Notebookcheck Logo

Cloud risk with BitLocker: Microsoft occasionally hands over BitLocker keys to the FBI

Microsoft hands over BitLocker keys in the event of a court order. (Symbolic image created with Nano Banana Pro)
Microsoft hands over BitLocker keys in the event of a court order. (Symbolic image created with Nano Banana Pro)
While Apple and Google stress that they cannot unlock customer devices, the situation is different with Windows encryption: Microsoft routinely hands over BitLocker keys from the cloud to law enforcement agencies.

Apple and Google regularly highlight that they are technically unable to unlock their customers' encrypted smartphones or tablets, even if requested to do so by authorities. The situation is more nuanced with Microsoft and its Windows encryption feature, BitLocker. If the user stores the recovery key in the cloud, the company can provide it to law enforcement.

BitLocker is the drive encryption feature integrated into Windows that protects data on hard drives from unauthorized access, such as in the event of device theft. To regain access to the system in an emergency, a recovery key is generated during setup. Windows offers various backup methods for this: the code can be printed, saved to a USB drive, or stored directly in the Microsoft account in the cloud.

If you choose to store your data in your Microsoft account, this data is saved on the Redmond-based company's servers. As Microsoft has confirmed to Forbes, these BitLocker keys are released when a valid court order is presented. The FBI makes about 20 such requests annually. This implies that Microsoft has access to the key data, although it remains unclear whether this data is stored on the servers in plain text or encrypted.

However, cloud storage doesn't necessarily mean that the provider has read access to the data. Technically, the recovery keys could be stored on the servers in such a way that they are encrypted, for example, with a separate password or hash belonging to the user. In this scenario, Microsoft could host the data but would have no way of viewing it in plaintext or sharing it with authorities. Since the company can release the keys upon a court order, such a safeguard clearly does not apply here. This also raises questions about the overall security of recovery keys stored in the cloud.

Microsoft spokesman Charles Chamberlayne noted that while cloud recovery offers convenience, it also carries the risk of unauthorized access. Users must therefore weigh whether such convenience is worth it or to keep the key stored locally.

Source(s)

Please share our article, every link counts!
Mail Logo
Google Logo Add as a preferred
source on Google
static version load dynamic
Loading Comments
Comment on this article
> Expert Reviews and News on Laptops, Smartphones and Tech Innovations > News > News Archive > Newsarchive 2026 01 > Cloud risk with BitLocker: Microsoft occasionally hands over BitLocker keys to the FBI
Marc Herter, 2026-01-24 (Update: 2026-01-24)