Technet Article dd875529
If I clear the TPM, the Surface will reboot and prompt me with an American Megatrends "TPM Page" BIOS/UEFI page.
Press F12 to enable, activate, clear, enable, and activate the TPM
Press Esc to reject this change request and continue
I can then clear the TPM, and it resets to a "The TPM is ready for use." state.
At this point when I go to enable Bitlocker I get the message "Group Policy settings require that a recovery password be specified before encrypting the drive". Surface Pro #1 was able to come out of Sysprep and backup it's keys correctly and required nothing further to enable Bitlocker. I was hoping that after clearing the TPM, Surface Pro #2 would be able to do the same, but it seems at some point, #2 is not backing up keys to AD.