Case in point: TPM is not required to implement UEFI Secure Boot. You can test yourself in a QEMU VM, if you don’t believe me.
From my understanding, TPM is just a separate crypto-module meant to keep the keys secret even from the CPU and OS itself, allowing you to do various crypto and security related things with higher confidence of the keys not getting leaked.
Applications includes passwordless disk-encryption (MS BitLocker) but also hard-to-crack DRM, making the TPM a somewhat controversial piece if hardware.
Someone please correct me if I’m wrong or my answer is inaccurate in any way ;)