Once the GPO is active and machines are encrypted, retrieving a key is straightforward: Open . Locate the Computer Object for the machine in question. Right-click the computer and select Properties .

GPOs typically only apply to new encryption events. If a machine was encrypted before the policy was active, the key will not be in AD.