Allowing end users to use BitLocker encryption at will is a risky proposition. I strongly recommend storing BitLocker recovery passwords in Active Directory to avoid data loss as a result of lost ...