Microsoft fixes BitLocker recovery bug on Windows Server 2025
Microsoft released updates (KB5094125 and KB5093998) to address a bug in Windows Server 2025 and Windows 11 that caused BitLocker recovery prompts after installing security updates. The issue stemmed from specific Group Policy configurations related to TPM validation and PCR7, leading to unexpected recovery key requests. Microsoft recommends specific remediation steps, including Group Policy adjustments or Known Issue Rollbacks, to prevent the problem.
This vulnerability centered around a misconfiguration within Windows Server 2025 and Windows 11’s BitLocker encryption feature. Specifically, certain Group Policy settings combined with TPM validation configurations resulted in the system attempting to trigger a BitLocker recovery key prompt upon restart after installing updates. The root cause involved an incompatibility between the 2023-signed Windows Boot Manager and the PCR7 configuration, leading to the system attempting to revert to recovery mode. Microsoft identified this issue following Patch Tuesday in April 2026 and subsequently released updates to resolve it.