# CapaBitLocker v4.0 - Release Notes

> What changed in CapaBitLocker v4.0, released 16 December 2022, including new features, improvements, and prerequisites.

Source: https://docs.capaone.com/capainstaller/capabitlocker/capabitlocker-release-notes/capabitlocker-v4-0-release-notes/  
Product: CapaInstaller — a separate CapaSystems product; do not apply this page to any other.

*CapaBitLocker v4.0 released on December 16, 2022*

---

### New Features

<details>
<summary>Windows 11 Support</summary>

Windows 11 is supported.

</details>

<details>
<summary>Multiple Drive Support</summary>

It's possible to encrypt only the operating system drive or all fixed drives.

</details>

<details>
<summary>Fast and Easy Integration</summary>

Integration with Active Directory doesn't require service accounts or group policies.

</details>

<details>
<summary>Recovery Password Backup</summary>

Multiple recovery passwords can be saved in Active Directory or CapaInstaller or both.

</details>

<details>
<summary>Encrypt without wait</summary>

Encryption can be started without waiting for it to finish, if you want to encrypt drives during your endpoint deployment process.

</details>

<details>
<summary>Multiple domains and standalone endpoints</summary>

Multiple domains and standalone endpoints are supported.

</details>

<details>
<summary>Status on dynamic install screen</summary>

Encryption and decryption status is presented on the dynamic install screen.

</details>

<details>
<summary>Suspend Drives</summary>

It's possible to suspend the operating system drive, if you need to perform an operation that requires BitLocker to be deactivated.

</details>

<details>
<summary>Activate Recovery Mode</summary>

It's possible to activate BitLocker Recovery Mode, in case an endpoint has been stolen or is otherwise lost.

</details>

---

### Improvements

<details>
<summary>Improved Logging</summary>

Logging has been improved with a simple and a standard log.

</details>

<details>
<summary>Check PreRequisites (optional)</summary>

The Check PreRequisites package is now optional.

</details>

<details>
<summary>ReInstall status shown in console</summary>

The endpoint **Details** tab shows *Reinstall failed* as the state when a reinstall is aborted.

![Endpoint Details tab in the CapaInstaller Console with State showing Reinstall failed](/attachments/capainstaller/capabitlocker-reinstall-status-console.png)

The reason is written to custom inventory under **Inventory → Custom**.

![Custom inventory entry showing CapaServices | CapaBitLocker, Reinstall aborted, All data drives must be decrypted before reinstall](/attachments/capainstaller/capabitlocker-reinstall-status-details.png)

</details>

---

### Prerequisites

<details>
<summary>TPM</summary>

TPM version 2.0 or later.

</details>

---

### Technical Stuff

<details>
<summary>Command Line Based</summary>

To make troubleshooting easier, all actions are command line based, using PowerShell or `manage-bde.exe`.

</details>

<details>
<summary>Mask Sensitive Data</summary>

Recovery key values can be masked to improve security.

</details>

<details>
<summary>Troubleshooting</summary>

Issues related to the TPM chip are presented at the top of the log file and in the CapaInstaller console.

![Log line reading JOBERROR: TPM chip is NOT ready for encryption because it's not activated, enabled, owned, version 2.0 or higher](/attachments/capainstaller/capabitlocker-tpm-issue-log.png)

![CapaInstaller Console job error description reading TPM chip is NOT ready for encryption](/attachments/capainstaller/capabitlocker-tpm-issue-console.png)

</details>

<details>
<summary>Cloud Updater</summary>

CapaBitLocker is fully supported by the CapaSystems Cloud Updater, and we can update the scripting library automatically.

</details>
