Introduction
Update: March 2022. This is now resolved natively in ConfigMgr 2203 or later, please review this post for more info.
NOTE: If you are using ConfigMgr 2103 or later do NOT use the Invoke-MbamClientDeployment.ps1 Powershell script as it will cause serious problems with your site. Read the following and scroll down for more info.
see https://docs.microsoft.com/en-us/microsoft-desktop-optimization-pack/mbam-v25/how-to-enable-bitlocker-by-using-mbam-as-part-of-a-windows-d