How-to guides · Device Encryption and BitLocker recovery key checks on Windows 11 / Windows 10 as described on Microsoft support pages, and the preconditions to settle before replacing a drive

Before you swap in a new SSD: check whether the drive is encrypted, and where the recovery key lives

Of everything that can go wrong after you buy a new SSD, the one that cannot be undone is discovering afterwards that the old drive was encrypted. Windows Device Encryption is switched on by how you first signed in, not by the edition you bought. Microsoft states that when you first sign in or set up a device with a Microsoft account or a work or school account, Device Encryption is turned on and a recovery key is attached to that account, and that with a local account it is not turned on automatically. So a drive can be encrypted even though you never chose to encrypt it. This guide was written on 2026-09-20 from Microsoft's support pages and covers only what to establish before you touch the drive. No timing or speed figure was measured.

Published · Updated · FaultNote editorial policy

Before you swap in a new SSD: check whether the drive is encrypted, and where the recovery key lives overview: 1. Encryption is decided by the sign-in method, not the edition, 2. A lost recovery key cannot be reissued by anyone, 3. What to check before the swap, 4. Moving files and moving a whole drive are different questions, 5. What to do next
An overview of this guide’s steps and checks, not a screenshot of the app.

Who this guide is for and what to prepare

  • Anyone who has bought a new SSD and is about to clone or replace the existing one
  • Anyone who does not know whether their PC is encrypted at all
  • Anyone who wants to know where to look before a recovery key is demanded

What you need

  • Open Settings > System > About and note the Windows edition (Home, Pro and so on)
  • Check whether you sign in with a Microsoft account or a local account (Settings > Accounts)
  • Have somewhere outside the PC to record the key: paper, another device, or a printout

1. Encryption is decided by the sign-in method, not the edition

The common assumption that BitLocker is irrelevant on a Home machine does not match what Microsoft writes. On Device Encryption the page states: "Device Encryption is a Windows feature that enables BitLocker encryption automatically for the Operating System drive and fixed drives." The operating system drive and fixed drives, automatically.

The condition the same page gives for it turning on is the sign-in method: "When you first sign in or set up a device with a Microsoft account, or work or school account, Device Encryption is turned on and a recovery key is attached to that account. If you're using a local account, Device Encryption isn't turned on automatically." First sign-in or setup with a Microsoft or work or school account switches it on and attaches the key to that account; a local account does not.

The relationship to editions is on the same page: "Unlike BitLocker Drive Encryption, which is available on Windows Pro, Enterprise, or Education editions, Device Encryption is available on a wider range of devices, including those running Windows Home." Device Encryption is the one that reaches Home, and it is counted separately from BitLocker Drive Encryption. Sorting this question by edition does not work.

2. A lost recovery key cannot be reissued by anyone

One sentence on Microsoft's recovery key page sets the order of everything else here: "Microsoft Support doesn't have the ability to retrieve, provide, or recreate a lost BitLocker recovery key." Not retrieve, not provide, not recreate. That is why this check comes before the drive work rather than after it.

On the key itself the page says: "A BitLocker recovery key is needed when BitLocker can’t automatically unlock an encrypted drive in Windows. This is a 48‑digit number that lets you regain access to your drive."

Among the circumstances the page lists for being prompted is a "hardware change" — Microsoft's own wording. The page does not say that replacing an SSD specifically triggers the prompt, and this guide does not say so either. What follows is only this: since a hardware change is listed as a reason you may be asked, confirming you have the key before the swap is the reasonable order.

Where the key lives follows the account. For a Microsoft account the page points to aka.ms/myrecoverykey. It also notes that if someone else set the device up or turned BitLocker on, the key may sit in that person's account. For a work or school account it may be held by the organisation.

There is something worth noting down before you start looking, and the same page says so. On the screen that asks for the recovery key, take the first eight digits of the recovery key ID: Take note of the first 8 digits of the recovery key ID . The recovery key ID helps identifying which recovery key to use, in case you have more than one. It is how you tell two keys apart.

3. What to check before the swap

Every check here is read-only. The table lists where to look, what to look at, and what the answer means. Anything not listed — turning encryption off, partition work, running a cloning tool — is outside this guide.

Scroll horizontally to see the full table →

3. What to check before the swap
Where to lookWhat to look atWhat it means
Settings > Privacy & security > Device encryptionWhether the item exists, and whether it is on or offSome machines do not have the item at all. If it exists and is on, the drive is encrypted
Settings > AccountsMicrosoft account or local accountThis is exactly the distinction Microsoft's page gives as the condition for automatic encryption
aka.ms/myrecoverykey (Microsoft account)Whether a key appears under your accountIf it does, you have confirmed where it is stored. If not, it may be attached to a different account
Work or school account (aka.ms/aadrecoverykey)Whether the organisation holds itYou have to ask the administrator. This one cannot be settled from your own machine
A printout you keptWhether you printed the key when BitLocker was turned onMicrosoft's page names this as one of the places to look. Check where you keep papers about the device
A USB flash driveWhether you saved the key to a USB stick when it was turned onThe same page names this too. If it was saved as a text file, read it on a different device
0

4. Moving files and moving a whole drive are different questions

Searching for how to move to a new SSD mixes Windows' own features with disk cloning. Keeping them apart is the safer reading.

On Windows Backup, Microsoft writes: "Your Windows PC comes with a one-stop backup solution, Windows Backup , that helps you back up many of the things that are most important to you. From your files, themes, and settings to many of your installed apps and Wi-Fi information, Windows Backup protects what matters and makes it easier than ever to move to a new PC." The phrases to notice are "many of the things" and "many of your installed apps". Microsoft wrote many, not all.

Microsoft's page on transferring to a new PC opens with a box reading: "This feature is no longer available. Use Windows Backup and Restore instead." The body below that box still describes the feature in the present tense, so reading the body alone makes it look current. Read the box. This guide does not offer that feature as an option.

The page is still worth reading for its list of what a file transfer does not carry, which is the most concrete statement available on the difference between moving files and moving a whole drive. It lists: "OneDrive files won't be transferred.", "Applications installed on your previous PC.", "Saved Passwords and sign-in credentials.", and "Drives encrypted with BitLocker. To include data from such drives, please decrypt them before starting the transfer." That last line is Microsoft stating the constraint around encrypted drives, not an inference made here.

Those four items describe a feature Microsoft says is no longer available. Read them not as current behaviour but as an indication of what file-level migration generally does not carry.

5. What to do next

Once the checks are done, the next step depends on the answer. If encryption is on and you have located the key, record it somewhere outside the PC and then proceed. If encryption is on and the key cannot be found, stopping there is the sound decision: touch the drive in that state and there is no route back if it locks.

If encryption is off, or the item does not exist on your machine, the concern in this guide does not apply to you. That is not the same as saying you do not need a backup.

Choosing and running a cloning tool is not covered here. None of the Microsoft pages read for this guide points to a disk-cloning tool, and the conditions attached to the tools drive makers distribute have to be checked on each maker's own pages. This guide does not fill in what the pages it read do not say.

0

Limitations and requirements

  • Everything here was read on Microsoft's support pages on 2026-09-20. Microsoft changes its pages.
  • Microsoft's pages do not say that replacing an SSD necessarily triggers a recovery key prompt. A hardware change is listed as one reason you may be asked, and this guide claims nothing beyond that.
  • Turning encryption off, partition work and the specific steps of cloning are not covered. Nothing here was reproduced on hardware, so no destructive procedure is printed.
  • There is no timing, transfer speed or duration figure anywhere in this guide. None was measured.
  • No drive maker's migration tool could be read here under conditions this site can verify, so no maker is named in a comparison.
  • Erasing data before selling or disposing of a machine is a separate guide. This one is about not losing access.

Frequently asked questions

I never encrypted anything. Can my drive still be encrypted?

Yes. Microsoft states that when you first sign in or set up a device with a Microsoft account, or a work or school account, Device Encryption is turned on and a recovery key is attached to that account. That describes it happening without the user doing anything explicit. With a local account, the same page says it is not turned on automatically.

Surely this does not apply to the Home edition?

It does. Microsoft states that, unlike BitLocker Drive Encryption on Pro, Enterprise or Education, Device Encryption is available on a wider range of devices including those running Windows Home. The question cannot be settled by edition.

If I lose the recovery key, can Microsoft reissue it?

Microsoft's page states that Microsoft Support cannot retrieve, provide or recreate a lost BitLocker recovery key. No plan should assume reissue is possible.

Where do I find the recovery key?

Microsoft's page names four places: your own Microsoft account (aka.ms/myrecoverykey), a work or school account (aka.ms/aadrecoverykey), a printout made when BitLocker was turned on, and a USB flash drive the key was saved to. It also notes that if someone else set the device up or turned BitLocker on, the key may be in that person's account. Do not conclude the key is lost without checking the printout and the USB stick.

Will Windows Backup move my whole environment onto the new SSD?

Nothing on the pages read here supports that. Microsoft's own wording is "many of the things" and "many of your installed apps", not all of them. Windows Backup is also described in terms of moving to a new PC, and is not presented as the procedure for swapping a drive inside the same machine.

Sources and verification date

Sources checked: . These sources support the specifications, procedures or prices discussed here. Check each source for applicable conditions and current information.

Related practical guides

Device Encryption and BitLocker recovery key checks on Windows 11 / Windows 10 as described on Microsoft support pages, and the preconditions to settle before replacing a drive troubleshooting

How-to guides: browse all guides →