When attempting to create a Windows 11 VM on the second vCenter, an error is encountered stating:
"Microsoft Windows 11 (64-bit) requires a Virtual TPM device, which cannot be added to this virtual machine because the vSphere environment is not configured with a key provider."
When deploying Windows 11 virtual machines (VMs) in VMware vSphere, a Virtual Trusted Platform Module (vTPM) is a mandatory requirement. vTPM provides enhanced security by allowing guest operating systems to store sensitive cryptographic information, such as encryption keys.
VMware vCenter Server 8.0.3
VMware vSphere ESXi 8.0.3
When deploying Windows 11 virtual machines (VMs) in VMware vSphere, a Virtual Trusted Platform Module (vTPM) is a mandatory requirement. vTPM provides enhanced security by allowing guest operating systems to store sensitive cryptographic information, such as encryption keys.
To solve this issue:
1. create a native key provider (see https://techdocs.broadcom.com/
2. ensure that the native key provider is configured to apply to the hosts, disable the option "Use key provider only with TPM-protected ESXi hosts", if the hosts do not have a physical TPM 2.0 installed
3. backup the native key provider to activate it
4. ensure that the native key provider is marked as the default key provider