Using the same CLI, which shows all the alternative "protectors".
You need some implicit trust in a system to use it. And at worst, you can probably reverse engineer the (unencrypted) BitLocker metadata that preboot authentication reads.
Key ring contents (and what is done with them) are typically much harder to verify as they’re encrypted.