The April 2026 update puts at risk the start of BitLocker on Windows Server 2025

Author: Published 4 min de lectura 287 reading

The images in this article were generated with artificial intelligence. How we publish

Microsoft has solved a problem that, following the security update of April 2026, caused some servers with Windows Server 2025 to boot on the BitLocker recovery screen and ask for the recovery key at first reboot. Although the phenomenon mainly affected corporate environments with poorly recommended BitLocker and TPM configurations, the episode once again put real operational risks on the table for critical infrastructure when updates interact with platform validations and boot signatures.

In technical terms, the failure occurred in teams that met a number of very specific conditions: BitLocker enabled in operating system drive, the group directive "Configure TPM platform validation profile for native UEFI firmware configurations" configured including the PCR7, the system information tool (msinfo32.exe) showing that the "Secure Boot State PCR7 Binding" was "Not Possible," the presence of the Windows UEFI CA 2023 certificate in the Secure Boot DB and that the team was no longer using the Windows Boot Manager signed with the 2023 chain. When all these circumstances were present, the automatic update of the boot manager could trigger the recovery of BitLocker by considering that the status of the platform had changed.

The April 2026 update puts at risk the start of BitLocker on Windows Server 2025
Image generated with IA.

Microsoft distributed corrections in June 2025: the update for Windows Server 2025 is published under KB5094125 and the corresponding for Windows 11 23H2 low KB5093998. The official notes further explain that the hit devices will record the 1032 event in the system log during the installation of updates, a useful track to identify equipment that have tried to install the 2023-signed boot manager and had forced recovery.

For administrators who are not yet able to deploy these patches, Microsoft recommends two mitigation pathways: remove the configuration of the problem group directive before installing the updates or apply a Known Issue Rollback (KIR) that prevents automatic change to the Windows Boot Manager signed in 2023. KIRs instructions and description are available in Microsoft documentation on Known Issue Rollbacks and they should be planned in controlled maintenance windows to avoid surprises.

Beyond the immediate patch, there are several practical actions that turn this lesson into a sustainable improvement of the safety and operation posture: verify that BitLocker recovery keys are properly stored and accessible(e.g. in Active Directory or Azure AD), validate in laboratory any TPM / UEFI policy changes before rolling it in production and monitor relevant events such as the ID 1032 and BitLocker and Secure Boot related records during deployments.

For diagnostic problems, inspect msinfo32 to confirm the status of PCR7 and Secure Boot, review the Secure Boot DB to check the presence of the Windows UEFI CA 2023 certificate and use group directives to locate the configuration "Configure TPM platform validation profile for native UEFI firmware configurations." If a team enters the BitLocker recovery, the single key input usually restore the boot; however, on remote servers or private clouds this may involve significant downtime if there are no staff to physically enter the key.

The April 2026 update puts at risk the start of BitLocker on Windows Server 2025
Image generated with IA.

It is important to stress that, according to Microsoft, the incidence is limited in scope and less likely in personal devices; however, business environments with advanced TPM policies and safe start-up are the most exposed. For operations and security equipment this means adjusting patch deployment procedures: prioritizing staging tests, preparing access to recovery keys and coordinating with maintenance window operations.

Finally, it is appropriate to adopt a preventive practice: document and automate the management and backup of BitLocker keys, audit changes in TPM and Secure Boot policies and maintain a catalogue of approved drivers and boot signatures. The interaction between patches, firmware and security policies is a recurring vector of operational risk; applying proven validation and recovery controls reduces the likelihood of unexpected interruptions after critical updates.

For more technical information and Microsoft guides on BitLocker and its administration, see official documentation at BitLocker overview in addition to the support pages of the indicated updates KB5094125 and KB5093998.

Coverage

Related

More news on the same subject.