In theory, they've always banned JIT in UWP apps, at least by default. UWP apps can't use VirtualProtect; they have to use VirtualProtectFromApp, which only allows JIT if you have the "codeGeneration" capability (and always enforces W^X). I don't use Windows so I don't know how it interacts with this new thing. Maybe the protection wasn't enforced at the kernel level?
On any platform, it makes sense to enforce code signing by default as a hardening measure, but some apps like browsers cannot operate without a JIT. So there needs to be some exception process - possibly requiring the use of a separate process for JIT compilation, as Edge now does. You don't want to end up like iOS where Safari is the only browser permitted on the platform.