Earlier quoted context omitted.
All "Global Reader" accounts have "microsoft.directory/bitlockerKeys/key/read" permission. Whether you opt in, or not, if you connect your account to Microsoft, then they do have the ability fetch the bitlocker key, if the account is not local only. [0] Global Reader is builtin to everything +365. [0] https://github.com/MicrosoftDocs/entra-docs/commit/2364d8da9...
This is for the _ActiveDirectory_. If your machine is joined into a domain, the keys will be stored in the AD. This does not apply to standalone devices. MS doesn't have a magic way to reach into your laptop and pluck the keys.
I'd be curious to see a conclusive piece of documentation about this, though