If you have a datastore in a protection group then *all* VMs on that datastore must be configured for protection otherwise it will not succeed.
I.e. if it's not protected SRM isn't aware of it, can't shut it down, and thereby won't be able to unmount the datastore, etc.