gamma7 Can uploading be disabled or avoided?
According to the information I have, which is from Microsoft, it is only on Home licensed versions of Windows 10/11 the automatic uploading of the disk encryption key happens, and only if you login to your Microsoft Account during first setup of a freshly installed version of Windows.
Logging in to a Microsoft Account is mandatory on at least all Home/Pro versions, I don't know about others. It cannot be skipped in the UI. You need to connect to internet and then either create an account or login to an existing one. However, this is possible to bypass by unplugging the network cable, refusing to connect to a Wifi, and instead at the internet setup screen press Ctrl+F10 to open a terminal, and then type "oobe\bypassnro" and press Enter. The first time setup wizard will restart, and this time around there will be a tiny button at the bottom of the internet setup screen that says "I don't have access to internet" which you can click to instead setup a local account. This will however disable disk encryption completely, with no possibility to enable again, leaving all your data unencrypted, so you will have to use a third-party disk encryption software instead if you need disk encryption, such as VeraCrypt.
On Pro licenses it is possible to setup disk encryption using the built-in BitLocker functionality, without any key being uploaded to any Microsoft Account, allegedly. I would not trust this.
On Enterprise licenses it is possible to enable actually secure disk encryption modes in BitLocker that cannot be broken by skilled attackers. This should give comparable security to using third-party disk encryption tools such as VeraCrypt. In theory. But given that they think uploading the encryption key is okay at all, I would be hesitant to trust this.
Really, just use VeraCrypt instead, and pray they won't start detecting and uploading VeraCrypt keys too.
Or better, switch away from Windows if Microsoft or law enforcement is in your threat model.
gamma7 Does this mean that LTSC versions of Windows allow users to turn off file scanning?
In theory it should be possible to disable the scanning on Enterprise licensed versions of Windows, including the LTSC edition. You will need to edit Group Policies using the administrative tools. Look up guides for how to do it, if you really need to use Windows despite such scanning being in your threat model.