Recommended Free Tools
iTechGuides is reader-supported. When you buy through links on our site, we may earn an affiliate commission. As an Amazon Associate I earn from qualifying purchases. Learn more
If Windows 11 asks for your BitLocker recovery key after every restart, first confirm you can access the key. Then check your UEFI boot order: Microsoft documents a recurring recovery problem when PXE or network boot is ahead of the local Windows Boot Manager. Put Windows Boot Manager first, or disable PXE if you do not use it. A single prompt after a Secure Boot update is a different, usually temporary case.
First, distinguish a one-time prompt from a prompt on every restart
A recovery prompt immediately after a Secure Boot update does not necessarily indicate a persistent fault. Microsoft says firmware may not report the updated Secure Boot values on the first boot while Windows reseals BitLocker. In that specific case, enter the recovery key; later restarts should work normally. If the prompt returns at every restart, investigate the boot path and configuration rather than treating it as the one-time update behavior. Microsoft’s Secure Boot troubleshooting guide describes both the recurring PXE-first scenario and update-related behavior.
Make sure you have the recovery key before changing settings
Do not change firmware, boot order, or Secure Boot settings until you have confirmed that the recovery key is available. BitLocker can request recovery after hardware, firmware, or software changes it cannot distinguish from a possible attack. Without the key, the drive’s contents remain unreadable, and many Windows Recovery Environment options require it when BitLocker is enabled. See Microsoft’s BitLocker overview and Windows recovery options.
Check whether network boot comes before Windows Boot Manager
Microsoft documents a Secure Boot scenario in which the device enters BitLocker recovery on every boot when PXE/network boot is ordered ahead of local disk boot. If the PXE attempt fails and the computer then starts Windows locally, the two paths can use different signing authorities. The resulting TPM measurements may not be stable from one boot to the next.
#1 Best Overall
- Does Not Fix Hardware Issues - Please Test Your PC hardware to be sure everything passes before buying this USB Windows 11 Software Recovery USB.
- Make sure your PC is set to the default UEFI Boot mode, in your BIOS Setup menu. Most all PC made after 2013 come with UEFI set up and enabled by Default
- Does Not Include A KEY CODE, LICENSE OR A COA. Use your Windows KEY to preform the REINSTALLATION option
- Free tech support
- Restart the PC and enter UEFI firmware settings. The key or startup method varies by manufacturer; follow the PC maker’s instructions.
- Open the firmware’s boot-priority or boot-order settings. Look for PXE, network boot, or a network adapter listed ahead of Windows Boot Manager.
- Move Windows Boot Manager ahead of network boot. If you do not use PXE, disable network boot.
- Save the change and restart to check whether Windows starts without another recovery prompt.
If your organization requires PXE, do not simply disable it. Microsoft’s guidance identifies a PXE boot loader using the 2023 signing authority as the relevant option for this scenario. Ask your IT administrator to check the network boot setup. Do not reset Secure Boot to firmware defaults as a routine fix: on affected devices, that can remove certificates needed by a 2023-signed Windows boot manager. See the Microsoft Secure Boot troubleshooting guide.
Open UEFI settings through Windows if needed
If you can reach Windows, use its Advanced startup menu to get to the firmware settings:
- Open Settings > System > Recovery.
- Next to Advanced startup, select Restart now.
- Choose Troubleshoot > Advanced options > UEFI Firmware Settings, then restart if prompted.
- In UEFI, adjust the boot priority as described above, following your PC manufacturer’s directions for the firmware controls.
Microsoft’s Windows 11 and Secure Boot guidance covers Secure Boot and firmware navigation. If you temporarily disable Secure Boot to address a specific issue, Microsoft recommends turning it back on afterward. Firmware menus vary by device, so do not assume that a setting has the same name or location on every PC.
Free tools Windows power users keep installed
One-click scans. No signup required.
Check for the narrow PCR7 policy case only if it matches your PC
Microsoft’s April 14, 2026 update notes describe a separate case involving a TPM platform validation policy that explicitly includes PCR7. The described device has msinfo32.exe reporting PCR7 Binding as “Not Possible,” and the Windows UEFI CA 2023 certificate is present. Under those conditions, the recovery key may be needed once, with later restarts expected not to prompt as long as the policy remains unchanged.
Rank #2
- 🔑 RESET WINDOWS PASSWORDS IN MINUTES Quickly reset forgotten local Windows user and administrator passwords without reinstalling Windows or losing important files. Fast and simple offline recovery process.
- 💻 WORKS WITH MOST WINDOWS PCS & LAPTOPS Compatible with many Windows desktop and laptop systems. Supports USB boot startup for convenient and reliable password recovery access.
- ⚡ EASY PLUG & PLAY USB DESIGN No complicated setup required. Simply insert the USB, boot from it, and follow the included step-by-step instructions to reset passwords quickly.
- 🔒 SAFE OFFLINE PASSWORD RECOVERY Runs completely offline with no internet connection required. Helps protect your privacy while keeping your files and operating system intact.
- 🛠 BEGINNER-FRIENDLY WITH INCLUDED INSTRUCTIONS Designed for home users, students, technicians, and IT professionals. Includes easy-to-follow written instructions and boot menu guidance for hassle-free recovery.
This guidance is not a general fix for repeated prompts. If your PC meets those conditions, review applicable Group Policy and PCR7 status with your organization’s administrator. The same update notes describe temporarily suspending BitLocker when installing the new boot manager; do not apply that step to a device that does not match the documented case. See Microsoft’s April 14, 2026 Windows 11 update notes.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Use the Secure Boot recovery USB only for its documented failure
A USB drive is not a general remedy for a BitLocker recovery prompt. Microsoft’s Secure Boot recovery utility is intended for a specific boot failure after Secure Boot certificate changes. Its procedure requires a second Windows PC with the July 2024 or newer Windows update installed and a FAT32-formatted USB drive:
- On the second PC, copy
SecureBootRecovery.efifromC:WindowsBootEFIto the USB drive’sEFIBOOTfolder. - Rename the copied file to
bootx64.efi. - Boot the affected device from the USB and follow the recovery utility’s instructions.
The utility restores the Windows UEFI CA 2023 certificate. Microsoft cautions that this restores one certificate; it recommends ensuring the latest certificates are reapplied and considering the latest OEM firmware. Follow Microsoft’s exact file placement and naming instructions, and use this procedure only for the Secure Boot failure it addresses. See the Secure Boot troubleshooting guide.
When the prompt continues
If Windows Boot Manager is first and recovery still appears on every restart, avoid repeatedly changing Secure Boot or firmware settings without a diagnosis. Confirm the key remains accessible, note any recent firmware or Secure Boot changes, and consult the PC manufacturer or your IT administrator. A Secure Boot update, a PXE-first boot path, and the narrowly defined PCR7 policy case call for different responses; the correct next step depends on which applies.
Quick Recap
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

