The Issue 

When joining to the domain,  get this error, TPM malfunctioned.   When using a local account,  no issue.

The Solution

registry edit

To work around this problem, create a DWORD, set the value of the ProtectionPolicy registry entry to 1 to enable local backup of the MasterKey instead of requiring a RWDC in the following registry subkey: