The images in this article were generated with artificial intelligence. How we publish
Microsoft has solved a problem that, following the security update of April 2026, caused some servers with Windows Server 2025 to boot on the BitLocker recovery screen and ask for the recovery key at first reboot. Although the phenomenon mainly affected corporate environments with poorly recommended BitLocker and TPM configurations, the episode once again put real operational risks on the table for critical infrastructure when updates interact with platform validations and boot signatures.
In technical terms, the failure occurred in teams that met a number of very specific conditions: BitLocker enabled in operating system drive, the group directive "Configure TPM platform validation profile for native UEFI firmware configurations" configured including the PCR7, the system information tool (msinfo32.exe) showing that the "Secure Boot State PCR7 Binding" was "Not Possible," the presence of the Windows UEFI CA 2023 certificate in the Secure Boot DB and that the team was no longer using the Windows Boot Manager signed with the 2023 chain. When all these circumstances were present, the automatic update of the boot manager could trigger the recovery of BitLocker by considering that the status of the platform had changed.

Microsoft distributed corrections in June 2025: the update for Windows Server 2025 is published under KB5094125 and the corresponding for Windows 11 23H2 low KB5093998. The official notes further explain that the hit devices will record the 1032 event in the system log during the installation of updates, a useful track to identify equipment that have tried to install the 2023-signed boot manager and had forced recovery.
For administrators who are not yet able to deploy these patches, Microsoft recommends two mitigation pathways: remove the configuration of the problem group directive before installing the updates or apply a Known Issue Rollback (KIR) that prevents automatic change to the Windows Boot Manager signed in 2023. KIRs instructions and description are available in Microsoft documentation on Known Issue Rollbacks and they should be planned in controlled maintenance windows to avoid surprises.
Beyond the immediate patch, there are several practical actions that turn this lesson into a sustainable improvement of the safety and operation posture: verify that BitLocker recovery keys are properly stored and accessible(e.g. in Active Directory or Azure AD), validate in laboratory any TPM / UEFI policy changes before rolling it in production and monitor relevant events such as the ID 1032 and BitLocker and Secure Boot related records during deployments.
For diagnostic problems, inspect msinfo32 to confirm the status of PCR7 and Secure Boot, review the Secure Boot DB to check the presence of the Windows UEFI CA 2023 certificate and use group directives to locate the configuration "Configure TPM platform validation profile for native UEFI firmware configurations." If a team enters the BitLocker recovery, the single key input usually restore the boot; however, on remote servers or private clouds this may involve significant downtime if there are no staff to physically enter the key.

It is important to stress that, according to Microsoft, the incidence is limited in scope and less likely in personal devices; however, business environments with advanced TPM policies and safe start-up are the most exposed. For operations and security equipment this means adjusting patch deployment procedures: prioritizing staging tests, preparing access to recovery keys and coordinating with maintenance window operations.
Finally, it is appropriate to adopt a preventive practice: document and automate the management and backup of BitLocker keys, audit changes in TPM and Secure Boot policies and maintain a catalogue of approved drivers and boot signatures. The interaction between patches, firmware and security policies is a recurring vector of operational risk; applying proven validation and recovery controls reduces the likelihood of unexpected interruptions after critical updates.
For more technical information and Microsoft guides on BitLocker and its administration, see official documentation at BitLocker overview in addition to the support pages of the indicated updates KB5094125 and KB5093998.
Related
More news on the same subject.

GitLab critical alert: emergency patch fixes CVE-2026-19478 allowing to modify or eliminate public projects without credentials
GitLab published an emergency patch on August 17, 2026 to correct critical vulnerability in its self-hosted software (Community and Enterprise Edition) which, under certain cond...

When the MCP server keeps your credentials: the silent attack vector of the IA in production
The incorporation of IA agents into business processes has opened a practical way for production systems and data to be accessible from models: it is called Model Context Protoc...

Critical alert: CVE-2026-58231 in SAP Commerce Cloud could allow remote code execution; patch and urgent mitigation
A critical vulnerability that affects SAP Commerce Cloud, registered as CVE-2026-58231 and with maximum score 10.0 on the CVSS scale, it is being exploited attempts shortly afte...

The massive purchase of expired domains drives fraud, malware and streaming pirate: the business behind the dropcatch
An intelligence report on DNS published by Infoblox and disseminated by specialized media confirms that criminals are buying large-scale expired domains - the so-called dropcatc...

HoneyMyte updates CoolClient with a signed kernel driver to hide processes and protect the C2 channel
Kaspersky has published an analysis that attributes to the actor known as HoneyMyte (also Mustang Panda) an updated version of the CoolClient backdoor that incorporates a signed...

GeoServer on zero-day vulnerability alert in jsonArrayContains with real risk of remote execution
The GeoServer open source project has a zero-day vulnerability that is being actively explored by attackers, according to researchers' public alerts and the watchTowr intelligen...

AmnesiaStealer MacOS malware that steals credentials and controls real-time browser sessions
Security researchers have documented a new malware family aimed at macOS - called AmnesiaStealer - that combines a dropper in shell, an infostealer written in Rust and a remote ...