Moving a vTPM enabled VM (e.g. Windows 11) to a host running 8.0 U3 may cause the following behavior:
PowerCLI command Get-TpmSupportedFeature, nothing is returned.On the Event view logs for the VM you can observe the following error:
AadTokenBrokerPlugin Operation
Error: 0xCAA5001C Token broker operation failed.
Operation name: GetTokenSilently, Error: -2144862075 (0x80280085), Description: TPM 2.0: Hierarchy is not enabled or is not correct for the use.
VMware vSphere ESXi 8.0.3
This is due to a new backend feature enablement for vTPM. Due to this new feature, additional flags were added for vTPM in 8.0 U3 that were not present in previous versions. When the VM migrates from an older version to 8.0 U3, these new values result in a null hierarchy disable, causing vTPM to have issues.
This issue is resolved in VMware ESXi 8.0 U3e or later release. Log in to the Broadcom Support Portal to download this patch.