Also enabling secure boot is a pain in the ass for users that dual boot, because in Linux, to load a custom compiled kernel module you have to sign it first and do a whole lot of mumbling around to get it working. Just try to install Virtualbox with secure boot enabled. I get the security concern, but why not let users install whatever they want on whatever hardware they want? Come on Microsoft, it's not like you don't already have a working kernel with arguably the best support in terms of drivers in the whole personal computing market.
Also their "supported CPUs" list is a fucking joke. Why would they cut off first gen AMD Ryzen, for example when all Zen CPUs have full TPM 2.0 support built into the AMD PSP. The Ryzen 2000 chips they list as a minimum are basically the same in terms of features and very similar in performance to the previous gen. Zen+ is a slight improvement over Zen that didn't introduce any groundbreaking features to warrant such a cutoff point. Or are you gonna tell me that an Athlon 3000G will run Windows 11 better than a first gen Threadripper?
Get your head out of your ass Microsoft, otherwise you'll be stuck with another Windows Vista.