News, Trends, and Insights for IT & Managed Services Providers
News, Trends, and Insights for IT & Managed Services Providers
diagram

Microsoft’s BitLocker encryption, designed to safeguard data on Windows PCs, may not be as secure as users believe. The company has confirmed that it can provide BitLocker recovery keys to law enforcement if requested through valid legal orders. According to a report by Forbes, this was demonstrated in a recent case involving the FBI, where the agency successfully obtained keys to access encrypted data related to an investigation. Users are encouraged to back up their BitLocker recovery keys locally rather than in the cloud, as storing them online can lead to potential unauthorized access. Microsoft acknowledges that while cloud storage facilitates key recovery, it also raises privacy concerns. Key custody remains a critical issue for users who want to ensure their personal data stays private while still benefiting from encryption technology.

Why do we care?

Encryption doesn’t matter if you don’t control the keys.

Too many MSPs check the “BitLocker enabled” box and move on, assuming they’ve delivered privacy. They haven’t. They’ve delivered recoverability — and handed authority to Microsoft by default.

That’s not inherently wrong. But it is absolutely a governance choice, and pretending otherwise is where harm starts.  Encryption is no longer a checkbox — it’s a documented decision about key custody, recovery authority, and disclosure. If those choices aren’t explicitly defined and agreed to, then security outcomes are being assumed, not delivered. 

Contrast this with Apple, which has intentionally designed systems where it cannot comply with certain data access requests even if it wants to. Microsoft has made the opposite tradeoff: supportability over exclusivity. Neither is accidental.

The danger is silence. Customers aren’t told. MSPs don’t document it. And then, under legal pressure, everyone acts surprised when access exists.

If you manage endpoints for executives, regulated industries, or anyone who actually cares about data sovereignty, this matters now — not later. Cloud convenience quietly collapses privacy guarantees unless you actively intervene.

The real risk isn’t law enforcement.

The real risk is assuming encryption equals control, and discovering — too late — that it never did.

Choose your upgrade:

Get the full benefits of Business of Tech Plus

Insider Access

$12/month

Perfect for MSPs and ITSPs that want full interviews, early access, and ad-free listening

  • Programmatic Ad-free private podcast feedSame show, little interruptions
  • Channel Chatter previews1–2 topics with light insights
  • Early access to interview episodesHear it days before public release
  • Monthly Insider BriefTighter analysis you can share internally
  • Extra audio segmentsCut interviews, behind-the-scenes commentary, quick competitive notes
  • Become an Insider for $12/month

    Leadership Access

    $149/month

    Perfect for MSPs and Vendors that run a team and need the extended tactics, executive summaries, and weekly alignment brief

  • All Insider Access benefits plus . . .
  • Invite your teamIncludes access for 5 team members with option to add more
  • Vendor Strategy BriefsThe entire library, plus new analysis every month
  • Channel ChatterAll topics, full insights, complete vendor discussion + sentiment list
  • Quarterly State of the Channel Briefing
  • Monthly AMA submission priorityAsk Dave direct questions, and skip the line
  • Get the Leadership Edge for $149/month

    Vendor Partner

    $500/month

    Perfect for channel companies or vendors looking to deepen their engagement with the show.

  • All Leadership Access benefits plus . . .
  • Get highlighted as a show sponsor You'll get placement in the show notes, throughout the website, and on our dedicated sponsors page.
  • Enjoy regular shout outs You'll be featured in a rotating format during the show
  • Become a show sponsor for $500/month

    Search all stories