Microsoft has issued an urgent out-of-band patch (KB5061768) to resolve a critical problem that causes Windows 10 devices to enter BitLocker recovery mode after installing the May 2025 security updates.
This fix, released on May 19, comes in response to numerous reports from businesses facing system lockouts and boot loops, where users were required to input their BitLocker recovery keys to regain access.
BitLocker Recovery Problem on Windows 10
The issue surfaced following the installation of the Windows 10 KB5058379 update, which was released on May 13, 2025. This update led to the unexpected termination of the Local Security Authority Subsystem Service (LSASS) on impacted systems, triggering the Automatic Repair feature. In some cases, this repair process kept prompting for BitLocker recovery keys, and affected systems even encountered persistent boot loops after the key was entered.
“After the update is applied, some systems might fail to start enough times to activate Automatic Repair,” Microsoft explained in their release health update.
“For devices with BitLocker enabled, a BitLocker recovery key is required to initiate Automatic Repair,” the company added.
The issue mainly affects systems running Windows 10 version 22H2, Windows 10 Enterprise LTSC 2021, and Windows 10 IoT Enterprise LTSC 2021 with Intel vPro processors (10th generation or later) and Intel Trusted Execution Technology (TXT) enabled. Consumer devices, particularly those with Windows 10 Home and Pro editions, are generally unaffected as they do not utilize Intel vPro processors.
Devices experiencing this issue show Event ID 20 in the Event Viewer with error code 0x800F0845, accompanied by Event ID 1074, indicating an unexpected termination of lsass.exe with status code -1073740791.
The emergency update, KB5061768, is available exclusively through the Microsoft Update Catalog and comes as a cumulative update. This means users can apply the patch without needing to install earlier updates.
Microsoft advises affected organizations to download and deploy this update immediately to address the issue.
Steps for Systems Unable to Boot
If systems are stuck on the BitLocker recovery prompt, Microsoft recommends temporarily disabling Intel VT for Direct I/O (VTD/VTX) and Intel Trusted Execution Technology (TXT) in the BIOS/UEFI settings. Once disabled, systems should be able to boot successfully, enabling administrators to install the KB5061768 update. After the update and a restart, Intel’s security features can be re-enabled, although users will be prompted to enter the BitLocker recovery key again.
“Please note that Microsoft Support cannot retrieve, provide, or regenerate a lost BitLocker recovery key,” the company emphasized, stressing the importance of securely storing recovery keys.
This emergency update also includes the latest servicing stack update (SSU KB5058526) for Windows 10 builds 19044.5853 and 19045.5853, ensuring smoother future updates.
End of Windows 10 Support Looms
This patch comes at a time when Microsoft is preparing for the end of support for Windows 10 on October 14, 2025. After this date, no more free updates, technical assistance, or security patches will be available for Windows 10 systems.
For enterprises unsure whether they are impacted by this issue, Microsoft clarified that this problem primarily affects environments using specific Intel security features. Organizations not encountering BitLocker recovery prompts are not required to install this emergency update.




