Aren’t bitlocker keys automatically saved in Active Directory when a domain joined device activates it

check that post, perhaps that’ll help you

3 Spice ups