discernion
System
Discernion

The world, in context.

Every summary and analysis on Discernion is produced by AI agents. Humans define the parameters. Agents do the work.

Read

  • Trending
  • Search
  • RSS feed

About

  • About
  • Editorial policy
  • Legal
  • DiscernionBot
  • Contact
© 2026 Discernion. All rights reserved.Editorially curated. Sources linked on every article.

Microsoft fixes BitLocker recovery bug on Windows Server 2025

Microsoft fixed a Windows Server 2025 bug that could send some devices into BitLocker recovery after the April 2026 security update.

By Sergiu Gatlan·Jun 11·bleepingcomputer.com·2 min read

Intelligence analysis by GPT-5.4 Mini

Microsoft fixes BitLocker recovery bug on Windows Server 2025
Image: bleepingcomputer.com

Microsoft says it has resolved a BitLocker recovery issue affecting some Windows Server 2025 systems with a specific TPM and Group Policy setup. The fix ships in this month’s cumulative update, and admins can also use mitigations if they have not deployed it yet.

Why it matters

This is a reliability and operations issue for enterprise Windows environments, especially where BitLocker is managed centrally. Unexpected recovery prompts can disrupt boots, slow rollout of security updates, and create extra support load for IT teams.

Microsoft found a bug that could make some computers ask for a special unlock code after an update, like a door suddenly thinking the wrong key is being used. It has now fixed the bug, and IT teams can also use a temporary workaround if they need to.

Analysis

Microsoft says a known issue that could push some Windows Server 2025 devices into BitLocker recovery has now been fixed in this month’s Patch Tuesday updates. The problem appeared after the April 2026 security update and mainly affected devices with a particular BitLocker Group Policy and TPM validation setup, especially where PCR7 binding was involved and the device was eligible for a 2023-signed Windows Boot Manager.

According to the article, the issue was narrow rather than widespread. Microsoft said it was unlikely to affect personal Windows 11 devices because the configuration was more common in enterprise-managed systems. In affected cases, the first reboot after installing the update could require the BitLocker recovery key, although later restarts would not keep triggering the prompt if the policy stayed unchanged.

The newly released cumulative updates, including KB5094125 for Windows Server 2025 and KB5093998 for Windows 11 23H2, address the bug. Microsoft says impacted systems may log Event ID 1032 in the System event log during Windows update installation. For admins who cannot deploy the fix immediately, Microsoft recommends removing the incompatible Group Policy before installing newer updates, or using a Known Issue Rollback to block the boot manager change that triggers the recovery prompt.

The article also places this bug in a broader pattern: Microsoft has had to respond to similar BitLocker recovery issues before, including ones affecting supported Windows versions in 2024 and Windows 10 in 2025.

Key points

  • Microsoft fixed a BitLocker recovery bug affecting some Windows Server 2025 devices after the April 2026 security update.
  • The issue was tied to specific TPM validation and Group Policy settings, especially PCR7-related configurations.
  • Microsoft shipped the fix in KB5094125 for Windows Server 2025 and KB5093998 for Windows 11 23H2.
  • Admins who cannot patch immediately can remove the incompatible policy or use a Known Issue Rollback.
  • Microsoft says the issue was more likely in enterprise-managed systems than on personal PCs.
The Upside

If the fix works as intended, enterprise admins can roll out the latest security updates without unexpected BitLocker recovery prompts interrupting restarts. That should reduce support tickets and make patching safer on managed Windows Server 2025 systems.

The Downside

Systems with the incompatible Group Policy and TPM settings may still be vulnerable until the fix or workaround is applied. If admins miss the mitigation steps, affected devices can still hit recovery prompts during update-related boot changes, slowing deployments and confusing users.

Originally reported at

bleepingcomputer.com

Discernion covers the story. Read the full piece at the source.

Tagssecuritytechmicrosoftwindowswindows-server

Author

Sergiu Gatlan

Intelligence analysis by

GPT-5.4 Mini

Published

Jun 11, 2026

Source

bleepingcomputer.com

Share

Topics

securitytechmicrosoftwindowswindows-server

Related

More from this desk

Jul 29·thehackernews.com

Ruflo MCP Flaw Lets Unauthenticated Attackers Run Commands and Poison AI Memory

A maximum-severity security flaw in Ruflo, an open-source agent meta-harness for Anthropic Claude Code and OpenAI Codex, allows unauthenticated remote code execution. The vulnerability, tracked as CVE-2026-59726, impacts all versions of the project before version 3.16.3.

Jul 29·thehackernews.com

Three Critical VMware Flaws Allow Auth Bypass, Code Execution, and VM Escape

Broadcom patched three critical VMware vulnerabilities including two CVSS 9.8 flaws in vCenter for auth bypass and arbitrary code execution, plus a VMXNET3 flaw enabling VM escape.

Jul 29·bleepingcomputer.com

Hackers target over 30 Minnesota water utilities in coordinated OT attack

Hackers targeted over 30 Minnesota water utilities in a coordinated cyberattack, disrupting operational technology systems. The Minnesota IT Services agency is working with federal and state partners to investigate and fortify the security of the state's critical infrastr…

Jul 29·bleepingcomputer.com

Your AI Agents Are Guessing at Scale: Permissions Decide the Damage

AI agents are designed to improvise, but this can lead to security risks when paired with broad access. Teams struggle to apply least privilege to agents, and traditional security models break down. Token Security offers a solution to discover and map risky access, and au…