Option to add "Trusted Platform Module" to a Virtual Machine is not available.
search cancel

Option to add "Trusted Platform Module" to a Virtual Machine is not available.

book

Article ID: 414469

calendar_today

Updated On:

Products

VMware vSphere ESXi VMware vCenter Server

Issue/Introduction

The option to add a virtual Trusted Platform Module (vTPM) is missing from the "Add New Device" menu in vCenter Server, preventing the deployment of security features like Windows 11 requirements or VM encryption.

Environment

  • VMware vCenter Server 9.x
  • VMware vSphere ESXi 9.x
  • VMware vCenter Server 8.x
  • VMware vSphere ESXi 8.x
  • VMware vCenter Server 7.x
  • VMware vSphere ESXi 7.x
  • VMware vCenter Server 6.7.x
  • VMware vSphere ESXi 6.7.x

Cause

This issue occurs if the virtual machine firmware is set to legacy BIOS or if a vSphere Native Key Provider (NKP) is configured but not designated as the "Default" provider.

Resolution

Step 1: Designate a Default Key Provider

  1. Navigate to vCenter Server > Configure > Security > Key Providers.
  2. Select the intended Native Key Provider.
  3. Click Set as Default.
    • Note: If multiple providers exist, only the one set as Default will surface vTPM options for the environment.
  4. Ensure the Key Provider is backed up. Download the .p12 file and record the password. Loss of this key prevents decryption of any VMs using this provider.

Step 2: Configure VM Firmware to UEFI

  1. Power off the virtual machine.
  2. Right-click the VM and select Edit Settings.
  3. Navigate to VM Options > Boot Options.
  4. Change Firmware from BIOS to EFI.
  5. Click OK.
    • Warning: Guest OS partitions must be GPT-compatible. Converting from BIOS to UEFI on an existing OS may prevent booting and require OS-level reconfiguration or reinstallation.

Step 3: Add the vTPM Device

  1. Navigate to Edit Settings > Add New Device.
  2. Select Trusted Platform Module.
  3. Click OK and power on the VM.

Additional Information

Note: Hardware version 14 (ESXi 6.7) or later is required - What Is a Virtual Trusted Platform Module