Published by

Brink's Avatar

Join Date: Jul 2009
Posts: 21,863

How to Copy the BitLocker Startup Key for the OS Drive in Windows 8

information   Information
If you encrypt the drive that Windows 8 is installed on, other than using a password to unlock the OS drive, you can also make your PC more secure by setting BitLocker Drive Encryption to require a startup key or use TPM (if available) for a personal identification number (PIN) to unlock the OS drive whenever you start your PC. You can create either a startup key or a PIN—but not both—when you turn on BitLocker for the first time.

A startup key can be used to store the encryption keys for your operating system drive if your PC doesn't have the Trusted Platform Module (TPM) security hardware. You can only use a startup key instead of the TPM if your system administrator has set up your network to allow the use of startup keys.

You can't change a startup key after you've created it, but you can make additional copies of it in case you lose the original. If you create backup copies, make sure you store them on separate USB flash drives or other removable media.

This tutorial will show you how to make additional copies of the BitLocker startup key for the encrypted Windows 8 drive for safe keeping.

You must be signed in as an administrator to be able to do the steps in this tutorial.

Tip   Tip
If you were signed in to your Microsoft account when you encrypted a drive with BitLocker, then you can get your recovery key from your OneDrive at the link below.

Microsoft account: BitLocker recovery keys

EXAMPLE: BitLocker Startup Key
NOTE: The startup key is saved as a .BEK file on the USB flash drive. The .BEK file is a hidden protected OS file. Only when you have a USB flash drive with the startup key saved to it connected during boot will it automatically unlock the OS drive to allow Windows 8 to startup.

Click image for larger version

Here's How:

1. Do step 2, 3, or 4 below for how you would like to start.

2. Open the Control Panel (icons view), click/tap on BitLocker Drive Encryption icon, and go to step 5 below.

3. In File Explorer, open Computer, right click or press and hold on the encrypted Windows 8 drive, click/tap on Manage BitLocker, and go to step 5 below. (see screenshot below step 4)

4. In File Explorer, open Computer, select (highlight) the encrypted Windows 8 drive, click/tap on Manage (Drive Tools) tab, click/tap on BitLocker icon in the ribbon, click/tap Manage BitLocker, and go to step 5 below. (see screenshot below)

Click image for larger version

5. Under Operating system drive, click/tap on the arrow to expand the Windows 8 OS drive, and click/tap on the Copy startup key link. (see screenshot below)

Click image for larger version

If prompted by UAC, click/tap on Yes.

7. Connect the USB flash drive, select it, and click/tap on Save. (see screenshot below)

Name:  BitLocker_Startup_Key-3.jpg
Views: 16568
Size:  33.5 KB

8. If you like, you can now close the BitLocker Drive Encryption (Manage BitLocker) window. (see screenshot below step 5)

That's it,