6
submitted 3 weeks ago* (last edited 3 weeks ago) by dhkuq3645@lemmy.dbzer0.com to c/windows11@lemmy.world

It's password only, non tpm and it still creates a recovery key. Why tho?

linux doesn't do that when using LUKS encryption. trust me I'd love to switch, but can't.

top 2 comments
sorted by: hot top new old
[-] Object@sh.itjust.works 4 points 3 weeks ago* (last edited 3 weeks ago)

So that you can decrypt in case you forget the password, of course. You can also do that in LUKS it seems. IIRC, hash of your password encrypts Volume Master Key, and another copy of VMK is encrypted with your recovery key. If you use a TPM, VMK is stored inside it instead of storing an VMK encrypted with your password.

[-] LifeInMultipleChoice@lemmy.world 3 points 3 weeks ago

Not 100% sure but in my previous use cases in work atmospheres bitlocker recovery keys we would auto collect/store in Active Roles/active directory. So if windows did an update and messed up something or a user forgot their password to get passed it we could search ARS/AD and get the machine back up and running.

this post was submitted on 11 Sep 2026
6 points (87.5% liked)

Windows 11

1247 readers
25 users here now

Welcome to the community for Windows 11, Microsoft's latest computer operating system.

Rules:

founded 3 years ago
MODERATORS