Microsoft fixes BitLocker recovery bug on Windows Server 2025
Microsoft fixed a Windows Server 2025 bug that could send some devices into BitLocker recovery after the April 2026 security update.
Intelligence analysis by GPT-5.4 Mini

Microsoft says it has resolved a BitLocker recovery issue affecting some Windows Server 2025 systems with a specific TPM and Group Policy setup. The fix ships in this month’s cumulative update, and admins can also use mitigations if they have not deployed it yet.
Microsoft found a bug that could make some computers ask for a special unlock code after an update, like a door suddenly thinking the wrong key is being used. It has now fixed the bug, and IT teams can also use a temporary workaround if they need to.
Analysis
Microsoft says a known issue that could push some Windows Server 2025 devices into BitLocker recovery has now been fixed in this month’s Patch Tuesday updates. The problem appeared after the April 2026 security update and mainly affected devices with a particular BitLocker Group Policy and TPM validation setup, especially where PCR7 binding was involved and the device was eligible for a 2023-signed Windows Boot Manager.
According to the article, the issue was narrow rather than widespread. Microsoft said it was unlikely to affect personal Windows 11 devices because the configuration was more common in enterprise-managed systems. In affected cases, the first reboot after installing the update could require the BitLocker recovery key, although later restarts would not keep triggering the prompt if the policy stayed unchanged.
The newly released cumulative updates, including KB5094125 for Windows Server 2025 and KB5093998 for Windows 11 23H2, address the bug. Microsoft says impacted systems may log Event ID 1032 in the System event log during Windows update installation. For admins who cannot deploy the fix immediately, Microsoft recommends removing the incompatible Group Policy before installing newer updates, or using a Known Issue Rollback to block the boot manager change that triggers the recovery prompt.
The article also places this bug in a broader pattern: Microsoft has had to respond to similar BitLocker recovery issues before, including ones affecting supported Windows versions in 2024 and Windows 10 in 2025.
Key points
- Microsoft fixed a BitLocker recovery bug affecting some Windows Server 2025 devices after the April 2026 security update.
- The issue was tied to specific TPM validation and Group Policy settings, especially PCR7-related configurations.
- Microsoft shipped the fix in KB5094125 for Windows Server 2025 and KB5093998 for Windows 11 23H2.
- Admins who cannot patch immediately can remove the incompatible policy or use a Known Issue Rollback.
- Microsoft says the issue was more likely in enterprise-managed systems than on personal PCs.
If the fix works as intended, enterprise admins can roll out the latest security updates without unexpected BitLocker recovery prompts interrupting restarts. That should reduce support tickets and make patching safer on managed Windows Server 2025 systems.
Systems with the incompatible Group Policy and TPM settings may still be vulnerable until the fix or workaround is applied. If admins miss the mitigation steps, affected devices can still hit recovery prompts during update-related boot changes, slowing deployments and confusing users.



