Forcing people to buy new hardware while there's a global chip shortage is going to be interesting.
Not to mention the rise of DRM and other user-hostile shit that they are now forcing you to have.
I fucking hate what this industry has become...
The reason they're doing this is because Microsoft doesn't control OEMs directly. They can't make Dell or whoever put in good hardware unless it's a hard-requirement to run their OS. They obviously want to start leveraging TPM 2.0, probably in order to properly compete with Chromebooks, which all require that tech already.
Chromebooks and GSuite are a meaningful threat to Microsoft - Google has a huge head start in that they've enforced much stricter restrictions from day 1 on Chromebook hardware. Microsoft is just getting aggressive about doing the same. And it's going to take at least 4 years for them to catch up, given that Windows 10 EOLs in 2015 at the earliest.
This fits far more into their business model of 0365, Sentinel, and Azure than it does with their Windows business model.
edit: Expanding on this, TPM technology is critical to Zero Trust Networking, which I'm quite sure Microsoft is going to want to push - especially since Active Directory is getting ripped out of networks practically by government order at this point. If they follow through on this, in 4 years Windows networks could be radically more secure than they are today. This fits in well with where Microsoft is taking its business (cloud, security, organization support).
They control the Windows Logo standards, and have used these to enforce a variety of hardware requirements (including TPM) in the past.
They actually can. They have Windows Logo program, which specifies conditions that your product has to comply with, if you want to qualify. OEMs like Dell want to qualify, that allows them to put the Windows sticker on the box.
How do you think Microsoft made the OEMs ship UEFI and Secure Boot in the first place?
Like it's happening on the Mac, it's getting harder for the average user to screw up since software from "unidentified developers" can't run by default.
I can still run anything I want as a power user and that will not change on macOS and won't change on Windows.
As for secure boot, I don't see how that could be anything else than policy (that can have an impact on a security model and so on associated security measures, granted, but not having secure boot should technically not prevent booting / installation unless it is enforced by an explicit artificial limitation). But they could at least remove legacy boot support, in which case it just won't work without UEFI.
Yeah, you can run Windows 10 on some pretty ancient unsupported hardware too, but when they break support for a driver a couple years in, you end up with a nonworking machine.