TPM means the system can boot and then do face login or whatever using the user's password in exactly one place.
This is as much as most users will tolerate. And it also means Microsoft account recovery can work to unlock a forgotten password.
The whole point is Microsoft don't want user devices to ever be trivially bypassed, regardless of how unlikely that is (probably more likely then you think though).
These things are everywhere: they're used by small businesses, unsophisticated users etc. but the story which will be written if anything happens because the disk was imaged sometime will be "how this small business lost everything because of a stolen Windows laptop" and include a quote about how it wouldn't have happened on a MacBook.