BitLocker policy stuck pending and recovery key not showing in Device Summary on WindowsSolved

Participant
Discussion
3 days ago Jun 25, 2026

I’m testing BitLocker settings on a Windows laptop using a cloned policy. The goal is to make sure devices without BitLocker get encrypted and that the BitLocker recovery key is visible later in the device summary, so it can be retrieved if a user gets the BitLocker recovery screen.

The policy initially stayed in Pending for a long time. After checking, I realized I had assigned it to the wrong Windows device record. Once I moved the policy to the correct device, the policy applied, but I still don’t see the BitLocker key in the Device Summary.

Is there another step needed before the recovery key appears?

Replies (1)

Marked SolutionPending Review
Hexnode Expert
3 days ago Jun 25, 2026
Marked SolutionPending Review

Hi @ren_ben,

For a BitLocker recovery key to appear in the Device Summary, the policy must be applied to the correct device and the device must complete BitLocker encryption.

If a Windows policy remains in Pending, first confirm that the policy is assigned to the active device record. A stale or incorrect device entry can keep the policy status pending because the device is not checking in.

Recommended checks:

  • Confirm the target Windows device has checked in recently.
  • If the device is online but the policy is still pending, run a Scan Device action.
  • If the scan does not complete, restart the Windows device and try again.
  • Open the Hexnode agent on the device and use Sync, then run Scan Device again from the portal.
  • Make sure the BitLocker policy is assigned to the correct device, not an older or duplicate device record.

After the policy is successfully deployed, the device still needs to be encrypted. Once the BitLocker policy has been applied, restart the Windows device. The device should then prompt for BitLocker encryption based on the configured policy.

If the encryption prompt does not appear after restart, you can initiate it from Hexnode:

  1. Go to the Windows device in Hexnode.
  2. Select Actions > Security.
  3. Choose Force BitLocker Encryption.
  4. Follow the on-screen instructions.
  5. Set the required password or PIN according to the policy requirements. In this case, use a minimum length of 8 characters.

After encryption is triggered and the recovery key is generated, the BitLocker recovery key should become available in the Device Summary.

Best Regards,
Isabel Lora
Hexnode UEM

Save