Would be this something that can be avoided by setting up BitLocker with the encryption password to be provided at boot time by the user? Because that's the way I've always configured it when I've used Windows in the past, due to me being paranoid and suspicious about the default "key saved on TPM" approach.