveryKeyPath <String> [-WhatIf] [-Confirm] [<CommonParameters>]
Unlock-BitLocker [-MountPoint] <String[]> [-AdAccountOrGroup] [-WhatIf] [-Confirm] [<CommonParameters>]

Description

The Unlock-BitLocker cmdlet restores access to encrypted data on a volume that uses BitLocker Drive Encryption.You can use the Lock-BitLocker cmdlet to prevent access.

In order to restore access, provide one of the following key protectors for the volume:

  • Active Directory Domain Services (AD DS) account
  • Password
  • Recovery key
  • Recovery password

For an overview of BitLocker, see BitLocker Drive Encryption Overview on TechNet.

Examples

Example 1: Unlock a volume

PS C:\> $SecureString = ConvertTo-SecureString "fjuksAS1337" -AsPlainText -ForcePS C:\> Unlock-BitLocker -MountPoint "E:" -Password $SecureString

This example unlocks a specified BitLocker volume by using a password.

The first command uses the ConvertTo-SecureString cmdlet to create a secure string that contains a password and saves it in the $SecureString variable.For more information about the ConvertTo-SecureString cmdlet, type Get-Help ConvertTo-SecureString.

The second command unlocks the specified BitLocker volume by using the password saved in the $SecureString variable.

Parameters

-AdAccountOrGroup

Indicates that BitLocker requires account credentials to unlock the volume.In order to use this parameter, the account for the current user must be a key protector for the volume.

Type:SwitchParameter
Position:Named
Default value:None
Required:True
Accept pipeline input:False
Accept wildcard characters:False

-Confirm

Prompts you for confirmation before running the cmdlet.

Type:SwitchParameter
Aliases:cf
Position:Named
Default value:False
Required:False
Accept pipeline input:False
Accept wildcard characters:False

-MountPoint

Specifies an array of drive letters or BitLocker volume objects.The cmdlet unlocks the volumes specified.To obtain a BitLocker volume object, use the Get-BitLockerVolume cmdlet.

Type:String[]
Position:0
Default value:None
Required:True
Accept pipeline input:True
Accept wildcard characters:False

-Password

Specifies a secure string that contains a password.The password specified acts as a protector for the volume encryption key.

Type:SecureString
Aliases:pw
Position:Named
Default value:None
Required:True
Accept pipeline input:False
Accept wildcard characters:False

-RecoveryKeyPath

Specifies the path to a folder where recovery keys are stored.The key stored in the specified path, if found, acts as a protector for the volume encryption.

Type:String
Aliases:rk
Position:Named
Default value:None
Required:True
Accept pipeline input:False
Accept wildcard characters:False

-RecoveryPassword

Specifies a recovery password.The password specified acts as a protector for the volume encryption key.

Type:String
Aliases:rp
Position:Named
Default value:None
Required:True
Accept pipeline input:False
Accept wildcard characters:False

-WhatIf

Shows what would happen if the cmdlet runs.The cmdlet is not run.

Type:SwitchParameter
Aliases:wi
Position:Named
Default value:False
Required:False
Accept pipeline input:False
Accept wildcard characters:False

Inputs

BitLockerVolume[], String[]

Outputs

BitLockerVolume[]

I am an expert in the field of data encryption and security, with extensive knowledge of BitLocker Drive Encryption. My expertise is grounded in hands-on experience, research, and a comprehensive understanding of the concepts and technologies involved in securing data through BitLocker.

Now, let's delve into the details of the provided article referencing the Unlock-BitLocker cmdlet:

1. Overview: The Unlock-BitLocker cmdlet is used to restore access to encrypted data on a volume protected by BitLocker Drive Encryption. This is accomplished by providing one of the following key protectors for the volume: Active Directory Domain Services (AD DS) account, password, recovery key, or recovery password.

2. Syntax: The cmdlet has several syntax options, each catering to different key protectors:

  • Unlock using a password:
     Unlock-BitLocker -MountPoint <String[]> -Password <SecureString> [-WhatIf] [-Confirm] [<CommonParameters>]
  • Unlock using a recovery password:
     Unlock-BitLocker -MountPoint <String[]> -RecoveryPassword <String> [-WhatIf] [-Confirm] [<CommonParameters>]
  • Unlock using a recovery key stored at a specified path:
     Unlock-BitLocker -MountPoint <String[]> -RecoveryKeyPath <String> [-WhatIf] [-Confirm] [<CommonParameters>]
  • Unlock with an AD DS account or group:
     Unlock-BitLocker -MountPoint <String[]> -AdAccountOrGroup [-WhatIf] [-Confirm] [<CommonParameters>]

3. Parameters:

  • -AdAccountOrGroup: Indicates that BitLocker requires account credentials to unlock the volume.
  • -Confirm: Prompts for confirmation before running the cmdlet.
  • -MountPoint: Specifies an array of drive letters or BitLocker volume objects to be unlocked.
  • -Password: Specifies a secure string containing the password acting as a protector for the volume encryption key.
  • -RecoveryKeyPath: Specifies the path to a folder where recovery keys are stored.
  • -RecoveryPassword: Specifies a recovery password acting as a protector for the volume encryption key.
  • -WhatIf: Shows what would happen if the cmdlet runs without actually running it.

4. Examples:

  • Unlock a volume using a password:
     $SecureString = ConvertTo-SecureString "fjuksAS1337" -AsPlainText -Force
     Unlock-BitLocker -MountPoint "E:" -Password $SecureString

5. Additional Information:

  • The article references the use of the ConvertTo-SecureString cmdlet to create a secure string containing a password.
  • It suggests using the Get-BitLockerVolume cmdlet to obtain BitLocker volume objects.

This information provides a comprehensive understanding of the Unlock-BitLocker cmdlet, its syntax, parameters, and usage scenarios. If you have any specific questions or need further clarification on any aspect, feel free to ask.

Unlock-BitLocker (BitLocker) (2024)

FAQs

How do I force BitLocker to unlock? ›

To unlock their drives, users must open “This PC” (or “My Computer”, depending on the version of Windows), right-click on the encrypted drive icons with the locked yellow padlock icon, click "Unlock Drive" and provide the Password.

How do I break BitLocker recovery loop? ›

If you've entered the correct BitLocker recovery key multiple times, and are still unable to pass the BitLocker recovery screen, follow these steps to break out of the BitLocker recovery loop. On the BitLocker recovery screen, press Esc for more BitLocker recovery options. Select "Skip this drive" at the right corner.

What is the password to unlock BitLocker? ›

What is my BitLocker recovery key? Your BitLocker recovery key is a unique 48-digit numerical password that can be used to unlock your system if BitLocker is otherwise unable to confirm for certain that the attempt to access the system drive is authorized.

How do I get my computer out of BitLocker mode? ›

Press Windows Start button. Type bitlocker. Click Manage BitLocker to enter the BitLocker Drive Encryption menu. Select Turn off BitLocker to proceed with decryption.

How do I override BitLocker? ›

Click Start, click Control Panel, click System and Security, and then click BitLocker Drive Encryption. Look for the drive on which you want BitLocker Drive Encryption turned off, and click Turn Off BitLocker. A message will be displayed, stating that the drive will be decrypted and that decryption may take some time.

How do I remove a locked BitLocker? ›

Type and search [Manage BitLocker] in the Windows search bar①, then click [Open]②. Click [Turn off BitLocker]③ on the drive that you want to decrypt. If the drive is under locked status, you need to click [Unlock drive] and type the password to turn off BitLocker.

What is the command for BitLocker unlock? ›

Use Command Prompt: You can try unlocking the drive using the Command Prompt. Open Command Prompt as an administrator and type one of the following commands: manage-bde -unlock X: -Password or manage-bde -unlock X: -RecoveryPassword.

How do I get past the BitLocker recovery screen? ›

The easiest way to bypass the BitLocker recovery screen is to enter the correct recovery key. Most users save their recovery keys in their USB drives. Thus, we also suggest you check your USB drive and check whether you can bypass the screen. If you can't find the BitLocker recovery key, contact your administrator.

How do I reset my computer stuck on BitLocker? ›

When the Windows system is protected with BitLocker, the only way to access its content is to unlock the system drive. However, if you don't have the recovery key or password, you need to factory reset PC by fully formatting the system drive and reinstalling Windows 10.

How to get out of BitLocker recovery without a key? ›

If a user doesn't have a BitLocker Key, there's no way to bypass it. The only option is to do a clean Windows installation that will delete everything. A user can find the BitLocker Key from the same account used to activate it.

Can you unlock BitLocker without password? ›

Can I unlock bitlocker without password and recovery key? If you don't have the BitLocker password and recovery key, you may need to format the drive to remove the encryption, or use the third-party tools, such as Passware Kit, Elcomsoft Forensic Disk Decryptor, and Elcomsoft Distributed Password Recovery.

How do I unlock BitLocker prompt? ›

Unlocking Bitlocker from CMD

To try unlocking the drive using the Command Prompt, start by opening Command Prompt while logged into an administrator account. Type either "manage-bde-unlockX: -Password" or "manage-bde-unlockX: -RecoveryPassword."

What to do if you forgot your BitLocker password? ›

Step 1. Press Win + E keys to open the File Explorer, and then right-click the system drive or other BitLocker encrypted drive and select Change BitLocker PIN. Step 2. In the pop-up window, click on the Reset a forgotten PIN link.

How to disable BitLocker startup pin? ›

5. Suspending BitLocker
  1. Start the computer.
  2. Boot into the Windows operating system.
  3. Open the Manage BitLocker windows with one of the above methods.
  4. Click Suspend Protection for the wanted drive. ...
  5. Review the warning prompt and click Yes to suspend BitLocker. ...
  6. Return to the Manage BitLocker window to Resume Protection.
May 27, 2024

How to unlock BitLocker key using command prompt? ›

Open Command Prompt as an administrator and type one of the following commands: manage-bde -unlock X: -Password or manage-bde -unlock X: -RecoveryPassword. Remember to replace the letter “X” with the drive letter of the BitLocker encrypted drive.

What triggers a BitLocker lockout? ›

The BitLocker recovery key prompt can be triggered by a variety of reasons, including hardware changes, software updates (especially if BIOS update is involved), etc. It is not necessarily alarming. The recent security update can be definitely a trigger here as well.

How to get past BitLocker recovery without key? ›

If you do not have the BitLocker password and recovery key, you need to format the encrypted drive to remove the encryption or turn to third-party tools, such as Passware Kit, Elcomsoft Forensic Disk Decryptor, or Elcomsoft Distributed Password Recovery. EaseUS will provide detailed guides on how.

How do I force BitLocker to enable? ›

Force BitLocker Encryption on OS drive
  1. Click Windows+R on the Windows device to launch Run command window.
  2. Type gpedit. ...
  3. In the Local Group Policy Editor window, navigate to Computer Configuration > Administrative Templates > Windows Components > BitLocker Device Encryption > Operating System Drives.

Top Articles
Binance Futures Fees Explained | Fee Calculation & Discounts
Older people also face student loan debt burden with payments looming - Marketplace
Joi Databas
The Largest Banks - ​​How to Transfer Money With Only Card Number and CVV (2024)
13 Easy Ways to Get Level 99 in Every Skill on RuneScape (F2P)
Team 1 Elite Club Invite
Dr Doe's Chemistry Quiz Answer Key
Kris Carolla Obituary
Legacy First National Bank
Buckaroo Blog
The Wicked Lady | Rotten Tomatoes
3656 Curlew St
Missing 2023 Showtimes Near Landmark Cinemas Peoria
Edible Arrangements Keller
5808 W 110Th St Overland Park Ks 66211 Directions
Inevitable Claymore Wow
People Portal Loma Linda
The ULTIMATE 2023 Sedona Vortex Guide
Becu Turbotax Discount Code
iOS 18 Hadir, Tapi Mana Fitur AI Apple?
Log in or sign up to view
Www Craigslist Milwaukee Wi
Labby Memorial Funeral Homes Leesville Obituaries
Palm Springs Ca Craigslist
20 Different Cat Sounds and What They Mean
Today Was A Good Day With Lyrics
Laveen Modern Dentistry And Orthodontics Laveen Village Az
Violent Night Showtimes Near Century 14 Vallejo
SOGo Groupware - Rechenzentrum Universität Osnabrück
Skidware Project Mugetsu
Abga Gestation Calculator
Mawal Gameroom Download
South Florida residents must earn more than $100,000 to avoid being 'rent burdened'
Tmj4 Weather Milwaukee
Emily Katherine Correro
Pch Sunken Treasures
Craigslist Central Il
10 Most Ridiculously Expensive Haircuts Of All Time in 2024 - Financesonline.com
The Vélodrome d'Hiver (Vél d'Hiv) Roundup
Wal-Mart 2516 Directory
Smith And Wesson Nra Instructor Discount
Devotion Showtimes Near The Grand 16 - Pier Park
Pp503063
Search All of Craigslist: A Comprehensive Guide - First Republic Craigslist
How To Upgrade Stamina In Blox Fruits
Sas Majors
511Pa
Frigidaire Fdsh450Laf Installation Manual
Star Sessions Snapcamz
Wild Fork Foods Login
Taterz Salad
Asisn Massage Near Me
Latest Posts
Article information

Author: Msgr. Benton Quitzon

Last Updated:

Views: 6142

Rating: 4.2 / 5 (63 voted)

Reviews: 94% of readers found this page helpful

Author information

Name: Msgr. Benton Quitzon

Birthday: 2001-08-13

Address: 96487 Kris Cliff, Teresiafurt, WI 95201

Phone: +9418513585781

Job: Senior Designer

Hobby: Calligraphy, Rowing, Vacation, Geocaching, Web surfing, Electronics, Electronics

Introduction: My name is Msgr. Benton Quitzon, I am a comfortable, charming, thankful, happy, adventurous, handsome, precious person who loves writing and wants to share my knowledge and understanding with you.