Back when I worked at MS, a PW was required on boot to deencrypt the drive.
I am honestly shocked that isn't the default for bitlocker. But then again it does require people to have a unique bitlocker PW, and if they ever forget it, everything on the machine is gone for good. (Which I've actually been bitten by, oops!)