JacobH wrote:
For Bitlocker - Storing Keys in AD is antiquated - it's moved to MDOP/MBAM SQL database to the best of my limited knowledge.
You can query the machines table, inner join the keys table, to get you computername and recovery key.
Where you go after that, is up to you. If you're MSSQL-minded, you know where I'm going with this...
Mainstream support for Microsoft BitLocker Administration and Monitoring (MBAM) is ending July 2019.
Supported method for storing keys is with Active Directory, either on premises or in Azure.