Emergency Updates for Windows 10 Address BitLocker Recovery Challenges
Microsoft has issued emergency out-of-band updates to address a critical issue that causes Windows 10 systems to enter BitLocker recovery mode following the installation of the May 2025 security updates.
To resolve this issue, users should download and install the KB5061768 emergency update, which is exclusively available through the Microsoft Update Catalog. This update is cumulative, meaning users can deploy it without the need to install any previous updates.
The affected systems include Windows 10 22H2, Windows 10 Enterprise LTSC 2021, and Windows 10 IoT Enterprise LTSC 2021 that are equipped with Intel vPro processors (10th generation or newer) and have Intel Trusted Execution Technology (TXT) enabled. Devices running Windows 10 Home and Pro editions are generally not impacted, as these typically do not utilize Intel vPro processors.
Microsoft reports that the issue arises when the May 13, 2025, security update (KB5058379) leads to an unexpected termination of the Local Security Authority Subsystem Service (LSASS), which in turn prompts users for the BitLocker recovery key to proceed with Automatic Repair.
In cases where immediate installation of KB5061768 is not feasible, it may be possible to disable Intel Trusted Execution Technology (TXT) from the BIOS settings as a temporary workaround.
The company recognized this issue following numerous reports from users and administrators encountering BitLocker recovery screens after accessing the Windows Recovery Environment (WinRE) post-installation of the KB5058379 cumulative update, part of the May 2025 Patch Tuesday.
Affected users can verify their system logs through the Windows Event Viewer, where they may find LSASS errors and installation failures accompanied by 0x800F0845 error codes.
When installing the update on affected devices, Windows may fail to boot sufficiently to trigger an Automatic Repair process, requiring BitLocker key input for restoration.
This situation echoes a similar issue that occurred in August 2022, which forced devices into BitLocker recovery mode after the installation of the KB5012170 security update. Moreover, Microsoft had previously resolved another BitLocker recovery prompting issue that surfaced following the July 2024 Windows security updates.
BitLocker recovery screen (Microsoft)