Microsoft has fixed the BitLocker recovery Windows Server 2025 problem that forced some enterprise machines into recovery mode after installing the April 2026 security update, and it only took two months. The fix arrived during June’s Patch Tuesday via cumulative updates KB5094125 (Windows Server 2025) and KB5093998 (Windows 11 23H2).
BitLocker encrypts storage drives to prevent unauthorised access, and it typically demands a recovery key when it detects changes to a system’s boot environment, such as a TPM (Trusted Platform Module) update or a new boot manager. That behaviour is by design. What was not by design was the behaviour introduced by the April 2026 update, which sent a specific subset of enterprise devices into recovery on their first restart.
Who was actually affected by the BitLocker recovery Windows Server 2025 issue
Microsoft was fairly precise about the conditions required to trigger the problem. A device had to have BitLocker enabled on the OS drive, with the Group Policy setting ‘Configure TPM platform validation profile for native UEFI firmware configurations’ active and PCR7 (Platform Configuration Register 7) included in the validation profile. On top of that, System Information (msinfo32.exe) had to report Secure Boot State PCR7 Binding as ‘Not Possible’, and the Windows UEFI CA 2023 certificate had to be present in the Secure Boot Signature Database, making the device eligible for the 2023-signed Windows Boot Manager, which it was not yet running.
When all those conditions aligned, installing the April update caused Windows to switch to the 2023-signed Boot Manager automatically, which then invalidated the stored TPM measurements and triggered the recovery prompt. Microsoft acknowledged the situation after April’s Patch Tuesday, noting that ‘the BitLocker recovery key only needs to be entered once, subsequent restarts will not trigger a BitLocker recovery screen, as long as the group policy configuration remains unchanged.’
While Windows 11 could also be caught by this, Microsoft said it was unlikely to affect personal devices, since the relevant configurations are typically only found on enterprise systems managed by corporate IT teams.
What the June cumulative updates actually do
The fix prevents the automatic switch to the 2023-signed Boot Manager on devices with the incompatible Group Policy configuration, sidestepping the trigger entirely. As Microsoft explained in updated advisories: ‘To prevent the unexpected BitLocker recovery key prompt, devices with this incompatible group policy configuration are prevented from installing the 2023-signed Windows Boot Manager.’ Devices that were affected during the April window will see Event ID 1032 in the System event log when installing Windows updates, which serves as confirmation of the impact.
The June Server 2025 update, KB5094125, also brings a new Group Policy setting called LimitSecureBootRequiredServiceData, which gives administrators control over how much Secure Boot service data is sent back to Microsoft as telemetry, according to IT-Connect. It is a small but welcome addition for organisations that prefer tighter control over what leaves their environment.
The wider June Patch Tuesday was not a quiet one. TheNextWeb reports that KB5094126, released on 9 June, patched a record 208 security vulnerabilities but introduced its own set of bugs, ranging from cosmetic annoyances to machines locked out of their own drives. The BitLocker recovery fix sits within that broader, somewhat turbulent monthly update cycle.
For IT admins who cannot yet deploy the June updates, Microsoft’s guidance remains to remove the problematic Group Policy configuration before installing KB5082063 or any later update, and to ensure BitLocker bindings use the PCR7 profile. Those unable to strip out the policy first can apply a Known Issue Rollback (KIR) to block the automatic Boot Manager switch and avoid the recovery prompts until they can act properly.
This is not the first time a Patch Tuesday has sent Windows machines scrambling for recovery keys. Microsoft addressed a similar episode in August 2024, when the July 2024 security updates triggered BitLocker recovery across all supported Windows versions. Then in May 2025, emergency updates were needed to pull Windows 10 systems out of the same predicament following the May 2025 security updates. Event ID 1032 in the system log is now, apparently, a known acquaintance for enterprise admins managing this update generation.

