Personally, I'd be relying on RMM or Intune for keys, as one of the fixes for constant requests for the key is to decrypt and re-encrypt the drive, then you'd need to make sure you're getting those keys. Alternatively, you've extended AD (if you have it) and it's in there, or Intune, or most RMMs can retrieve keys automatically… just my 2c.