After moving vSAN to a new KMS provider or a Native Key Provider (NKP) there are alarms in vSAN health for keys not available. This can also be seen after an upgrade to the key provider.
vSAN with Data at Rest Encryption (All versions)
During the key provider change a shallow rekey was not performed on the vSAN cluster. This is causing the new key provider to not have the expected keys.
Do not reboot or make any changes to the disk groups in this condition. Follow the below steps: