The Issue 

When joining to the domain,  get this error, TPM malfunctioned.   When using a local account,  no issue.




The Solution




https://community.spiceworks.com/topic/2303931-trusted-platform-module-error-80090034


registry edit

To work around this problem, create a DWORD, set the value of the ProtectionPolicy registry entry to 1 to enable local backup of the MasterKey instead of requiring a RWDC in the following registry subkey:
HKEY_LOCAL_MACHINE\Software\Microsoft\Cryptography\Protect\Providers\df9d8cd0-1501-11d1-8c7a-00c04fc297eb 





Reference

https://learn.microsoft.com/en-us/troubleshoot/windows-server/identity/dpapi-masterkey-backup-failures