Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Microsoft documented a BitLocker recovery and boot-repair problem linked to the May 13, 2025 Windows 10 update KB5058379—but only on a narrow class of Intel systems. The issue involved Intel Trusted Execution Technology (TXT) enabled on 10th-generation-or-later Intel vPro processors. Microsoft says the problem was fixed by updates released May 19, 2025 and later. KB5058379 is now expired and unavailable through Microsoft’s listed release channels.

Did KB5058379 trigger a BitLocker recovery screen?

It may have, if the computer matched Microsoft’s documented hardware and security conditions and the failure began after installing KB5058379. The May 13, 2025 update applied to Windows 10 version 22H2 and specified LTSC editions, but the documented BitLocker issue was not a general problem affecting every Windows 10 PC.

Microsoft described the affected configuration as a device with Intel Trusted Execution Technology (TXT) enabled on a 10th-generation-or-later Intel vPro processor. The update could cause lsass.exe to terminate unexpectedly, potentially starting Automatic Repair. If BitLocker was enabled, the recovery key might be needed to start that repair. Microsoft said consumer devices typically do not use Intel vPro processors and were less likely to be affected.

Compare the symptoms and configuration

  • Update: Check whether the device installed KB5058379, associated with Windows 10 OS builds 19044.5854 and 19045.5854.
  • Processor and security settings: Determine whether the device has a 10th-generation-or-later Intel vPro processor and whether Intel TXT is enabled. A model name by itself does not establish that both conditions are met.
  • Protection: Check whether BitLocker was enabled on the system drive.
  • Failure pattern: Compare what happened with Microsoft’s description: unexpected LSASS termination followed by Automatic Repair, a BitLocker recovery prompt, or a repair reboot loop.

Microsoft described two boot outcomes. In one, Windows might retry installing KB5058379 before Startup Repair successfully rolled back to the previous update. In another, Startup Repair might fail, repeatedly reboot, and return to the BitLocker recovery screen. Other errors may have different causes, so a recovery prompt alone does not prove KB5058379 was responsible.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
#1 Best Overall
Password Reset Recovery USB for Windows 11 ,10 ,8.1 ,7 ,Vista , XP, Server Compatible with all brands of PC Laptops and Desktops
  • [MISSING OR FORGOTTEN PASSWORD?] Are you locked out of your computer because of a lost or forgotten password or pin? Don’t’ worry, PassReset USB will reset any Windows User Password or PIN instantly, including Administrator. 100% Success Rate!
  • [EASY TO USE] 1: Boot PC from the PassReset USB drive. 2: Select the User account to reset password. 3: Click “Remove Password”. That’s it! Your computer is unlocked.
  • [COMPATIBILITY] This USB will reset any user passwords including administrator on all versions of Windows including 11, 10, 8, 7, Vista, Server. Also works on all PC Brands that have Windows as an operating system.
  • [SAFE] This USB will reset any Windows User password instantly without having to reinstall your operating system or lose any data. Other Passwords such as Wi-Fi, Email Account, BIOS, Bitlocker, etc are not supported.

Why is Windows asking for a BitLocker recovery key after an update?

BitLocker protects the drive by checking whether the device’s early-startup state meets its integrity requirements. Changes to boot configuration or early boot components can prevent the Trusted Platform Module (TPM) from releasing the usual unlock key, so Windows asks for recovery information instead. A prompt means Windows needs that information to unlock the encrypted drive; it does not, by itself, mean the drive or its files have been destroyed.

Find the recovery information

Use the recovery information saved for that device. Depending on how BitLocker was set up, it may be stored in a Microsoft Account, on a USB drive as a key file, or by an organization in Active Directory Domain Services (AD DS) or Microsoft Entra ID. If the computer is managed by work or school, contact the organization’s IT administrator.

Rank #2
Sale
Thetis Nano-A FIDO2 Security Key Hardware Passkey Device with USB Type A, TOTP/HOTP, FIDO2.0 Two Factor Authentication 2FA MFA, Works with Windows/mac/iOS/Android/Linux/Gmail/Facebook/GitHub/Coinbase
  • Ultra-Compact FIDO2 Security Key - Plug-and-stay or carry on a keychain. This USB-A hardware security key offers portable, always-on protection for desktop and mobile use. (Item Size: 0.75 X 0.74 IN x 0.25 IN)
  • USB-A Hardware Key for All Devices - Works with USB-A ports on PC, Mac, Android, and other laptop/notebook device. Enables secure, cross-platform login with FIDO2.0 passkey support.
  • FIDO Certified Security Key - Meets FIDO and FIDO2 standards. Works with Google, Microsoft, GitHub, Dropbox, and more. Please check service compatibility before purchase.
  • Passwordless Login with Passkey - Supports passkey login via WebAuthn and CTAP2. Enjoy password-free sign-ins where supported. Not all websites or services currently support passkeys.
  • Advanced Multi-Factor Authentication - Offers 200 FIDO2 passkey slots and 50 OATH-TOTP slots. Strong, flexible 2FA/MFA support across various apps and authentication platforms.

Microsoft lists recovery passwords and USB key files among the available recovery methods. A USB recovery drive used to reinstall or recover Windows is a different tool: Microsoft’s cited USB recovery-image instructions are for Surface devices, and creating or using recovery media does not fix the KB5058379 update bug.

Which update fixed the KB5058379 boot issue?

Microsoft says the issue was resolved by Windows updates released May 19, 2025 and later. The May 19 out-of-band update, KB5061768, brought Windows 10 builds 19044 and 19045 to 19044.5856 and 19045.5856, respectively. Its release notes explicitly identify the Intel TXT and vPro LSASS/BitLocker issue as fixed.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Rank #3
FIDO2 U2F Security Key Passkey Two-Factor Authentication (2FA) USB Key PIN+Touch (Non-Biometric) USB-A Type TrustKey T110
  • Security Key : Protect your online accounts against unauthorized access by using FIDO2 and U2F authentication with T110. It's the world's most protective security key that works with windows, Mac OS, Linux as well as Chrome, Firefox, Edge and many other major browsers.
  • Certified with the new FIDO2 standard, T110 provides the benefit of fast login and strong protection against phishing, account takeover as well as many other online attactks.
  • Works with : Bank of America, Github, Google, Microsoft, DUO, Twitter, Facebook, Dropbox, Apple, ebay, BINANCE, mor and more.
  • Fits USB-A port : Insert the T110 security key into the USB-A port of each service and log in conveniently with one touch
  • For the driver download and user guide, please visit TrustKey Solutions Home support page.

If you are troubleshooting a device now, check Windows Update and install the latest update applicable to that device and edition. Do not try to obtain KB5058379 as a remedy: Microsoft’s release notes say that, as of March 31, 2026, the update is no longer available from the Microsoft Update Catalog or other listed release channels.

Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

What Windows 10’s support end means now

Microsoft ended standard Windows 10 support on October 14, 2025. After that date, free Windows Update software updates, technical assistance, and security fixes for Windows 10 ended. This is separate from any extended servicing arrangement a device may have; the cited support notice describes the end of standard support.

Best Value
Thetis PRO-A for Business - USB A FIDO2 Security Key L1 MFA & Passkey Access for School ERP, Employee Online Account, Compatible with Coinbase Google Workspace Apple ID Window Salesfore - 2 Pack
  • FIDO2 & Passkey Ready: Business-ready and FIDO2 L1 certified. This key is supported by major management suites and is ideal for both individual and enterprise deployment. Works seamlessly with Gmail, Facebook, GitHub, Dropbox, Coinbase, and more.
  • Dedicated Manager App: Use the Thetis Manager App for the initial hardware PIN setup. Setting the PIN on the device first ensures a smooth registration process. Once the PIN is configured, you can begin registering the key across your favorite FIDO2-compatible online services.
  • Universal Connectivity (USB-A & NFC): The Thetis PRO-A features integrated USB Type A and NFC for a near-instant account unlock. Simply unfold the key and hold it to your smartphone’s NFC antenna to authenticate on the go.
  • Enhanced MFA (FIDO2 & TOTP/HOTP): Strengthen your security with flexible options. Use the Manager App to access TOTP/HOTP features for accounts that do not yet support FIDO2.
  • Check FIDO2 compatibility before purchase - Known limitations: ID Austria is not supported (requires FIDO2 Level 2). Windows Hello login only works with Windows Enterprise editions that support Entra ID. NFC is supported only through mobile authentication, Not MacOS/windows.
Rank #4
FIDO2 U2F Security Key Passkey Two-Factor Authentication (2FA) USB Key PIN+Touch (Non-Biometric) USB-C Type TrustKey T120
  • Security Key : Protect your online accounts against unauthorized access by using FIDO2 and U2F authentication with T120. It's the world's most protective security key that works with windows, Mac OS, Linux as well as Chrome, Firefox, Edge and many other major browsers.
  • Certified with the new FIDO2 standard, T120 provides the benefit of fast login and strong protection against phishing, account takeover as well as many other online attactks.
  • Works with : Bank of America, Github, Google, Microsoft, DUO, Twitter, Facebook, Dropbox, Apple, ebay, BINANCE, mor and more.
  • Fits USB-C port : Insert the T120 security key into the USB-C port of each service and log in conveniently with one touch
  • For the driver download and user guide, please visit TrustKey Solutions Home support page.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.