Also, if they're signing any Linux distro's shim loader, shim allows a physically present user to enroll their own key or disable secure boot. See method 3 at https://wiki.ubuntu.com/UEFI/SecureBoot/DKMS .
(I don't actually know if they are signing any Linux shim for ARM - https://wiki.ubuntu.com/UEFI/SecureBoot/Testing#UEFI.2FSecur... implies no. Which means you can't use any version of Linux on it, unless they change their policy.)