this post was submitted on 29 Sep 2025
7 points (81.8% liked)
Windows 11
1104 readers
10 users here now
Welcome to the community for Windows 11, Microsoft's latest computer operating system.
Rules:
- Do not promote pirated content or grey market keys.
- Be civil. No rude, offensive, or hateful posts/comments.
founded 2 years ago
MODERATORS
you are viewing a single comment's thread
view the rest of the comments
view the rest of the comments
The whole point of the TPM is that the encryption keys are securely stored on the device. There's nowhere you can "get them," and keys are set automatically.
What it looks like it's saying is that if you decide to use the optional BitLocker, the encryption keys will be stored in the TPM. If you were to replace your motherboard (or the TPM board, if it's a separate hardware device), you would only be able to recover your Windows drive if you had "the recovery key."
I've never bothered with BitLocker, but I would suspect that they'll generate a recovery key for you in the event you need to decrypt your device manually later on.
Ok thanks, so nothing for me to securely store. I'll proceed with the activation then.
Can confirm, if you enable bit locker, it'll force you into saving the recovery key!