This device is disabled. Contact your IT helpdesk to enable it.

2026-09-11T07:51:13.9733333+00:00

Hello,

I have a question regarding a laptop whose mainboard has recently been replaced.

After the mainboard replacement, Windows was completely reinstalled, which resulted in the laptop receiving a new Hardware ID. The laptop name, however, remained the same.

In our system, the device with the old Hardware ID has been disabled, while the new device with the new Hardware ID has been enabled.

The D: drive was also encrypted with BitLocker. Since the original device with the old Hardware ID is now disabled, I no longer have access to the BitLocker recovery keys associated with that device.

My question is: Is it possible to re-enable or otherwise access the old device record in order to retrieve the BitLocker recovery keys associated with the previous Hardware ID?

Our IT department is currently unsure how this can be done.

Could you please advise whether the old device can be restored or accessed, and if there is another way to retrieve the BitLocker recovery keys?

Thank you in advance for your help.

Best regards, Dragoimage

Windows für Unternehmen | Windows 365 Business
0 Kommentare Keine Kommentare

Antwort, die vom Frageautor angenommen wurde
Harry Phan 33,400 Zuverlässigkeitspunkte Unabhängiger Berater
2026-09-11T10:03:30.49+00:00

Hello Drago,

The situation you’re describing is a common consequence of hardware replacement, particularly when the motherboard is swapped. BitLocker recovery keys are bound to the TPM and hardware ID of the original device. Once the mainboard is replaced, the system generates a new hardware ID, which means the recovery key stored in Azure AD or Active Directory is associated with the old device object. If that object has been disabled, the keys remain tied to it and are not automatically migrated to the new device record.

To answer your question directly: yes, the old device record can typically be re-enabled in Azure AD or Active Directory. Once re-enabled, you should be able to access the BitLocker recovery keys from the device’s properties in the portal. In Azure AD, navigate to Azure Active Directory > Devices > All devices, locate the disabled device, and re-enable it. After that, open the device details and check the BitLocker keys section. The recovery key should still be present there, as disabling a device does not delete its stored recovery information. If you are using on-premises Active Directory with MBAM or Group Policy escrow, the same principle applies: re-enable the computer object in AD Users and Computers, then check the BitLocker Recovery tab.

If re-enabling is not possible due to policy restrictions, the only other way to retrieve the recovery key is from the original escrow location where it was stored at encryption time. This could be Azure AD, AD DS, or the user’s Microsoft account if self-service was enabled. Without access to that escrowed key, there is no supported method to bypass BitLocker protection. Microsoft’s security model does not allow recovery keys to be regenerated or transferred between hardware IDs.

In short: request your IT team to re-enable the old device object in Azure AD or AD DS. Once that’s done, you should be able to retrieve the BitLocker recovery key from the device record. If the object was deleted rather than disabled, then unfortunately the recovery key is permanently lost unless it was backed up elsewhere.

I hope you've found something useful here. If it helps you get more insight into the issue, it's appreciated to accept the answer. Should you have more questions, feel free to leave a message. Have a nice day!HP.

War diese Antwort hilfreich?

Eine Person fand diese Antwort hilfreich.
0 Kommentare Keine Kommentare

1 zusätzliche Antwort

Sortieren nach: Neueste
  1. Boras, Drago (DI SW GS&CS EU DACH GCO TP LCS LCS5) 25 Zuverlässigkeitspunkte
    2026-09-11T10:48:49.2766667+00:00

    Hi Harry,

    thank you very much for the answer. I will get in contact with our IT Departement.

    Kind regars

    Drago

    War diese Antwort hilfreich?


Ihre Antwort

Antworten können von Fragestellenden als „Angenommen“ und von Moderierenden als „Empfohlen“ gekennzeichnet werden, wodurch Benutzende wissen, dass diese Antwort das Problem des Fragestellenden gelöst hat.