BIOS and firmware updates are important because they can improve system security, compatibility, and hardware stability. However, firmware changes can also affect security technologies such as BitLocker and Secure Boot.
In 2026, HP documented an issue affecting some commercial notebooks, desktops, and workstations. After installing certain BIOS updates, users could successfully enter their BitLocker recovery key and start Windows, but the same recovery screen could appear again after the next restart. HP identified a failure involving the application of Microsoft’s 2023 Secure Boot certificates.
The good news is that this situation does not necessarily mean that your data or hard drive is damaged. In many cases, correcting the Secure Boot configuration allows Windows to complete the certificate update and stops the repeated BitLocker recovery prompts.
Why Does an HP BIOS Update Trigger a BitLocker Recovery Loop?
BitLocker uses hardware and boot-environment information to help determine whether a device is starting in a trusted state. Changes to firmware, TPM configuration, Secure Boot, or boot components can cause BitLocker to enter recovery mode.
Microsoft explains that firmware and certain UEFI changes can cause BitLocker to request the recovery key. Suspending BitLocker before planned firmware changes can prevent unnecessary recovery prompts.
In the HP-specific issue, the problem was related to the installation of Microsoft’s 2023 Secure Boot certificates. HP states that the certificates may fail to apply correctly, causing the computer to repeatedly enter BitLocker recovery after a BIOS update. The affected scope includes HP commercial notebooks, commercial desktops, and workstations running Windows 11 23H2, 24H2, or 25H2.
Symptoms of the HP BitLocker Recovery Loop
You may be experiencing this issue if:
- BitLocker asks for the recovery key after a BIOS update.
- The correct 48-digit recovery key successfully starts Windows.
- After restarting the computer, BitLocker asks for the recovery key again.
- The problem started immediately after an HP BIOS update.
- Windows appears to work normally after entering the recovery key, but the recovery screen returns on the next boot.
If these symptoms match your situation, avoid repeatedly reinstalling Windows or formatting the drive before trying the available recovery options.
How to Fix the BitLocker Recovery Loop After an HP BIOS Update
1. Locate Your BitLocker Recovery Key
Before changing BIOS or Secure Boot settings, make sure you have your BitLocker recovery key.
For a personal Microsoft account, the recovery key may be available through your Microsoft account. On an organization-managed computer, the key may be stored by the organization’s IT administrator through Microsoft Entra ID or Active Directory, depending on the environment. Microsoft recommends having the recovery information available when dealing with BitLocker recovery.
The recovery key contains 48 digits. Keep a copy in a secure location before continuing.
2. Open the HP BIOS Setup
Shut down the HP computer and turn it on again.
When the HP logo appears, repeatedly press F10 to enter the BIOS setup. HP’s documented procedure then directs users to the Security tab and the Secure Boot Configuration section.
The exact appearance of the BIOS menu can vary between HP models.
3. Check the Secure Boot Configuration
Inside Secure Boot Configuration, look for the certificate-related options provided by your HP system.
For affected systems, HP’s advisory instructs users to enable the required 2023 certificate settings. These include options associated with the Windows UEFI CA 2023, Microsoft UEFI CA 2023, Microsoft Option ROM UEFI CA 2023, and MS UEFI CA key.
Do not change unrelated BIOS settings. If you are unsure about a setting, check the documentation for your specific HP model or contact HP Support.
4. Save the BIOS Changes
After applying the recommended Secure Boot settings, return to the main BIOS menu and select Save Changes and Exit.
The computer should restart and attempt to boot into Windows.
HP notes that implementation of the new certificates can take some time because Windows may need to complete additional certificate and bootloader changes through Windows Update.
5. Check Whether the 2023 Secure Boot Certificates Were Applied
Once Windows starts successfully, you can check the certificate-update status.
Open PowerShell as Administrator and run:
Get-ItemProperty -Path "HKLM:\SYSTEM\CurrentControlSet\Control\SecureBoot\Servicing" -Name "UEFICA2023Status"
According to HP, the status should eventually show Updated after the certificate and bootloader changes have been successfully applied.
If the status remains In Progress for an extended period or an associated error value indicates a failure, further troubleshooting may be required.
6. Resume BitLocker Protection if It Was Suspended
If you suspended BitLocker before making firmware changes, remember to resume protection after the update has completed.
You can use PowerShell:
Resume-BitLocker -MountPoint "C:"
Microsoft explains that suspending BitLocker does not decrypt the drive. It temporarily changes how protection is applied so planned firmware or system changes can be completed without unnecessarily triggering recovery.
What If the BitLocker Recovery Screen Still Appears?
If the computer continues to request the recovery key after you have corrected the Secure Boot configuration, first verify that you are entering the correct recovery key.
If you can enter Windows, back up important files immediately. Do not assume that repeated BitLocker prompts mean the data has already been deleted.
For systems that cannot boot normally, Windows Recovery Environment and BitLocker management commands may provide additional recovery options. Microsoft documents methods for unlocking a BitLocker volume with its recovery password and temporarily disabling protection when required.
For example, an administrator can use:
manage-bde -status
to check the BitLocker status.
If the drive is accessible but important files appear to be missing or corrupted after the boot problem, avoid formatting or initializing the drive. A data recovery solution may be useful for attempting to recover inaccessible files.
Recover Data if Windows Becomes Inaccessible
In some cases, a BIOS or BitLocker-related boot problem may leave users unable to access important documents, photos, business files, or other data.
If the drive is physically healthy but Windows cannot start normally, BLR Data Recovery Toolkit can be considered for recovering files from an inaccessible Windows drive. The software is designed to scan storage media and recover deleted, lost, formatted, or inaccessible files.
Before attempting recovery, avoid unnecessary writes to the affected drive. If the data is particularly important, create a suitable backup or disk image where possible and perform recovery carefully.
How to Prevent Similar BitLocker Problems During Future BIOS Updates
The safest approach is to prepare BitLocker before planned firmware changes.
Microsoft recommends suspending BitLocker protection for certain firmware and UEFI updates because changes to the boot environment can otherwise cause the system to enter recovery mode.
Before installing a BIOS or firmware update:
- Make sure your BitLocker recovery key is backed up.
- Confirm that Windows is working normally.
- Check the BIOS update notes for your exact HP model.
- Suspend BitLocker when the update requires it.
- Install the BIOS update.
- Allow all required restarts to complete.
- Confirm that Windows starts normally.
- Resume BitLocker protection after the firmware update.
Microsoft provides the following PowerShell command for suspending BitLocker:
Suspend-BitLocker -MountPoint "C:" -RebootCount 0
After the firmware update has completed, protection can be restored with:
Resume-BitLocker -MountPoint "C:"
Microsoft notes that suspension keeps the data encrypted; it does not decrypt the entire volume.
Conclusion
An HP BIOS update that repeatedly triggers the BitLocker recovery screen can be frustrating, but it does not automatically mean that your files are lost. HP has documented a specific BitLocker recovery-loop issue affecting certain commercial systems after BIOS updates released in early April 2026. The problem is associated with the application of Microsoft’s 2023 Secure Boot certificates.
Start by securing your BitLocker recovery key, then check the Secure Boot configuration and allow Windows time to complete the required certificate updates. If the system remains inaccessible, use Windows recovery options and avoid formatting the drive until you have secured your important data.
For situations where files become inaccessible following the boot problem, BLR Data Recovery Toolkit can provide another option for scanning the affected storage device and attempting to recover important files.