I've got a VM with vTPM and BitLocker enabled using an untrusted guardian.
This VM now won't start, the event log is showing the event:
The computed authentication tag did not match the input authentication tag
I've checked that the VM has a key protector, and that the signed and encrypted certificates match the installed certificates for the untrusted guardian.
If I disable the vTPM I can start the VM and it boots after asking for the bitlocker recovery key.
There are no errors in the HGS Client event log, so I'm not sure what is wrong with this VM.
Any suggestions as to where to start looking?