ESXi Host Error: "Failed to power on the virtual machine <VM-Name>. The virtual machine must be encrypted."
vCenter Server Error: "The virtual machine must be encrypted. Failed to start the virtual machine. Module DevicePower On power on failed. Virtual TPM initialization failed."
"Virtual TPM initialization failed" error.Before performing any changes to a virtual machine that is failing to power on, ensure these requirements:
Note: Bypassing vTPM requirements is unsupported by Broadcom and is done at your own risk.
(If using HCX migration for encrypted VMs, following are the additional steps to be performed)
Network Configuration
Ensure Port 32032 (Secure Listener Port) is open on the firewall between the source network and the target vSphere Replication network (the HCX IX appliance).
Configure HCX Bulk Migration
Open the HCX Dashboard, click Migration, and select Migrate Virtual Machines.
Select the target Windows 11 virtual machines and choose Bulk Migration as the migration method.
In the Storage configuration settings, select the target Datastore and the VM Encryption Storage Policy. This forces HCX to land the virtual machine in an encrypted state.
Run the validation check under Ready for Validation and execute the migration upon success. Note: ESXi hosts running version 9.1.x or higher do not require a manual VIB installation as the replication mechanics are included in the default vmware-hbsrv. If ESXi version is <9.1 the these are the steps for manual vib installation KB: Manual-install-of-hbr-agent-vib
Broadcom requires all Microsoft prerequisites, including TPM 2.0, to be met to support Windows 11 virtual machines.
Reference Document: Find Windows 11 specs, features and computer requirements
For comprehensive instructions on configuring a vSphere Native Key Provider.
Reference Document: Configure vSphere Native Key Provider