If you are familiar with Group Policies in an on-premises Active Directory, you can use those to manage BitLocker on your domain. Make sure you install these RSAT tools on your workstation:
- Active Directory Domain Services (AD DS) Tools and Active Directory Lightwight Directory Services (AD LDS) Tools
- BitLocker Drive Encryption Administration Utilities
- Group Policy Management Tools
You can set a Group Policy that all computers in certain Organizational Units must be encrypted with BitLocker and have their recovery keys backed up to your Domain Controller. This will allow you to pull the recovery key from a new "BitLocker Recovery" tab in a computer's Properties page within the AD Users and Computers MMC snap-in.