Sophos Device Encryption: Securely retrieve recovery keys
A Sophos Device Encryption recovery key is obtained either by the authorized user in the Self Service Portal or by an authorized administrator in Sophos Fusion. The secure process is always the same: match the person to the device, compare the displayed identifier, only disclose the key for the specific recovery case and document the successful recovery without a key value.
Quick path for the help desk: Open My Products > Encryption > Computers, select the computer and click Retrieve Recovery Key. If the computer cannot be clearly found, open Retrieve Recovery Key directly and enter at least five characters of the recovery key ID or, in Windows, the volume ID. Do not select Show Key until identity, permission, device, volume, identifier, current recovery screen, and approved delivery channel are verified.
Requirements before retrieval
For an administrative retrieval, the executing person needs the role Help Desk, Admin or Super Admin in Sophos Fusion. For a separate recovery task, Help Desk is the smallest default role specifically mentioned by Sophos. For a custom role, access is checked with a test account in your own tenant. The actual permission to retrieve the key cannot be reliably determined from the basic role, product selection and visible menu alone. How to set up and control such roles is described in Assigning Sophos Fusion administration roles correctly.
The following points must also be met:
- A valid Sophos Encryption license is active, and a recovery key is available in Sophos Fusion. After the license expires, the Device Encryption page disappears from the Self Service Portal. A BitLocker key that was changed during the unmanaged period may initially be out of date after relicensing in Fusion.
- There is a comprehensible business reason for the recovery case. Device loss, suspected unauthorized access, or an unexplained recovery request will be handled first according to the internal security incident procedure.
- The helpdesk has an approved second channel for identity verification and a secure channel for immediate issuance.
- User, device, platform and expected volume are known or can be uniquely assigned using the identifier on the recovery screen.
Simply knowing the device name, user name or recovery key ID is not proof of identity. An already established, reliable helpdesk procedure is suitable, for example a callback via a verified number or a confirmation from a responsible internal office. Security questions with publicly discoverable answers are not enough.
Prepare and use the Self Service Portal
Self Service is suitable for users who have already set up access before the emergency. General invitation, login and access management remains described in the article Setting up Sophos Fusion Self Service Portal access.
The prerequisite is that the user has already activated their portal access and successfully checked their registration before the emergency. Invitation, account setup and access management are not repeated here.
In the event of recovery, the user proceeds as follows on a second computer:
- Log in to the Sophos Fusion Self Service Portal.
- Open Device Encryption.
- Select the affected computer and click Retrieve in the RECOVERY KEY column.
- Use the displayed key directly on your own recovery screen. Follow the appropriate platform instructions for the remaining input and follow-up checks.
Only computers on which this person was last logged in appear in the portal. If someone else has logged in in the meantime, Self Service is not available for this device. In addition, the user can only restore the boot volume via Self Service. The helpdesk handles a different volume, a missing computer or a portal access that can no longer be used; the restriction is not bypassed by another user identity.
Find recovery key through helpdesk
Variant 1: Computer is clearly known
- In Sophos Fusion, open My Products > Encryption > Computers.
- Select the exact computer based on the approved device information. For similarly named devices, additionally compare user, platform and inventory data.
- Click Retrieve Recovery Key.
- Before Show Key, compare the entry with the ID on the recovery screen. For Windows, the affected volume must also be correct.
A user name is used for assignment, but is not a replacement for comparing device and identifier. If only the person is known, you first determine the affected device and then display the recovery key ID. If multiple devices are possible, no key is disclosed.
Variant 2: Computer is missing from the list
Open Retrieve Recovery Key directly under My Products > Encryption > Computers. The following applies for each platform:
- Windows: Enter at least five characters of the Recovery Key ID or Volume ID from the BitLocker recovery screen. The user receives the ID after a restart and switching to this screen with
Esc. For a volume ID, Fusion can display multiple keys; the most recent is at the top. Nevertheless, only the entry whose association with the current recovery screen is clear is used. - Mac: Enter at least five characters of the Recovery Key ID that is briefly displayed at startup. If it is no longer visible, the Mac must be restarted. A key must not be selected on a Mac based on a similarly named device or user.
If a partial search produces several plausible results, enter additional characters. If there is no clear match or the ID does not match the expected device, stop the retrieval. A key from a “probably correct” record is not a valid attempt.
Disclose keys in a controlled manner
Immediately before Show Key the helpdesk confirms:
- The requesting person was identified according to the approved procedure and is allowed to access exactly this device.
- Device name, platform and recovery key ID match; under Windows the affected volume is also clarified.
- There is no loss of device or other issue that requires device blocking or a security escalation.
- The recipient is at the current recovery screen and can enter the key immediately without saving it permanently.
- The ephemeral channel intended for immediate transmission is approved.
Until all of these checks are completed, no part of the key will be disclosed. Only then select Show Key and transmit the value via the approved ephemeral channel. Where the established procedure allows it, direct entry on the device accompanied by the helpdesk is better than a written message.
The process deliberately ends before the operating system is unlocked. For Windows, continue with Manage BitLocker with Sophos Fusion. For Mac password and keychain dialogs, and for a possible APFS emergency path, continue with Manage FileVault with Sophos Fusion. This guide does not contain commands to unlock the operating system or an APFS volume.
Check key change and completion
On Windows, just viewing it by an administrator affects the key’s lifecycle: Fusion marks the recovery key as used and replaces it at the next sync. After successful recovery, a new key is generated and saved in Fusion; the old one is deleted from the computer. Existing BitLocker recovery keys will also be replaced when Sophos Device Encryption is installed and will no longer work afterwards. These statements do not carry over to FileVault.
The case will only be closed once the person responsible for the respective platform has confirmed:
- The user has access to the correct device or volume again.
- The device has reached Fusion again and synced.
- For Windows, a new key belonging to the device is present in Fusion after recovery. Do not disclose the new production key again with Show Key.
- For Mac, local FileVault state and centrally available recovery information match according to Mac instructions.
- The trigger has been explained plausibly or passed on to information security or the responsible platform support team.
A readiness test uses a dedicated test device and a fully planned recovery run. On production devices, it is sufficient to document regular checks of the license, role, device status, and existence of central recovery information. Do not display a real key merely for visual inspection.
Record evidence and secure case documentation
Only non-secret evidence is recorded in the ticket or operational journal:
- Case number, time and person carrying out the work,
- verified identity and verification procedure used,
- Device name or internal inventory ID, platform and affected volume,
- only a short part of the recovery key ID necessary for assignment, if the internal policy allows this,
- Retrieval method: self service, computer selection or search using the identifier,
- reason for release and secure transmission channel used,
- Result of the platform-specific check, synchronization status and any escalation.
Do not document the recovery key itself, full screenshots of the recovery screen, or an export. BitLocker recovery keys cannot be exported from Sophos Device Encryption. This product limitation is not circumvented with manual copies.
Troubleshooting and escalation
Computer is missing in the Self Service Portal
Check whether the requesting person was last logged in on this computer and whether Device Encryption is visible in the portal. A different last user, portal access that has not been activated or an expired encryption license excludes this option. Then switch to the authorized helpdesk retrieval.
Computer is missing from Encryption > Computers
Don’t guess based on a similar name. Search using the recovery key ID or, under Windows, alternatively the volume ID. If this search does not return a clear hit either, check the device status and connection to Central in Systematically troubleshoot Sophos Device Encryption and contact Sophos support if necessary.
Show Key is missing or cannot be selected
Check license status, default role and, for custom roles, actual product access with a designated test account. Do not spontaneously expand the role to Super Admin. If the action is unavailable despite a valid license and a role supported by Sophos, the tenant, administrator, time and affected computer are recorded without key material for Sophos Support.
ID does not match or the search remains ambiguous
Do not try any other ID or reveal any key. Record the full device name, platform, visible recovery key ID and, for Windows, the volume again. An identifier that still cannot be assigned is a stop condition. Escalate the case to the person responsible for Device Encryption or to Sophos Support.
Windows still shows the old key after the restore
First, make sure the correct computer is back online and synced with Fusion. Do not “test” a new key by Show Key again. If a new centrally stored key is still missing after synchronization or the device is unmanaged after a license interruption, leave the case open and escalate according to the troubleshooting instructions.