Bitlocker TPM and Active Directory Batch File Script for Windows 7

This DOS batch file script does everything for Bitlocker:

-Updates Group Policy and forces no logoff (we use a separate OU for computers staged to be encrypted)
-Enables the TPM
-Sets the TPM password
-Asks for USB drive letter
-Enables Bitlocker
-Backs up key to USB drive
-Backs up key to Active Directory, creates folder based on Hostname of PC
-Copies .BEK key file from USB drive to the network location of your choice (must edit)

@echo *** Did you Move the USAVxDxxx to Bitlocker Staging in AD?
@echo n | gpupdate /force

@echo *** Enable TPM
manage-bde -tpm -t
@echo *** Set TPM Password
manage-bde -tpm -o P@ssw0rd

@echo off
set usbletter=e:
Set /p usbletter= "Enter the letter of the USB drive ([e:]): "
If "%usbletter%"=="e:" goto :sub_gotlettere

echo * USB Drive is %usbletter%
echo *** Deleting existing .BEK files on USB...
attrib -h -s -r -a %usbletter%:\*.BEK
del %usbletter%:\*.bek
echo *** Enabling Bitlocker Encrytion on C: ...
Manage-BDE.exe -on c: -recoverypassword -recoverykey %usbletter%
goto sub_go

set usbletter=e:
echo * USB Drive is %usbletter%
echo *** Deleting existing .BEK files on USB...
attrib -h -s -r -a e:\*.BEK
del e:\*.BEK
echo *** Enabling Bitlocker Encrytion on C: ...
Manage-BDE.exe -on c: -recoverypassword -recoverykey e:
goto sub_go

Manage-BDE.exe -protectors -get c:|findstr ID >%Temp%\ID.txt
echo *** Saving Bitlocker Key to Active Directory...
for /f "tokens=1,2" %%a in (%temp%\ID.txt) do manage-bde -protectors -adbackup c: -id %%b
@Echo ****** VERIFY THE KEY WAS SAVED TO AD, ignore 1st/3rd ERROR ABOVE ^ *****
@Echo ****** LOOK FOR this V , up Above ^ *****
@Echo ****** "Recovery information was successfully backed up to Active Directory." *****
echo * This is %computername%
echo *** Creating folder at I:\BITLOCKER\Saved_Keys\Enterprise\%computername%
md \\data\it\BITLOCKER\Saved_Keys\Enterprise\%computername%
attrib -h -s -r -a %usbletter%\*.BEK
@echo *** Copying .BEK key file from USBdrive to
@echo *** I:\BITLOCKER\Saved_Keys\Enterprise\%computername%
copy %usbletter%\*.BEK \\data\it\BITLOCKER\Saved_Keys\Enterprise\%computername%
start \\data\it\BITLOCKER\Saved_Keys\Enterprise\%computername%\
@echo ****** NOW You Just Need to RENAME the .BEK file
@echo ****** adding the %computername%_xxxxxxxx_xxxx_xxxx_xxxx_xxxxxxx.bek ******
rem ren \\data\it\BITLOCKER\Saved_Keys\Enterprise\%computername%\*.bek rem \\data\it\BITLOCKER\Saved_Keys\Enterprise\%computername%\