I now think I was wrong earlier.
Summarizing https://www.gnu.org/licenses/gpl-3.0.html:
> The information (ie 'methods, procedures, authorization keys, or other information required to install and execute modified versions of a covered work') must suffice to ensure that the continued functioning of the modified object code is in no case prevented or interfered with solely because modification has been made.
The purpose of allowing signing is exactly to ensure modified code does not function in that environment.
Yes MS (and you) would be right. GPLv2, BSD or MIT would be fine but GPLv3 would not.
-----------------------------------
Edit reply to baobun (rate limit means I can't post)
I did think about that, but:
> continued functioning of the modified object code
is vague. Does it mean a new firmware binary should continue working on the same device as the unmodified predecessor or using is a new device (that allows arbitrary entities to sign) considered to be "continued functioning"?