On 16.2 I can add these lines to .vmx:
uefi.secureBoot.enabled = "TRUE"
uefi.allowAuthBypass = "TRUE"
managedvm.autoAddVTPM = "software"
and not have to encrypt disk for Windows 11.
Nice.
There is also the 'upgrade' option for a guest from 16.x to beta.
It appears I do not need to do this to get the 'new' VTPM. Is there
a description on what the 'beta' is and does?