Yeah, You could also check if Secure Boot is enabled in the BIOS, as that's another common requirement that gets overlooked. Let me know if that works.
Agreed. Also, double-check that TPM 2.0 is enabled in the BIOS, not just present. That one trips up a lot of Optiplex models. Let me know if that works.