Active Directory (on-premises): the key is stored against the computer object as the msFVE-RecoveryPassword attribute, inside an msFVE-RecoveryInformation child object. An administrator reads it with the BitLocker Recovery Password Viewer snap-in in Active Directory Users and Computers, by searching for the recovery password using the first part of the key ID, or with PowerShell. The key ID on the recovery screen matches the stored record.
Microsoft Entra ID (Azure AD): an administrator signs in to the portal, opens the device, and views the BitLocker keys stored against it, at aka.ms/aadrecoverykey for the device owner. This is the common case for modern cloud-joined laptops.
Intune: for Intune-managed devices, the recovery key is visible to administrators in the device's properties in the Intune admin centre. MBAM: older managed estates use Microsoft BitLocker Administration and Monitoring, which stores keys centrally and issues single-use recovery keys that expire once used.
Because the key is retrievable, most managed lockouts never need a recovery lab at all: the right administrator reads the key and the machine starts. We are for when that breaks down, a drive that has physically failed, a key record that is damaged or missing, or an organisation that finds its escrow was not capturing keys after all. In every case we work under documented authority from the organisation, with a clean chain of custody.