Check if the devices have an enabled TPM device and also I would check the eventlog to see if there are events which maybe clear the TPM this would trigger the recovery screen to pop up. If you are using Intune make sure that you disable the option to clear the TPM from your Defender policies.