You're almost there! That error usually means the Native Key Provider (NKP) isn’t trusted yet — even if it shows as active.
Try this:
-
Go to vCenter > Key Providers.
-
Click your Native Key Provider.
-
If it says "Trusted: No", click "Make Trusted".
Once trusted, you should be able to add vTPM to your VM without that error.
Also make sure:
It's licensed for encryption.
Helpful guides: