> I still don't follow. BitLocker explicitly includes a (optionally
> file-based) recovery password. If you want central management, why
> not centrally manage _that_?

On if MS provided some way to manage them centrally. Using a encrypted
DB to manually store the keys in it, is simply not feasible.

