For cloud-managed devices, you can use the Microsoft Graph PowerShell module to retrieve keys: powershell
Import-Module -Name BitLocker
Get-ADObject -Filter "Name -eq 'COMPUTERNAME'" -Properties msFVE-RecoveryPassword | ForEach-Object $_.'msFVE-RecoveryPassword'