Call us — 0141 404 0294
Mon–Fri · 9am–5:30pm · No fix, no fee
Start a free diagnostic →

Data Recovery Case File · Trust, Practice & Honest Limits · The Key Belongs to the Employer

Work Laptop Locked Out Remotely

His enquiry described a situation that is more common than it sounds and has a clear answer. "Is it possible to retrieve data from an old works laptop that has been locked out remotely? I have accessed the hard drive independently and it has asked for a 47-digit access number. Anything that can be done?" He has done the technically sensible thing — taking the drive out and connecting it separately — and discovered what that reveals: the drive is encrypted, and what it is asking for is a recovery key. The length he describes is characteristic of one. So the honest position has two parts, and the first is technical while the second is not. The key exists. Somebody holds it. That somebody is almost certainly the organisation that issued the laptop — and that makes this a question about authority rather than about equipment.

MediaHard drive from a laptop issued by a former employer — remotely locked; drive removed and connected independently; full-disk encryption prompting for a recovery key
Reported situationDevice locked remotely by the issuing organisation · drive extracted and connected separately by the enquirer · recovery key demanded · key not held by the enquirer
Fault classNo device fault — credentials and authority case; contents unreachable without a lawfully-held key, which rests with the issuing organisation
Equipment usedNo bypass attempted or offered · encryption state confirmed and the position explained · decryption available only against a lawfully-supplied key (Passware Kit Forensic) · limits issued in writing at no charge

The decode: what he has found, who holds the key, and why that settles it

What the prompt actually is: a long numeric access code requested when a drive is connected to another machine is a full-disk encryption recovery key. Organisations enable this as standard on issued equipment, so that a laptop lost on a train is an inconvenience rather than a data breach. The remote lock he describes is a separate management action, but the encryption is what makes the drive unreadable outside the machine — and it is why taking the drive out did not help.

Why the encryption cannot be worked around: the same wall this archive describes throughout. The volume is encrypted with a key that is itself protected, and the recovery key is the route to it. Without a legitimate key, the stored data is mathematically meaningless — not difficult, not expensive, but unreadable. Reading the drive perfectly returns ciphertext. No equipment changes that, and any firm suggesting otherwise is describing something that does not exist.

Who holds it, and why that is the whole answer: on a managed corporate device, recovery keys are escrowed — held centrally by the organisation's IT, precisely so that a device can be recovered when an employee leaves, forgets a password, or a machine misbehaves. So the key almost certainly exists in a system somebody administers. The route to the data therefore runs through a request to that organisation, not through a laboratory.

The question that comes before the technical one: and it has to be said plainly. A laptop issued by an employer is generally the employer's property, and so is the data on it — which frequently includes information belonging to their clients or staff. This bench turns lawfully-held keys only. If the organisation supplies the key, or authorises the work, everything that follows is ordinary. If it does not, the answer is no, and that is not a negotiating position. Where he believes personal material of his own is on the device, the appropriate route is to ask them for it — organisations deal with that request routinely, and it is a reasonable one to make.

What is worth checking meanwhile: whether the personal material exists elsewhere. Anything synced to his own account, emailed to himself, or copied to personal storage at the time is reachable without the laptop at all — and that is frequently where the answer actually lies.

On the bench

No bypass was attempted, offered or implied, and nothing was charged for establishing the position. The encryption state was confirmed so that he had a definite answer rather than an impression — that the prompt was a recovery key request and that the drive was genuinely encrypted rather than merely unformatted. The position was set out in writing: that the key is escrowed with the issuing organisation, that a request to them is the route, and that work could proceed immediately if they supplied the key or authorised it. Decryption, where a lawful key is provided, runs through Passware Kit Forensic against that key alone.

The outcome

The position established and explained at no cost, with the lawful route identified and nothing sold that could not be delivered. Free assessment and honest limits; where a lawful key is supplied, one fixed written figure including VAT before any work. The decode, for anyone holding a locked work device: a long numeric code demanded when the drive is connected elsewhere is a full-disk encryption recovery key, which is why removing the drive did not help — the contents are mathematically unreadable without it; that key is almost certainly escrowed with the organisation that issued the laptop, so the route to the data is a request to them rather than a laboratory; and a bench that offers to get past it is telling you something important about how it treats everybody else's data. Check what exists in your own accounts meanwhile, because personal material is often already there.

Locked device issued by an employer

Ask the organisation rather than a laboratory. A long numeric code demanded when you connect the drive to another machine is a full-disk encryption recovery key, which is why taking the drive out didn't help — the contents are unreadable without it, whoever reads the disk and however well. On managed corporate equipment those keys are held centrally by IT precisely so devices can be recovered when someone leaves or forgets a password, so the key almost certainly exists and somebody administers it. Make the request; if it's your personal material you're after, organisations handle that routinely. Be clear-eyed about ownership too: an issued laptop and the data on it are generally the employer's, and often include information about their clients or staff. And treat any service offering to get past the encryption as a warning — the same wall protects every device your own information sits on.

Work device locked and asking for a long code?
That key is escrowed with whoever issued it — call Glasgow Data Recovery on 0141 404 0294; encryption state confirmed free, lawfully-held keys only, and the position stated in writing.
Request a quote online →

Our case files are drawn from genuine enquiries received by our laboratory over the past ten years, anonymised to protect client confidentiality. Each one describes the diagnostic and recovery procedure our engineers apply to that fault, using the equipment listed.

0141 404 0294