{"id":45422,"date":"2026-04-15T20:04:10","date_gmt":"2026-04-15T12:04:10","guid":{"rendered":"https:\/\/nuoya.nuoyayasuo.top\/index.php\/2026\/04\/15\/microsoft-april-updates-trigger-bitlocker-key-prompts-on-some-servers\/"},"modified":"2026-04-15T20:04:10","modified_gmt":"2026-04-15T12:04:10","slug":"microsoft-april-updates-trigger-bitlocker-key-prompts-on-some-servers","status":"publish","type":"post","link":"https:\/\/nuoya.nuoyayasuo.top\/index.php\/2026\/04\/15\/microsoft-april-updates-trigger-bitlocker-key-prompts-on-some-servers\/","title":{"rendered":"Microsoft: April updates trigger BitLocker key prompts on some servers"},"content":{"rendered":"\n<p style=\"text-align:center\"><img loading=\"lazy\" decoding=\"async\" height=\"900\" src=\"https:\/\/www.bleepstatic.com\/content\/hl-images\/2024\/05\/24\/windows-logo-locked.jpg\" width=\"1600\" alt=\"Microsoft: April updates trigger BitLocker key prompts on some servers\"><\/p>\n<p>Microsoft confirmed on Tuesday that some Windows Server 2025 devices will boot into BitLocker recovery after installing the April 2026 KB5082063 Windows security update.<\/p>\n<p>BitLocker is a Windows security feature that encrypts storage drives to prevent data theft. Windows computers typically enter BitLocker recovery mode after hardware changes or events such as TPM (Trusted Platform Module) updates,&nbsp;to regain access to protected drives that have not been unlocked via the default unlock mechanism.<\/p>\n<p>&#8220;Some devices with an unrecommended BitLocker Group Policy configuration might be required to enter their BitLocker recovery key on the first restart after installing this update,&#8221; Microsoft <a href=\"https:\/\/support.microsoft.com\/en-us\/topic\/april-14-2026-kb5082063-os-build-26100-32690-c57e289d-27c9-47cd-a183-72fabc62c5d7#:~:text=Known%20issues%20in%20this%20update\" target=\"_blank\" rel=\"nofollow noopener\">said<\/a>.<\/p>\n<div align=\"center\" style=\"width:98%; margin:0 auto; text-align:center; padding:4px; background:#f0f0f0; border:1px solid #ccc; border-radius:6px;\">  <a href=\"https:\/\/www.adaptivesecurity.com\/demo\/security-awareness-training?utm_source=display_network&amp;utm_medium=paid_display&amp;utm_campaign=2026_04_display_bleepingcomputer&amp;utm_id=701Rd00000fE8REIA0&amp;utm_content=970x250\" rel=\"nofollow noopener\" target=\"_blank\"><img decoding=\"async\" src=\"https:\/\/www.bleepstatic.com\/c\/a\/as-tour-the-platform-970-x250.jpg\" style=\"margin-top: 0px;\" alt=\"Microsoft: April updates trigger BitLocker key prompts on some servers\"><\/a> <\/div>\n<p>&#8220;In this scenario, the BitLocker recovery key only needs to be entered once &#8212; subsequent restarts will not trigger a BitLocker recovery screen, as long as the group policy configuration remains unchanged.&#8221;<\/p>\n<p>However, as the company explained, this only happens for very specific configurations, on systems where all the following conditions are met:<\/p>\n<ol>\n<li>BitLocker is enabled on the OS drive.<\/li>\n<li>The Group Policy &#8220;<strong>Configure TPM platform validation profile for native UEFI firmware configurations<\/strong>&#8221; is configured, and PCR7 is included in the validation profile (or the equivalent registry key is set manually).<\/li>\n<li>System Information (<strong>msinfo32.exe<\/strong>) reports that the Secure Boot State PCR7 Binding is &#8220;<strong>Not Possible<\/strong>&#8220;.<\/li>\n<li>The Windows UEFI CA 2023 certificate is present in the device&#8217;s Secure Boot Signature Database (DB), making the device eligible for the 2023&#8209;signed Windows Boot Manager to be made the default.<\/li>\n<li>The device is not already running the 2023-signed Windows Boot Manager.<\/li>\n<\/ol>\n<p>Microsoft added that this known issue is unlikely to affect personal devices, as impacted configurations are typically found on systems managed by enterprise IT teams.<\/p>\n<div style=\"text-align:center\">\n<figure style=\"display:inline-block\"><img loading=\"lazy\" decoding=\"async\" height=\"315\" src=\"https:\/\/www.bleepstatic.com\/images\/news\/u\/1109292\/2024\/BitLocker%20recovery%20screen.png\" width=\"700\" alt=\"Microsoft: April updates trigger BitLocker key prompts on some servers\"><figcaption><em>BitLocker recovery screen (Microsoft)<\/em><\/figcaption><\/figure>\n<\/div>\n<p>&#8203;The company is now working on a solution to this issue and has shared temporary workarounds that allow installation of this month&#8217;s security updates.<\/p>\n<p>Admins are advised to remove the Group Policy configuration before deploying the KB5082063 update, and to ensure that BitLocker bindings use the PCR7 profile by following <a href=\"https:\/\/support.microsoft.com\/en-us\/topic\/april-14-2026-kb5082063-os-build-26100-32690-c57e289d-27c9-47cd-a183-72fabc62c5d7#:~:text=Option%201,-%3A%20Remove\" target=\"_blank\" rel=\"nofollow noopener\">these steps<\/a>.<\/p>\n<p>Those who can&#8217;t remove the PCR7 group policy before installing can apply a Known Issue Rollback (KIR) on affected devices to prevent the automatic switch to the 2023 Boot Manager and to avoid triggering BitLocker recovery.<\/p>\n<p>In May 2025, Microsoft <a href=\"https:\/\/www.bleepingcomputer.com\/news\/microsoft\/windows-10-emergency-updates-fix-bitlocker-recovery-issues\/\" target=\"_blank\" rel=\"nofollow noopener\">released emergency updates<\/a> to address a similar issue that was causing Windows 10 systems to boot into BitLocker recovery after installing the May 2025 security updates.<\/p>\n<p>One year earlier, in August 2024, Microsoft <a href=\"https:\/\/www.bleepingcomputer.com\/news\/microsoft\/microsoft-fixes-issue-that-sent-pcs-into-bitlocker-recovery\/\" target=\"_blank\" rel=\"nofollow noopener\">fixed another known issue<\/a> triggering BitLocker recovery prompts across all supported Windows versions after <a href=\"https:\/\/www.bleepingcomputer.com\/news\/microsoft\/windows-july-security-updates-send-pcs-into-bitlocker-recovery\/\" target=\"_blank\" rel=\"nofollow noopener\">installing the July 2024 Windows security updates<\/a>.<\/p>\n<p>In August 2022, Windows devices <a href=\"http:\/\/www.reddit.com\/r\/pcmasterrace\/comments\/wkqkmg\/is_the_windows_update_kb5012170_safe_to_install\/\" target=\"_blank\" rel=\"nofollow noopener\">also became stuck at a BitLocker recovery prompt<\/a> after installing the <a href=\"https:\/\/support.microsoft.com\/en-gb\/topic\/kb5012170-security-update-for-secure-boot-dbx-72ff5eed-25b4-47c7-be28-c42bd211bb15#:~:text=If%20BitLocker%20Group%20Policy\" target=\"_blank\" rel=\"nofollow noopener\">KB5012170 security update<\/a>.<\/p>\n<style> .ia_ad {     background-color: #f0f6ff;     width: 95%;     max-width: 800px;     margin: 15px auto;     border-radius: 8px;     border: 1px solid #d6ddee;     display: flex;     align-items: stretch;     padding: 0;     overflow: hidden; }  .ia_lef {     flex: 1;     max-width: 200px;     height: auto;     display: flex;     align-items: stretch; }  .ia_lef a {     display: flex;     width: 100%;     height: 100%; }   .ia_lef a img {     width: 100%;     height: 100%;          border-radius: 8px 0 0 8px;     margin: 0;     display: block; }  .ia_rig {     flex: 2;     padding: 10px;     display: flex;     flex-direction: column;     justify-content: center; }  .ia_rig h2 {     font-size: 17px !important;     font-weight: 700;     color: #333;     line-height: 1.4;     font-family: Georgia, \"Times New Roman\", Times, serif;     margin: 0 0 14px 0; }  .ia_rig p {     font-weight: bold;     font-size: 14px;     margin: 0 0 clamp(6px, 2vw, 14px) 0; }  .ia_button {     background-color: #FFF;     border: 1px solid #3b59aa;     color: black;     text-align: center;     text-decoration: none;     border-radius: 8px;     display: inline-block;     font-size: 16px;     font-weight: bold;     cursor: pointer;     padding: 10px 20px;     width: fit-content; }  .ia_button a {     text-decoration: none;     color: inherit;     display: block; }  @media (max-width: 600px) {     .ia_ad {         flex-direction: column;         align-items: center;     }      .ia_lef {         max-width: 100%;     }      .ia_lef a img {         border-radius: 8px 8px 0 0;     }       .ia_rig {         padding: 15px;         width: 100%;     }      .ia_button {         width: 100%; \tmargin: 0px auto;     } } <\/style>\n<div>\n<div>         <a href=\"https:\/\/hubs.li\/Q048zztN0\" target=\"_blank\" rel=\"noopener sponsored\">             <img decoding=\"async\" src=\"https:\/\/www.bleepingcomputer.com\/news\/microsoft\/microsoft-some-windows-servers-ask-for-bitlocker-key-after-april-updates\/data:image\/gif;base64,R0lGODlhAQABAAAAACH5BAEKAAEALAAAAAABAAEAAAICTAEAOw==\" data-src=\"https:\/\/www.bleepstatic.com\/c\/p\/picus-whitepaper.jpg\" alt=\"Microsoft: April updates trigger BitLocker key prompts on some servers\"><\/a>     <\/div>\n<div>\n<h2><a href=\"https:\/\/hubs.li\/Q048zztN0\" target=\"_blank\" rel=\"noopener sponsored\">Automated Pentesting Covers Only 1 of 6 Surfaces.<\/a><\/h2>\n<p>Automated pentesting proves the path exists. BAS proves whether your controls stop it. Most teams run one without the other.<\/p>\n<p>This whitepaper maps six validation surfaces, shows where coverage ends, and provides practitioners with three diagnostic questions for any tool evaluation.<\/p>\n<p>           <button><a href=\"https:\/\/hubs.li\/Q048zztN0\" target=\"_blank\" rel=\"noopener sponsored\">Get Your Copy Now<\/a><\/button>     <\/div>\n<\/p><\/div>\n<div>\n<h3>Related Articles:<\/h3>\n<p><a href=\"https:\/\/www.bleepingcomputer.com\/news\/microsoft\/microsoft-fixes-bug-behind-windows-server-2025-automatic-upgrades\/\">Microsoft fixes bug behind Windows Server 2025 automatic upgrades<\/a><\/p>\n<p><a href=\"https:\/\/www.bleepingcomputer.com\/news\/microsoft\/new-windows-11-kb5086672-emergency-update-fixes-install-issues\/\">New Windows 11 emergency update fixes preview update install issues<\/a><\/p>\n<p><a href=\"https:\/\/www.bleepingcomputer.com\/news\/microsoft\/microsoft-shares-fix-for-windows-c-drive-access-issues-on-samsung-pcs\/\">Microsoft shares fix for Windows C: drive access issues on Samsung PCs<\/a><\/p>\n<p><a href=\"https:\/\/www.bleepingcomputer.com\/news\/microsoft\/kb5079473-march-windows-11-update-breaks-microsoft-account-sign-ins\/\">Microsoft: March Windows updates break Teams, OneDrive sign-ins<\/a><\/p>\n<p><a href=\"https:\/\/www.bleepingcomputer.com\/news\/microsoft\/new-windows-11-hotpatch-fixes-bluetooth-device-visibility-issue\/\">New Windows 11 hotpatch fixes Bluetooth device visibility issue<\/a><\/p>\n<\/p><\/div>\n","protected":false},"excerpt":{"rendered":"<p>Microsoft confirmed on Tuesday that some Windows Server [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"","ping_status":"","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[28],"tags":[],"class_list":["post-45422","post","type-post","status-publish","format-standard","hentry","category--bleepingcomputer"],"_links":{"self":[{"href":"https:\/\/nuoya.nuoyayasuo.top\/index.php\/wp-json\/wp\/v2\/posts\/45422","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/nuoya.nuoyayasuo.top\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/nuoya.nuoyayasuo.top\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/nuoya.nuoyayasuo.top\/index.php\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/nuoya.nuoyayasuo.top\/index.php\/wp-json\/wp\/v2\/comments?post=45422"}],"version-history":[{"count":0,"href":"https:\/\/nuoya.nuoyayasuo.top\/index.php\/wp-json\/wp\/v2\/posts\/45422\/revisions"}],"wp:attachment":[{"href":"https:\/\/nuoya.nuoyayasuo.top\/index.php\/wp-json\/wp\/v2\/media?parent=45422"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/nuoya.nuoyayasuo.top\/index.php\/wp-json\/wp\/v2\/categories?post=45422"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/nuoya.nuoyayasuo.top\/index.php\/wp-json\/wp\/v2\/tags?post=45422"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}